· 7 years ago · Jul 26, 2019, 06:04 AM
1#######################################################################################################################################
2======================================================================================================================================
3Hostname www.geogroup.com ISP Amazon.com, Inc.
4Continent North America Flag
5US
6Country United States Country Code US
7Region Virginia Local time 26 Jul 2019 00:13 EDT
8City Ashburn Postal Code 20149
9IP Address 52.44.246.60 Latitude 39.048
10 Longitude -77.473
11
12=======================================================================================================================================
13#######################################################################################################################################
14> www.geogroup.com
15Server: 185.93.180.131
16Address: 185.93.180.131#53
17
18Non-authoritative answer:
19www.geogroup.com canonical name = geogroup.com.
20Name: geogroup.com
21Address: 52.44.246.60
22>
23######################################################################################################################################
24 Domain Name: GEOGROUP.COM
25 Registry Domain ID: 83137180_DOMAIN_COM-VRSN
26 Registrar WHOIS Server: whois.godaddy.com
27 Registrar URL: http://www.godaddy.com
28 Updated Date: 2014-12-09T19:05:24Z
29 Creation Date: 2002-01-29T16:24:02Z
30 Registry Expiry Date: 2023-01-10T11:59:59Z
31 Registrar: GoDaddy.com, LLC
32 Registrar IANA ID: 146
33 Registrar Abuse Contact Email: abuse@godaddy.com
34 Registrar Abuse Contact Phone: 480-624-2505
35 Domain Status: clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited
36 Domain Status: clientRenewProhibited https://icann.org/epp#clientRenewProhibited
37 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
38 Domain Status: clientUpdateProhibited https://icann.org/epp#clientUpdateProhibited
39 Name Server: NS0.DNSMADEEASY.COM
40 Name Server: NS1.DNSMADEEASY.COM
41 Name Server: NS2.DNSMADEEASY.COM
42 Name Server: NS3.DNSMADEEASY.COM
43 Name Server: NS4.DNSMADEEASY.COM
44 DNSSEC: unsigned
45######################################################################################################################################
46Domain Name: GEOGROUP.COM
47Registry Domain ID: 83137180_DOMAIN_COM-VRSN
48Registrar WHOIS Server: whois.godaddy.com
49Registrar URL: http://www.godaddy.com
50Updated Date: 2014-12-09T19:05:23Z
51Creation Date: 2002-01-29T16:24:02Z
52Registrar Registration Expiration Date: 2023-01-10T11:59:59Z
53Registrar: GoDaddy.com, LLC
54Registrar IANA ID: 146
55Registrar Abuse Contact Email: abuse@godaddy.com
56Registrar Abuse Contact Phone: +1.4806242505
57Domain Status: clientTransferProhibited http://www.icann.org/epp#clientTransferProhibited
58Domain Status: clientUpdateProhibited http://www.icann.org/epp#clientUpdateProhibited
59Domain Status: clientRenewProhibited http://www.icann.org/epp#clientRenewProhibited
60Domain Status: clientDeleteProhibited http://www.icann.org/epp#clientDeleteProhibited
61Registrant Organization: The GEO Group Inc.
62Registrant State/Province: Florida
63Registrant Country: US
64Registrant Email: Select Contact Domain Holder link at https://www.godaddy.com/whois/results.aspx?domain=GEOGROUP.COM
65Admin Email: Select Contact Domain Holder link at https://www.godaddy.com/whois/results.aspx?domain=GEOGROUP.COM
66Tech Email: Select Contact Domain Holder link at https://www.godaddy.com/whois/results.aspx?domain=GEOGROUP.COM
67Name Server: NS0.DNSMADEEASY.COM
68Name Server: NS1.DNSMADEEASY.COM
69Name Server: NS2.DNSMADEEASY.COM
70Name Server: NS3.DNSMADEEASY.COM
71Name Server: NS4.DNSMADEEASY.COM
72DNSSEC: unsigned
73#######################################################################################################################################
74[+] Target : www.geogroup.com
75
76[+] IP Address : 52.44.246.60
77
78[+] Headers :
79
80[+] Cache-Control : no-cache
81[+] Pragma : no-cache
82[+] Content-Type : text/html; charset=utf-8
83[+] Expires : -1
84[+] Set-Cookie : dnn_IsMobile=False; path=/; secure; HttpOnly, .ASPXANONYMOUS=xbEMhsQT7MpzMUO0ZUiwb_Y9RenmvlYc9xgmmm_G9le02leStJSdTPNwGAnYY7AOOU2Q8rnjsUC5Z3rqCKVZMCyXJmvK_FJMkO_zfucSaM3pV0yu0; expires=Thu, 03-Oct-2019 15:08:32 GMT; path=/; HttpOnly, dnn_IsMobile=False; path=/; secure; HttpOnly, .ASPXANONYMOUS=xbEMhsQT7MpzMUO0ZUiwb_Y9RenmvlYc9xgmmm_G9le02leStJSdTPNwGAnYY7AOOU2Q8rnjsUC5Z3rqCKVZMCyXJmvK_FJMkO_zfucSaM3pV0yu0; expires=Thu, 03-Oct-2019 15:08:32 GMT; path=/; HttpOnly, language=en-US; path=/; secure; HttpOnly, __RequestVerificationToken=XP0Jz5JdM_Y0TP-8YZrJkiUxvxCyhgRZDIkVoIlDRw6fI_EV4Y6Id_P0jbfyr2fndaoztw2; path=/; secure; HttpOnly
85[+] X-Frame-Options : SAMEORIGIN
86[+] X-UA-Compatible : IE=edge
87[+] Strict-Transport-Security : max-age=31536000, includeSubDomains
88[+] Date : Fri, 26 Jul 2019 04:28:31 GMT
89[+] Content-Length : 64441
90
91[+] SSL Certificate Information :
92
93[+] jurisdictionCountryName : US
94[+] jurisdictionStateOrProvinceName : Florida
95[+] businessCategory : Private Organization
96[+] serialNumber : P13000058433
97[+] countryName : US
98[+] stateOrProvinceName : Florida
99[+] localityName : Boca Raton
100[+] organizationName : The Geo Group, Inc.
101[+] commonName : www.geogroup.com
102[+] countryName : US
103[+] stateOrProvinceName : Arizona
104[+] localityName : Scottsdale
105[+] organizationName : GoDaddy.com, Inc.
106[+] organizationalUnitName : http://certs.godaddy.com/repository/
107[+] commonName : Go Daddy Secure Certificate Authority - G2
108[+] Version : 3
109[+] Serial Number : 53F9BC0CA3BDBFC1
110[+] Not Before : Feb 20 04:17:01 2018 GMT
111[+] Not After : Feb 16 21:05:00 2020 GMT
112[+] OCSP : ('http://ocsp.godaddy.com/',)
113[+] subject Alt Name : (('DNS', 'www.geogroup.com'), ('DNS', 'geogroup.com'))
114[+] CA Issuers : ('http://certificates.godaddy.com/repository/gdig2.crt',)
115[+] CRL Distribution Points : ('http://crl.godaddy.com/gdig2s3-10.crl',)
116
117[+] Whois Lookup :
118
119[+] NIR : None
120[+] ASN Registry : arin
121[+] ASN : 14618
122[+] ASN CIDR : 52.44.0.0/15
123[+] ASN Country Code : US
124[+] ASN Date : 2015-09-02
125[+] ASN Description : AMAZON-AES - Amazon.com, Inc., US
126[+] cidr : 52.32.0.0/11
127[+] name : AT-88-Z
128[+] handle : NET-52-32-0-0-1
129[+] range : 52.32.0.0 - 52.63.255.255
130[+] description : Amazon Technologies Inc.
131[+] country : US
132[+] state : WA
133[+] city : Seattle
134[+] address : 410 Terry Ave N.
135[+] postal_code : 98109
136[+] emails : ['aws-routing-poc@amazon.com', 'amzn-noc-contact@amazon.com', 'abuse@amazonaws.com']
137[+] created : 2015-09-02
138[+] updated : 2015-09-02
139
140[+] Crawling Target...
141
142[+] Looking for robots.txt........[ Found ]
143[+] Extracting robots Links.......[ 31 ]
144[+] Looking for sitemap.xml.......[ Not Found ]
145[+] Extracting CSS Links..........[ 15 ]
146[+] Extracting Javascript Links...[ 16 ]
147[+] Extracting Internal Links.....[ 49 ]
148[+] Extracting External Links.....[ 22 ]
149[+] Extracting Images.............[ 33 ]
150
151[+] Total Links Extracted : 166
152
153[+] Dumping Links in /opt/FinalRecon/dumps/www.geogroup.com.dump
154[+] Completed!
155######################################################################################################################################
156[+] Starting At 2019-07-26 00:28:48.102823
157[+] Collecting Information On: https://www.geogroup.com/
158[#] Status: 200
159--------------------------------------------------
160- Cache-Control: no-cache
161- Pragma: no-cache
162- Content-Type: text/html; charset=utf-8
163- Expires: -1
164- Set-Cookie: dnn_IsMobile=False; path=/; secure; HttpOnly, .ASPXANONYMOUS=iXyo51mR7q3MLc8gVJcu5nFua8SmrddSDpZo2DirAIHY8SZ2J3vsFguS44-oZ2fDrcqVTy_Io4VJnM_u2y6Kb5ENQTC6F-UOHXUhrNVA4ua6ryDH0; expires=Thu, 03-Oct-2019 15:08:36 GMT; path=/; HttpOnly, dnn_IsMobile=False; path=/; secure; HttpOnly, .ASPXANONYMOUS=iXyo51mR7q3MLc8gVJcu5nFua8SmrddSDpZo2DirAIHY8SZ2J3vsFguS44-oZ2fDrcqVTy_Io4VJnM_u2y6Kb5ENQTC6F-UOHXUhrNVA4ua6ryDH0; expires=Thu, 03-Oct-2019 15:08:36 GMT; path=/; HttpOnly, language=en-US; path=/; secure; HttpOnly, __RequestVerificationToken=rfnlbhnzZWwmhSQ6DM5zSDQXDw832bmHffeI9wb5QqtL9LTSpo87ubtl_OhOwZTJwIZuKQ2; path=/; secure; HttpOnly
165- X-Frame-Options: SAMEORIGIN
166- X-UA-Compatible: IE=edge
167- Strict-Transport-Security: max-age=31536000, includeSubDomains
168- Date: Fri, 26 Jul 2019 04:28:36 GMT
169- Content-Length: 65166
170--------------------------------------------------
171[#] Finding Location..!
172[#] as: AS14618 Amazon.com, Inc.
173[#] city: Ashburn
174[#] country: United States
175[#] countryCode: US
176[#] isp: Amazon.com, Inc.
177[#] lat: 39.0438
178[#] lon: -77.4874
179[#] org: Amazon Technologies Inc
180[#] query: 52.44.246.60
181[#] region: VA
182[#] regionName: Virginia
183[#] status: success
184[#] timezone: America/New_York
185[#] zip: 20149
186--------------------------------------------------
187[x] Didn't Detect WAF Presence on: https://www.geogroup.com/
188--------------------------------------------------
189[#] Starting Reverse DNS
190[!] Found 1 any Domain
191- geogroup.com
192--------------------------------------------------
193[!] Scanning Open Port
194[#] 80/tcp open http
195[#] 443/tcp open https
196[#] 3389/tcp open ms-wbt-server
197--------------------------------------------------
198[+] Collecting Information Disclosure!
199[#] Detecting sitemap.xml file
200[-] sitemap.xml file not Found!?
201[#] Detecting robots.txt file
202[!] robots.txt File Found: https://www.geogroup.com//robots.txt
203[#] Detecting GNU Mailman
204[-] GNU Mailman App Not Detected!?
205--------------------------------------------------
206[+] Crawling Url Parameter On: https://www.geogroup.com/
207--------------------------------------------------
208[#] Searching Html Form !
209[+] Html Form Discovered
210[#] action: /
211[#] class: None
212[#] id: Form
213[#] method: post
214--------------------------------------------------
215[!] Found 8 dom parameter
216[#] https://www.geogroup.com//javascript:__doPostBack('dnn$dnnSearch2$cmdSearch','')
217[#] https://www.geogroup.com//#
218[#] https://www.geogroup.com//javascript:__doPostBack('dnn$dnnSearch$cmdSearch','')
219[#] http://geogroup.com/Locations#us-corrections
220[#] http://geogroup.com/Locations#international-services
221[#] http://geogroup.com/Locations#reentry-services
222[#] http://geogroup.com/Locations#Non-Residential-Reentry
223[#] http://geogroup.com/Locations#youth-services
224--------------------------------------------------
225[!] 9 Internal Dynamic Parameter Discovered
226[+] https://www.geogroup.com///Resources/Shared/stylesheets/dnndefault/7.0.0/default.css?cdv=71
227[+] https://www.geogroup.com///Resources/Search/SearchSkinObjectPreview.css?cdv=71
228[+] https://www.geogroup.com///Portals/_default/Skins/GeoGroup/bootstrap/css/bootstrap.min.css?cdv=71
229[+] https://www.geogroup.com///Portals/_default/Skins/GeoGroup/css/jquery.smartmenus.bootstrap.css?cdv=71
230[+] https://www.geogroup.com///Portals/_default/Skins/GeoGroup/Menus/MainMenu/MainMenu.css?cdv=71
231[+] https://www.geogroup.com///Portals/_default/Skins/GeoGroup/skin.css?cdv=71
232[+] https://www.geogroup.com///Portals/_default/Skins/GeoGroup/Home.css?cdv=71
233[+] https://www.geogroup.com/Login?returnurl=%2f
234[+] https://www.geogroup.com/Register?returnurl=https%3a%2f%2fwww.geogroup.com%2f
235--------------------------------------------------
236[-] No external Dynamic Paramter Found!?
237--------------------------------------------------
238[!] 164 Internal links Discovered
239[+] https://www.geogroup.com///css/font-awesome.min.css
240[+] https://www.geogroup.com///css/scroll.css
241[+] https://www.geogroup.com///css/jquery.mCustomScrollbar.css
242[+] https://www.geogroup.com///css/accordion.css
243[+] https://www.geogroup.com///css/slick.css
244[+] https://www.geogroup.com///css/slick-theme.css
245[+] https://www.geogroup.com///css/GeoCare.css
246[+] https://www.geogroup.com///GEO_Corrections
247[+] https://www.geogroup.com///GEO-Care
248[+] https://www.geogroup.com///Foundation
249[+] http://jobs.geogroup.com
250[+] https://www.geogroup.com/
251[+] https://www.geogroup.com///Home
252[+] http://investors.geogroup.com
253[+] https://www.geogroup.com///GEO_World
254[+] https://www.geogroup.com///GEONewsletters
255[+] https://www.geogroup.com/who_we_are
256[+] https://www.geogroup.com/who_we_are
257[+] https://www.geogroup.com/partnerships
258[+] https://www.geogroup.com/board_of_directors
259[+] https://www.geogroup.com/management_team
260[+] https://www.geogroup.com/history_timeline
261[+] https://www.geogroup.com/social_responsibility
262[+] https://www.geogroup.com/-Communities_We_Serve
263[+] https://www.geogroup.com/Foundation
264[+] https://www.geogroup.com/active_community_engagement
265[+] https://www.geogroup.com/Sustainability
266[+] https://www.geogroup.com/GEOs-Commitment-to-Respect-Human-Rights
267[+] https://www.geogroup.com/GEOs-Commitment-to-Respect-Human-Rights
268[+] https://www.geogroup.com/geos_global_human_rights_policy
269[+] https://www.geogroup.com/Human-Rights-Engagement
270[+] https://www.geogroup.com/exceeding_quality_compliance
271[+] https://www.geogroup.com/dedicated_compliance_team
272[+] https://www.geogroup.com/Industry_leading_Standards
273[+] https://www.geogroup.com/PREA
274[+] https://www.geogroup.com/Cultivating_a-Fulfilling_Workplace
275[+] https://www.geogroup.com/embracing_diversity_inclusion
276[+] https://www.geogroup.com/career_development_and_advancement
277[+] https://www.geogroup.com/commitment_to_training_excellence
278[+] https://www.geogroup.com/Responsible_Governance
279[+] https://www.geogroup.com/Recent-Corporate-Governance-Events
280[+] https://www.geogroup.com/business_conduct_and_ethics
281[+] https://www.geogroup.com/Political_Engagement
282[+] https://www.geogroup.com/GEO_Secure_Services
283[+] https://www.geogroup.com/GEO_Secure_Services_Leadership_Team
284[+] https://www.geogroup.com/Design_Build_Finance/Lease
285[+] https://www.geogroup.com/Management_and_Operations
286[+] https://www.geogroup.com/GEO_Transport_Inc
287[+] https://www.geogroup.com/GEO-Care
288[+] https://www.geogroup.com/GEO_Care_Leadership_Team
289[+] https://www.geogroup.com/GEOs_Continuum_of_Care
290[+] https://www.geogroup.com/Reentry-Services
291[+] https://www.geogroup.com/Electronic_Monitoring
292[+] https://www.geogroup.com/Abraxas_Youth_and_Family_Services
293[+] https://www.geogroup.com/Locations
294[+] https://www.geogroup.com/GEO_News
295[+] https://www.geogroup.com/GEO_News
296[+] https://www.geogroup.com/GEO_World
297[+] https://www.geogroup.com/Newsletters
298[+] https://www.geogroup.com/Video_Library
299[+] https://www.geogroup.com/Media_Resources
300[+] https://www.geogroup.com/Careers
301[+] https://www.geogroup.com/Benefits
302[+] http://jobs.geogroup.com/
303[+] https://www.geogroup.com/Education
304[+] https://www.geogroup.com/HiringHeroes
305[+] https://www.geogroup.com///css/slick.css
306[+] https://www.geogroup.com///css/slick-theme.css
307[+] https://www.geogroup.com///css/slick-custom.css
308[+] https://www.geogroup.com//' + o.data[i].link + '
309[+] https://www.geogroup.com//' + o.data[i].link + '
310[+] https://www.geogroup.com///Portals/0/CoC%20Annual%20Report%20020719%20FINAL.pdf
311[+] https://www.geogroup.com///GEOs_Continuum_of_Care
312[+] https://www.geogroup.com///GEOs_Continuum_of_Care
313[+] https://www.geogroup.com///Design_Build_Finance/Lease
314[+] https://www.geogroup.com///Design_Build_Finance/Lease
315[+] https://www.geogroup.com///Design_Build_Finance/Lease
316[+] https://www.geogroup.com///Management_and_Operations
317[+] https://www.geogroup.com///Management_and_Operations
318[+] https://www.geogroup.com///Management_and_Operations
319[+] https://www.geogroup.com//In-Custody_Evidence_Based_Programs
320[+] https://www.geogroup.com//In-Custody_Evidence_Based_Programs
321[+] https://www.geogroup.com//In-Custody_Evidence_Based_Programs
322[+] https://www.geogroup.com///GEO_Transport_Inc
323[+] https://www.geogroup.com///GEO_Transport_Inc
324[+] https://www.geogroup.com///GEO_Transport_Inc
325[+] https://www.geogroup.com///Residential_Reentry
326[+] https://www.geogroup.com///Residential_Reentry
327[+] https://www.geogroup.com///Residential_Reentry
328[+] https://www.geogroup.com///Non-Residential_Reentry
329[+] https://www.geogroup.com///Non-Residential_Reentry
330[+] https://www.geogroup.com///Non-Residential_Reentry
331[+] https://www.geogroup.com///Electronic_Monitoring
332[+] https://www.geogroup.com///Electronic_Monitoring
333[+] https://www.geogroup.com///Electronic_Monitoring
334[+] https://www.geogroup.com///Locations
335[+] https://www.geogroup.com///Locations
336[+] https://www.geogroup.com///Careers
337[+] https://www.geogroup.com///Careers
338[+] https://www.geogroup.com///Foundation
339[+] https://www.geogroup.com///Foundation
340[+] https://www.geogroup.com///Industry_leading_Standard
341[+] https://www.geogroup.com///Industry_leading_Standard
342[+] https://www.geogroup.com///GEOs_Continuum_of_Care
343[+] https://www.geogroup.com///GEOs_Continuum_of_Care
344[+] https://www.geogroup.com///Locations
345[+] https://www.geogroup.com///Locations
346[+] https://www.geogroup.com///Careers
347[+] https://www.geogroup.com///Careers
348[+] https://www.geogroup.com///Foundation
349[+] https://www.geogroup.com///Foundation
350[+] https://www.geogroup.com///Compliance
351[+] https://www.geogroup.com///Compliance
352[+] https://www.geogroup.com///GEOs_Continuum_of_Care
353[+] https://www.geogroup.com///GEOs_Continuum_of_Care
354[+] https://www.geogroup.com///css/slick.css
355[+] https://www.geogroup.com///css/slick-theme.css
356[+] https://www.geogroup.com///css/slick-custom.css
357[+] https://www.geogroup.com//' + mailData + '
358[+] https://www.geogroup.com//' + Ans + '
359[+] https://www.geogroup.com//' + linkedInText + '
360[+] https://www.geogroup.com///News-Detail/tabid/189/NewsID/' + o.data[i].newsID + '/Default.aspx
361[+] https://www.geogroup.com///News-Detail/tabid/189/NewsID/' + o.data[i].newsID + '/Default.aspx
362[+] https://www.geogroup.com///News-Detail/tabid/189/NewsID/' + o.data[i].newsID + '/Default.aspx
363[+] https://www.geogroup.com///who_we_are
364[+] https://www.geogroup.com///who_we_are
365[+] https://www.geogroup.com///partnerships
366[+] https://www.geogroup.com///board_of_directors
367[+] https://www.geogroup.com///management_team
368[+] https://www.geogroup.com///history_timeline
369[+] https://www.geogroup.com///social_responsibility
370[+] https://www.geogroup.com///-Communities_We_Serve
371[+] https://www.geogroup.com///GEOs-Commitment-to-Respect-Human-Rights
372[+] https://www.geogroup.com///exceeding_quality_compliance
373[+] https://www.geogroup.com///Cultivating_a-Fulfilling_Workplace
374[+] https://www.geogroup.com///Responsible_Governance
375[+] https://www.geogroup.com///GEO_Corrections
376[+] https://www.geogroup.com///GEO_Corrections_Leadership_Team
377[+] https://www.geogroup.com///Design_Build_Finance/Lease
378[+] https://www.geogroup.com///Management_and_Operations
379[+] https://www.geogroup.com///GEO_Transport_Inc
380[+] https://www.geogroup.com///GEO-Care
381[+] https://www.geogroup.com///GEO_Care_Leadership_Team
382[+] https://www.geogroup.com///GEOs_Continuum_of_Care
383[+] https://www.geogroup.com///Reentry-Services
384[+] https://www.geogroup.com///Electronic_Monitoring
385[+] https://www.geogroup.com///Abraxas_Youth_and_Family_Services
386[+] https://www.geogroup.com///LOCATIONS
387[+] https://www.geogroup.com///GEO_News
388[+] https://www.geogroup.com///GEO_News
389[+] https://www.geogroup.com///GEO_World
390[+] https://www.geogroup.com///Newsletters
391[+] https://www.geogroup.com///Video_Library
392[+] https://www.geogroup.com///Media_Resources
393[+] https://www.geogroup.com///Careers
394[+] https://www.geogroup.com///Benefits
395[+] http://jobs.geogroup.com
396[+] https://www.geogroup.com///Education
397[+] https://www.geogroup.com///Hiring-Heroes
398[+] https://www.geogroup.com///vendors
399[+] https://www.geogroup.com///privacy
400[+] https://www.geogroup.com///TermsOfUse
401[+] https://www.geogroup.com///GEO_World
402[+] https://www.geogroup.com///Portals/_default/Skins/GeoGroup/Home.css
403--------------------------------------------------
404[!] 20 External links Discovered
405[#] https://www.facebook.com/GEOGroup
406[#] https://twitter.com/WeAreGeo
407[#] https://www.linkedin.com/company/the-geo-group-inc.
408[#] https://www.youtube.com/user/TheGEOGroupInc
409[#] https://twitter.com/GEOnewsroom
410[#] https://www.linkedin.com/company-beta/47738/
411[#] https://www.facebook.com/GEOGroup
412[#] https://twitter.com/WeAreGeo
413[#] https://www.linkedin.com/company/the-geo-group-inc.
414[#] https://www.youtube.com/user/TheGEOGroupInc
415[#] http://www.appdevelop.com
416[#] https://adasitecompliance.com/xap_geo/
417[#] http://www.aca.org/
418[#] http://www.iso.org/iso/home.html
419[#] https://www.jointcommission.org/
420[#] http://www.ncchc.org/
421[#] http://www.ceanational.org/
422[#] http://www.sacs.org/
423[#] http://nsca.org.au/
424[#] http://www.achs.org.au/
425--------------------------------------------------
426[#] Mapping Subdomain..
427[!] Found 18 Subdomain
428- vpn2.geogroup.com
429- vcs-e.geogroup.com
430- remote.geogroup.com
431- webmail.geogroup.com
432- pam.geogroup.com
433- vpn.geogroup.com
434- jabber.geogroup.com
435- as.geogroup.com
436- apps.geogroup.com
437- geoapps.geogroup.com
438- myapps.geogroup.com
439- geo-webex.geogroup.com
440- geotracksa.geogroup.com
441- geotrackpecs.geogroup.com
442- identityselfservice.geogroup.com
443- phishing.geogroup.com
444- geogroup.com
445- webexproxy.geogroup.com
446--------------------------------------------------
447[!] Done At 2019-07-26 00:29:19.798629
448######################################################################################################################################
449[i] Scanning Site: https://www.geogroup.com
450
451
452
453B A S I C I N F O
454====================
455
456
457[+] Site Title:
458 The GEO Group - Official Website
459
460[+] IP address: 52.44.246.60
461[+] Web Server: Could Not Detect
462[+] CMS: Could Not Detect
463[+] Cloudflare: Not Detected
464[+] Robots File: Found
465
466-------------[ contents ]----------------
467# Begin robots.txt file
468#/-----------------------------------------------\
469#| In single portal/domain situations, uncomment the sitmap line and enter domain name
470#\-----------------------------------------------/
471#Sitemap: http://www.DomainNamehere.com/sitemap.aspx
472
473
474User-agent: *
475Disallow: /admin/
476Disallow: /App_Browsers/
477Disallow: /App_Code/
478Disallow: /App_Data/
479Disallow: /App_GlobalResources/
480Disallow: /bin/
481Disallow: /Components/
482Disallow: /Config/
483Disallow: /contest/
484Disallow: /controls/
485Disallow: /DesktopModules/
486Disallow: /Documentation/
487Disallow: /HttpModules/
488Disallow: /images/
489Disallow: /Install/
490Disallow: /js/
491Disallow: /Portals/
492Disallow: /Providers/
493Disallow: /Resources/ContentRotator/
494Disallow: /Resources/ControlPanel/
495Disallow: /Resources/Dashboard/
496Disallow: /Resources/FeedBrowser/
497Disallow: /Resources/OpenForceAd/
498Disallow: /Resources/Search/
499Disallow: /Resources/Shared/
500Disallow: /Resources/SkinWidgets/
501Disallow: /Resources/TabStrip/
502Disallow: /Resources/Widgets/
503Disallow: /Activity-Feed/userId/ # Do not index user profiles
504
505User-agent: msnbot
506Disallow: /admin/
507Disallow: /App_Browsers/
508Disallow: /App_Code/
509Disallow: /App_Data/
510Disallow: /App_GlobalResources/
511Disallow: /bin/
512Disallow: /Components/
513Disallow: /Config/
514Disallow: /contest/
515Disallow: /controls/
516Disallow: /DesktopModules/
517Disallow: /Documentation/
518Disallow: /HttpModules/
519Disallow: /images/
520Disallow: /Install/
521Disallow: /js/
522Disallow: /Portals/
523Disallow: /Providers/
524Disallow: /Resources/ContentRotator/
525Disallow: /Resources/ControlPanel/
526Disallow: /Resources/Dashboard/
527Disallow: /Resources/FeedBrowser/
528Disallow: /Resources/OpenForceAd/
529Disallow: /Resources/Search/
530Disallow: /Resources/Shared/
531Disallow: /Resources/SkinWidgets/
532Disallow: /Resources/TabStrip/
533Disallow: /Resources/Widgets/
534Disallow: /Activity-Feed/userId/ # Do not index user profiles
535Crawl-delay: 5
536
537User-agent: Slurp
538Disallow: /*/ctl/ # Slurp permits *
539Disallow: /admin/
540Disallow: /App_Browsers/
541Disallow: /App_Code/
542Disallow: /App_Data/
543Disallow: /App_GlobalResources/
544Disallow: /bin/
545Disallow: /Components/
546Disallow: /Config/
547Disallow: /contest/
548Disallow: /controls/
549Disallow: /DesktopModules/
550Disallow: /Documentation/
551Disallow: /HttpModules/
552Disallow: /images/
553Disallow: /Install/
554Disallow: /js/
555Disallow: /Portals/
556Disallow: /Providers/
557Disallow: /Resources/ContentRotator/
558Disallow: /Resources/ControlPanel/
559Disallow: /Resources/Dashboard/
560Disallow: /Resources/FeedBrowser/
561Disallow: /Resources/OpenForceAd/
562Disallow: /Resources/Search/
563Disallow: /Resources/Shared/
564Disallow: /Resources/SkinWidgets/
565Disallow: /Resources/TabStrip/
566Disallow: /Resources/Widgets/
567Disallow: /Activity-Feed/userId/ # Do not index user profiles
568Crawl-delay: 5
569
570User-agent: Googlebot
571Disallow: /*/ctl/ # Googlebot permits *
572Disallow: /admin/
573Disallow: /App_Browsers/
574Disallow: /App_Code/
575Disallow: /App_Data/
576Disallow: /App_GlobalResources/
577Disallow: /bin/
578Disallow: /Components/
579Disallow: /Config/
580Disallow: /contest/
581Disallow: /controls/
582Disallow: /Documentation/
583Disallow: /HttpModules/
584Disallow: /Install/
585Disallow: /Providers/
586Disallow: /Activity-Feed/userId/ # Do not index user profiles
587
588User-agent: Yahoo Pipes 1.0
589Disallow: /admin/
590Disallow: /App_Browsers/
591Disallow: /App_Code/
592Disallow: /App_Data/
593Disallow: /App_GlobalResources/
594Disallow: /bin/
595Disallow: /Components/
596Disallow: /Config/
597Disallow: /contest/
598Disallow: /controls/
599Disallow: /DesktopModules/
600Disallow: /Documentation/
601Disallow: /HttpModules/
602Disallow: /images/
603Disallow: /Install/
604Disallow: /js/
605Disallow: /Portals/
606Disallow: /Providers/
607Disallow: /Resources/ContentRotator/
608Disallow: /Resources/ControlPanel/
609Disallow: /Resources/Dashboard/
610Disallow: /Resources/FeedBrowser/
611Disallow: /Resources/OpenForceAd/
612Disallow: /Resources/Search/
613Disallow: /Resources/Shared/
614Disallow: /Resources/SkinWidgets/
615Disallow: /Resources/TabStrip/
616Disallow: /Resources/Widgets/
617Disallow: /Activity-Feed/userId/ # Do not index user profiles
618
619
620# End of robots.txt file
621
622-----------[end of contents]-------------
623
624
625
626W H O I S L O O K U P
627========================
628
629 Domain Name: GEOGROUP.COM
630 Registry Domain ID: 83137180_DOMAIN_COM-VRSN
631 Registrar WHOIS Server: whois.godaddy.com
632 Registrar URL: http://www.godaddy.com
633 Updated Date: 2014-12-09T19:05:24Z
634 Creation Date: 2002-01-29T16:24:02Z
635 Registry Expiry Date: 2023-01-10T11:59:59Z
636 Registrar: GoDaddy.com, LLC
637 Registrar IANA ID: 146
638 Registrar Abuse Contact Email: abuse@godaddy.com
639 Registrar Abuse Contact Phone: 480-624-2505
640 Domain Status: clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited
641 Domain Status: clientRenewProhibited https://icann.org/epp#clientRenewProhibited
642 Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
643 Domain Status: clientUpdateProhibited https://icann.org/epp#clientUpdateProhibited
644 Name Server: NS0.DNSMADEEASY.COM
645 Name Server: NS1.DNSMADEEASY.COM
646 Name Server: NS2.DNSMADEEASY.COM
647 Name Server: NS3.DNSMADEEASY.COM
648 Name Server: NS4.DNSMADEEASY.COM
649 DNSSEC: unsigned
650 URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/
651>>> Last update of whois database: 2019-07-26T04:26:59Z <<<
652
653For more information on Whois status codes, please visit https://icann.org/epp
654
655
656
657The Registry database contains ONLY .COM, .NET, .EDU domains and
658Registrars.
659
660
661
662
663G E O I P L O O K U P
664=========================
665
666[i] IP Address: 52.44.246.60
667[i] Country: United States
668[i] State: Virginia
669[i] City: Ashburn
670[i] Latitude: 39.0481
671[i] Longitude: -77.4728
672
673
674
675
676H T T P H E A D E R S
677=======================
678
679
680[i] HTTP/1.1 200 OK
681[i] Cache-Control: no-cache
682[i] Pragma: no-cache
683[i] Content-Type: text/html; charset=utf-8
684[i] Expires: -1
685[i] Set-Cookie: dnn_IsMobile=False; path=/; secure; HttpOnly
686[i] Set-Cookie: .ASPXANONYMOUS=SXZ1-E4jWtxrw2f0QxjEs2n1rjfAG5xzr_YhNpKsaJvQ5vhkomTvswgElI40ztH6X1k42Muq1zPAz0wKjs3kzZWiR7c79uhaGsqcN1B5eE8JcIKv0; expires=Thu, 03-Oct-2019 15:07:02 GMT; path=/; HttpOnly
687[i] X-Frame-Options: SAMEORIGIN
688[i] X-UA-Compatible: IE=edge
689[i] Set-Cookie: dnn_IsMobile=False; path=/; secure; HttpOnly
690[i] Set-Cookie: .ASPXANONYMOUS=SXZ1-E4jWtxrw2f0QxjEs2n1rjfAG5xzr_YhNpKsaJvQ5vhkomTvswgElI40ztH6X1k42Muq1zPAz0wKjs3kzZWiR7c79uhaGsqcN1B5eE8JcIKv0; expires=Thu, 03-Oct-2019 15:07:02 GMT; path=/; HttpOnly
691[i] Set-Cookie: language=en-US; path=/; secure; HttpOnly
692[i] Set-Cookie: __RequestVerificationToken=Pi7z_2JrjhTetCBcOmiibzzS1z9COk6j5WjlGHj5tsqHudj0GYQjRXoVa0Ory7mgYPamUw2; path=/; secure; HttpOnly
693[i] Strict-Transport-Security: max-age=31536000, includeSubDomains
694[i] Date: Fri, 26 Jul 2019 04:27:01 GMT
695[i] Connection: close
696[i] Content-Length: 64526
697
698
699
700
701D N S L O O K U P
702===================
703
704geogroup.com. 21599 IN SOA ns0.dnsmadeeasy.com. dns.dnsmadeeasy.com. 2008010345 43200 3600 1209600 180
705geogroup.com. 21599 IN NS ns1.dnsmadeeasy.com.
706geogroup.com. 21599 IN NS ns2.dnsmadeeasy.com.
707geogroup.com. 21599 IN NS ns3.dnsmadeeasy.com.
708geogroup.com. 21599 IN NS ns0.dnsmadeeasy.com.
709geogroup.com. 21599 IN NS ns4.dnsmadeeasy.com.
710geogroup.com. 1799 IN A 52.44.246.60
711geogroup.com. 1799 IN MX 10 mxb-00217401.gslb.pphosted.com.
712geogroup.com. 1799 IN MX 10 mxa-00217401.gslb.pphosted.com.
713geogroup.com. 3599 IN TXT "ym3PKhWfO+YUn21OOMtNljU+4X2e/LecanP1erOL3OH2VnUhgRMCf5oBL5YrVsmV9EQ0+yh6hY+4YHtjLEPnyA=="
714geogroup.com. 3599 IN TXT "@ MS=ms98706971"
715geogroup.com. 3599 IN TXT "v=spf1 a include:_spf.google.com include:spf.protection.outlook.com include:spf-00217401.pphosted.com ip4:8.17.112.16 ip4:8.17.112.7 ip4:8.44.244.7 ~all"
716geogroup.com. 3599 IN TXT "@ MS=F0C5AEC0E4703A199A9B6F336E7FCAA9F660C2D0"
717geogroup.com. 3599 IN TXT "google-site-verification=mp9Tyd2gAoVpYJzKy5ePt1wH0vQZX8smMbtkZhAkjRQ"
718geogroup.com. 3599 IN TXT "globalsign-domain-verification=oiM-PiF7SVVL-ozOu6K60tUBN2RhZGaNrD5GG52ES_"
719geogroup.com. 3599 IN TXT "google-site-verification=u5loptN1DWKjoWSkHGkVllzPvuYBhDSJ3UIi_4yPjWY"
720geogroup.com. 1799 IN SPF "v=spf1 a include:_spf.google.com include:spf.protection.outlook.com include:spf-00217401.pphosted.com ip4:8.17.112.16 ip4:8.17.112.7 ip4:8.44.244.7 ~all"
721
722
723
724
725S U B N E T C A L C U L A T I O N
726====================================
727
728Address = 52.44.246.60
729Network = 52.44.246.60 / 32
730Netmask = 255.255.255.255
731Broadcast = not needed on Point-to-Point links
732Wildcard Mask = 0.0.0.0
733Hosts Bits = 0
734Max. Hosts = 1 (2^0 - 0)
735Host Range = { 52.44.246.60 - 52.44.246.60 }
736
737
738
739N M A P P O R T S C A N
740============================
741
742Starting Nmap 7.70 ( https://nmap.org ) at 2019-07-26 04:27 UTC
743Nmap scan report for geogroup.com (52.44.246.60)
744Host is up (0.0083s latency).
745rDNS record for 52.44.246.60: ec2-52-44-246-60.compute-1.amazonaws.com
746
747PORT STATE SERVICE
74821/tcp filtered ftp
74922/tcp filtered ssh
75023/tcp filtered telnet
75180/tcp open http
752110/tcp filtered pop3
753143/tcp filtered imap
754443/tcp open https
7553389/tcp open ms-wbt-server
756
757Nmap done: 1 IP address (1 host up) scanned in 1.24 seconds
758
759
760
761S U B - D O M A I N F I N D E R
762==================================
763
764
765[i] Total Subdomains Found : 17
766
767[+] Subdomain: vpn2.geogroup.com
768[-] IP: 8.44.244.7
769
770[+] Subdomain: geotracksa.geogroup.com
771[-] IP: 35.169.136.153
772
773[+] Subdomain: vcs-e.geogroup.com
774[-] IP: 74.11.166.22
775
776[+] Subdomain: identityselfservice.geogroup.com
777[-] IP: 35.172.196.161
778
779[+] Subdomain: remote.geogroup.com
780[-] IP: 8.44.244.30
781
782[+] Subdomain: phishing.geogroup.com
783[-] IP: 35.172.196.161
784
785[+] Subdomain: webmail.geogroup.com
786[-] IP: 8.17.112.17
787
788[+] Subdomain: pam.geogroup.com
789[-] IP: 8.44.244.32
790
791[+] Subdomain: vpn.geogroup.com
792[-] IP: 8.44.244.7
793
794[+] Subdomain: jabber.geogroup.com
795[-] IP: 74.11.166.30
796
797[+] Subdomain: as.geogroup.com
798[-] IP: 8.17.112.19
799
800[+] Subdomain: geotrackpecs.geogroup.com
801[-] IP: 35.169.136.153
802
803[+] Subdomain: apps.geogroup.com
804[-] IP: 8.17.112.15
805
806[+] Subdomain: geoapps.geogroup.com
807[-] IP: 8.44.244.33
808
809[+] Subdomain: myapps.geogroup.com
810[-] IP: 8.44.244.29
811
812[+] Subdomain: geo-webex.geogroup.com
813[-] IP: 74.11.166.24
814
815[+] Subdomain: webexproxy.geogroup.com
816[-] IP: 74.11.166.25
817######################################################################################################################################
818Enter Address Website = geogroup.com
819
820
821
822Reversing IP With HackTarget 'geogroup.com'
823----------------------------------------------
824
825[+] ec2-52-44-246-60.compute-1.amazonaws.com
826[+] geogroup.com
827
828
829
830Reverse IP With YouGetSignal 'geogroup.com'
831----------------------------------------------
832
833[*] IP: 52.44.246.60
834[*] Domain: geogroup.com
835[*] Total Domains: 1
836
837[+] geogroup.com
838
839
840
841Geo IP Lookup 'geogroup.com'
842-------------------------------
843
844[+] IP Address: 52.44.246.60
845[+] Country: United States
846[+] State: Virginia
847[+] City: Ashburn
848[+] Latitude: 39.0481
849[+] Longitude: -77.4728
850
851
852
853Whois 'geogroup.com'
854-----------------------
855
856[+] Domain Name: GEOGROUP.COM
857[+] Registry Domain ID: 83137180_DOMAIN_COM-VRSN
858[+] Registrar WHOIS Server: whois.godaddy.com
859[+] Registrar URL: http://www.godaddy.com
860[+] Updated Date: 2014-12-09T19:05:24Z
861[+] Creation Date: 2002-01-29T16:24:02Z
862[+] Registry Expiry Date: 2023-01-10T11:59:59Z
863[+] Registrar: GoDaddy.com, LLC
864[+] Registrar IANA ID: 146
865[+] Registrar Abuse Contact Email: abuse@godaddy.com
866[+] Registrar Abuse Contact Phone: 480-624-2505
867[+] Domain Status: clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited
868[+] Domain Status: clientRenewProhibited https://icann.org/epp#clientRenewProhibited
869[+] Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
870[+] Domain Status: clientUpdateProhibited https://icann.org/epp#clientUpdateProhibited
871[+] Name Server: NS0.DNSMADEEASY.COM
872[+] Name Server: NS1.DNSMADEEASY.COM
873[+] Name Server: NS2.DNSMADEEASY.COM
874[+] Name Server: NS3.DNSMADEEASY.COM
875[+] Name Server: NS4.DNSMADEEASY.COM
876[+] DNSSEC: unsigned
877[+] URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/
878[+] >>> Last update of whois database: 2019-07-26T04:23:59Z <<<
879[+] For more information on Whois status codes, please visit https://icann.org/epp
880[+] The Registry database contains ONLY .COM, .NET, .EDU domains and
881[+] Registrars.
882
883
884
885Bypass Cloudflare 'geogroup.com'
886-----------------------------------
887
888
889[!] CloudFlare Bypass 8.17.112.17 | webmail.geogroup.com
890[!] CloudFlare Bypass 8.17.112.16 | mail.geogroup.com
891[!] CloudFlare Bypass 52.44.246.60 | www.geogroup.com
892[!] CloudFlare Bypass 8.44.244.7 | vpn.geogroup.com
893[!] CloudFlare Bypass 8.17.112.16 | mail2.geogroup.com
894
895
896
897
898DNS Lookup 'geogroup.com'
899----------------------------
900
901[+] geogroup.com. 1799 IN SPF "v=spf1 a include:_spf.google.com include:spf.protection.outlook.com include:spf-00217401.pphosted.com ip4:8.17.112.16 ip4:8.17.112.7 ip4:8.44.244.7 ~all"
902[+] geogroup.com. 3599 IN TXT "google-site-verification=mp9Tyd2gAoVpYJzKy5ePt1wH0vQZX8smMbtkZhAkjRQ"
903[+] geogroup.com. 3599 IN TXT "google-site-verification=u5loptN1DWKjoWSkHGkVllzPvuYBhDSJ3UIi_4yPjWY"
904[+] geogroup.com. 3599 IN TXT "v=spf1 a include:_spf.google.com include:spf.protection.outlook.com include:spf-00217401.pphosted.com ip4:8.17.112.16 ip4:8.17.112.7 ip4:8.44.244.7 ~all"
905[+] geogroup.com. 3599 IN TXT "globalsign-domain-verification=oiM-PiF7SVVL-ozOu6K60tUBN2RhZGaNrD5GG52ES_"
906[+] geogroup.com. 3599 IN TXT "@ MS=F0C5AEC0E4703A199A9B6F336E7FCAA9F660C2D0"
907[+] geogroup.com. 3599 IN TXT "@ MS=ms98706971"
908[+] geogroup.com. 3599 IN TXT "ym3PKhWfO+YUn21OOMtNljU+4X2e/LecanP1erOL3OH2VnUhgRMCf5oBL5YrVsmV9EQ0+yh6hY+4YHtjLEPnyA=="
909[+] geogroup.com. 1799 IN MX 10 mxa-00217401.gslb.pphosted.com.
910[+] geogroup.com. 1799 IN MX 10 mxb-00217401.gslb.pphosted.com.
911[+] geogroup.com. 1799 IN A 52.44.246.60
912[+] geogroup.com. 21599 IN NS ns2.dnsmadeeasy.com.
913[+] geogroup.com. 21599 IN NS ns0.dnsmadeeasy.com.
914[+] geogroup.com. 21599 IN NS ns3.dnsmadeeasy.com.
915[+] geogroup.com. 21599 IN NS ns4.dnsmadeeasy.com.
916[+] geogroup.com. 21599 IN NS ns1.dnsmadeeasy.com.
917[+] geogroup.com. 21599 IN SOA ns0.dnsmadeeasy.com. dns.dnsmadeeasy.com. 2008010345 43200 3600 1209600 180
918
919
920
921Find Shared DNS 'geogroup.com'
922---------------------------------
923
924[+] No DNS server records found for geogroup.com
925
926
927
928Show HTTP Header 'geogroup.com'
929----------------------------------
930
931[+] HTTP/1.1 301 Moved Permanently
932[+] Cache-Control: private
933[+] Content-Length: 141
934[+] Location: http://www.geogroup.com/
935[+] X-Redirect-Reason: Wrong Portal Alias Requested
936[+] Set-Cookie: dnn_IsMobile=False; path=/; secure; HttpOnly
937[+] Strict-Transport-Security: max-age=31536000, includeSubDomains
938[+] Date: Fri, 26 Jul 2019 04:24:32 GMT
939[+]
940
941
942
943Port Scan 'geogroup.com'
944---------------------------
945
946Starting Nmap 7.70 ( https://nmap.org ) at 2019-07-26 04:24 UTC
947Nmap scan report for geogroup.com (52.44.246.60)
948Host is up (0.0082s latency).
949rDNS record for 52.44.246.60: ec2-52-44-246-60.compute-1.amazonaws.com
950
951PORT STATE SERVICE
95221/tcp filtered ftp
95322/tcp filtered ssh
95423/tcp filtered telnet
95580/tcp open http
956110/tcp filtered pop3
957143/tcp filtered imap
958443/tcp open https
9593389/tcp open ms-wbt-server
960
961Nmap done: 1 IP address (1 host up) scanned in 1.41 seconds
962
963
964
965
966Cms Scan 'geogroup.com'
967--------------------------
968
969[+] Cms : DNN
970[+] Web Servers : IIS
971[+] Programming Languages : [@] Sorry, The webserver of the website you entered have no domains other then the one you gave
972
973
974
975Robot.txt 'geogroup.com'
976---------------------------
977
978# Begin robots.txt file
979#/-----------------------------------------------\
980#| In single portal/domain situations, uncomment the sitmap line and enter domain name
981#\-----------------------------------------------/
982#Sitemap: http://www.DomainNamehere.com/sitemap.aspx
983
984
985User-agent: *
986Disallow: /admin/
987Disallow: /App_Browsers/
988Disallow: /App_Code/
989Disallow: /App_Data/
990Disallow: /App_GlobalResources/
991Disallow: /bin/
992Disallow: /Components/
993Disallow: /Config/
994Disallow: /contest/
995Disallow: /controls/
996Disallow: /DesktopModules/
997Disallow: /Documentation/
998Disallow: /HttpModules/
999Disallow: /images/
1000Disallow: /Install/
1001Disallow: /js/
1002Disallow: /Portals/
1003Disallow: /Providers/
1004Disallow: /Resources/ContentRotator/
1005Disallow: /Resources/ControlPanel/
1006Disallow: /Resources/Dashboard/
1007Disallow: /Resources/FeedBrowser/
1008Disallow: /Resources/OpenForceAd/
1009Disallow: /Resources/Search/
1010Disallow: /Resources/Shared/
1011Disallow: /Resources/SkinWidgets/
1012Disallow: /Resources/TabStrip/
1013Disallow: /Resources/Widgets/
1014Disallow: /Activity-Feed/userId/ # Do not index user profiles
1015
1016User-agent: msnbot
1017Disallow: /admin/
1018Disallow: /App_Browsers/
1019Disallow: /App_Code/
1020Disallow: /App_Data/
1021Disallow: /App_GlobalResources/
1022Disallow: /bin/
1023Disallow: /Components/
1024Disallow: /Config/
1025Disallow: /contest/
1026Disallow: /controls/
1027Disallow: /DesktopModules/
1028Disallow: /Documentation/
1029Disallow: /HttpModules/
1030Disallow: /images/
1031Disallow: /Install/
1032Disallow: /js/
1033Disallow: /Portals/
1034Disallow: /Providers/
1035Disallow: /Resources/ContentRotator/
1036Disallow: /Resources/ControlPanel/
1037Disallow: /Resources/Dashboard/
1038Disallow: /Resources/FeedBrowser/
1039Disallow: /Resources/OpenForceAd/
1040Disallow: /Resources/Search/
1041Disallow: /Resources/Shared/
1042Disallow: /Resources/SkinWidgets/
1043Disallow: /Resources/TabStrip/
1044Disallow: /Resources/Widgets/
1045Disallow: /Activity-Feed/userId/ # Do not index user profiles
1046Crawl-delay: 5
1047
1048User-agent: Slurp
1049Disallow: /*/ctl/ # Slurp permits *
1050Disallow: /admin/
1051Disallow: /App_Browsers/
1052Disallow: /App_Code/
1053Disallow: /App_Data/
1054Disallow: /App_GlobalResources/
1055Disallow: /bin/
1056Disallow: /Components/
1057Disallow: /Config/
1058Disallow: /contest/
1059Disallow: /controls/
1060Disallow: /DesktopModules/
1061Disallow: /Documentation/
1062Disallow: /HttpModules/
1063Disallow: /images/
1064Disallow: /Install/
1065Disallow: /js/
1066Disallow: /Portals/
1067Disallow: /Providers/
1068Disallow: /Resources/ContentRotator/
1069Disallow: /Resources/ControlPanel/
1070Disallow: /Resources/Dashboard/
1071Disallow: /Resources/FeedBrowser/
1072Disallow: /Resources/OpenForceAd/
1073Disallow: /Resources/Search/
1074Disallow: /Resources/Shared/
1075Disallow: /Resources/SkinWidgets/
1076Disallow: /Resources/TabStrip/
1077Disallow: /Resources/Widgets/
1078Disallow: /Activity-Feed/userId/ # Do not index user profiles
1079Crawl-delay: 5
1080
1081User-agent: Googlebot
1082Disallow: /*/ctl/ # Googlebot permits *
1083Disallow: /admin/
1084Disallow: /App_Browsers/
1085Disallow: /App_Code/
1086Disallow: /App_Data/
1087Disallow: /App_GlobalResources/
1088Disallow: /bin/
1089Disallow: /Components/
1090Disallow: /Config/
1091Disallow: /contest/
1092Disallow: /controls/
1093Disallow: /Documentation/
1094Disallow: /HttpModules/
1095Disallow: /Install/
1096Disallow: /Providers/
1097Disallow: /Activity-Feed/userId/ # Do not index user profiles
1098
1099User-agent: Yahoo Pipes 1.0
1100Disallow: /admin/
1101Disallow: /App_Browsers/
1102Disallow: /App_Code/
1103Disallow: /App_Data/
1104Disallow: /App_GlobalResources/
1105Disallow: /bin/
1106Disallow: /Components/
1107Disallow: /Config/
1108Disallow: /contest/
1109Disallow: /controls/
1110Disallow: /DesktopModules/
1111Disallow: /Documentation/
1112Disallow: /HttpModules/
1113Disallow: /images/
1114Disallow: /Install/
1115Disallow: /js/
1116Disallow: /Portals/
1117Disallow: /Providers/
1118Disallow: /Resources/ContentRotator/
1119Disallow: /Resources/ControlPanel/
1120Disallow: /Resources/Dashboard/
1121Disallow: /Resources/FeedBrowser/
1122Disallow: /Resources/OpenForceAd/
1123Disallow: /Resources/Search/
1124Disallow: /Resources/Shared/
1125Disallow: /Resources/SkinWidgets/
1126Disallow: /Resources/TabStrip/
1127Disallow: /Resources/Widgets/
1128Disallow: /Activity-Feed/userId/ # Do not index user profiles
1129
1130
1131# End of robots.txt file
1132
1133
1134
1135
1136Traceroute 'geogroup.com'
1137----------------------------
1138
1139Start: 2019-07-26T04:24:57+0000
1140HOST: web01 Loss% Snt Last Avg Best Wrst StDev
1141 1.|-- 45.79.12.202 0.0% 3 0.7 0.9 0.7 1.0 0.2
1142 2.|-- 45.79.12.2 0.0% 3 0.7 0.6 0.5 0.7 0.2
1143 3.|-- equinix01-dfw3.amazon.com 0.0% 3 1.1 1.4 1.1 2.1 0.6
1144 4.|-- 176.32.125.198 0.0% 3 29.4 29.3 29.2 29.4 0.1
1145 5.|-- 176.32.125.203 0.0% 3 30.6 31.3 30.6 31.8 0.7
1146 6.|-- ??? 100.0 3 0.0 0.0 0.0 0.0 0.0
1147 7.|-- 52.93.129.253 0.0% 3 31.6 33.7 31.6 37.2 3.0
1148 8.|-- 54.239.42.237 0.0% 3 29.4 29.3 29.2 29.4 0.1
1149 9.|-- ??? 100.0 3 0.0 0.0 0.0 0.0 0.0
1150 10.|-- ??? 100.0 3 0.0 0.0 0.0 0.0 0.0
1151 11.|-- ??? 100.0 3 0.0 0.0 0.0 0.0 0.0
1152 12.|-- ??? 100.0 3 0.0 0.0 0.0 0.0 0.0
1153 13.|-- ??? 100.0 3 0.0 0.0 0.0 0.0 0.0
1154 14.|-- ??? 100.0 3 0.0 0.0 0.0 0.0 0.0
1155 15.|-- ??? 100.0 3 0.0 0.0 0.0 0.0 0.0
1156 16.|-- ??? 100.0 3 0.0 0.0 0.0 0.0 0.0
1157 17.|-- ??? 100.0 3 0.0 0.0 0.0 0.0 0.0
1158 18.|-- ??? 100.0 3 0.0 0.0 0.0 0.0 0.0
1159 19.|-- 52.93.28.152 0.0% 3 31.1 31.6 31.1 31.9 0.4
1160 20.|-- ??? 100.0 3 0.0 0.0 0.0 0.0 0.0
1161
1162
1163
1164
1165Page Admin Finder 'geogroup.com'
1166-----------------------------------
1167
1168
1169
1170Avilable Links :
1171
1172Find Page >> http://geogroup.com/admin/
1173######################################################################################################################################
1174Parsero scan report for www.geogroup.com
1175http://www.geogroup.com/Resources/TabStrip/ 404 Not Found
1176http://www.geogroup.com/Resources/ContentRotator/ 404 Not Found
1177http://www.geogroup.com/js/ 403 Forbidden
1178http://www.geogroup.com/App_GlobalResources/ 404 Not Found
1179http://www.geogroup.com/images/ 403 Forbidden
1180http://www.geogroup.com/Resources/Dashboard/ 403 Forbidden
1181http://www.geogroup.com/HttpModules/ 404 Not Found
1182http://www.geogroup.com/Documentation/ 403 Forbidden
1183http://www.geogroup.com/bin/ 404 Not Found
1184http://www.geogroup.com/Resources/FeedBrowser/ 404 Not Found
1185http://www.geogroup.com/Providers/ 403 Forbidden
1186http://www.geogroup.com/Install/ 403 Forbidden
1187http://www.geogroup.com/Components/ 403 Forbidden
1188http://www.geogroup.com/Portals/ 403 Forbidden
1189http://www.geogroup.com/Resources/OpenForceAd/ 404 Not Found
1190http://www.geogroup.com/Resources/Shared/ 403 Forbidden
1191http://www.geogroup.com/App_Data/ 404 Not Found
1192http://www.geogroup.com/contest/ 404 Not Found
1193http://www.geogroup.com/admin/ 301 Moved Permanently
1194http://www.geogroup.com/controls/ 403 Forbidden
1195http://www.geogroup.com/DesktopModules/ 403 Forbidden
1196http://www.geogroup.com/App_Code/ 404 Not Found
1197http://www.geogroup.com/Config/ 403 Forbidden
1198http://www.geogroup.com/Resources/SkinWidgets/ 404 Not Found
1199#######################################################################################################################################
1200[INFO] Date: 26/07/19 | Time: 00:38:11
1201[INFO] ------TARGET info------
1202[*] TARGET: https://www.geogroup.com/
1203[*] TARGET IP: 52.44.246.60
1204[INFO] NO load balancer detected for www.geogroup.com...
1205[*] DNS servers: geogroup.com.
1206[*] TARGET server:
1207[*] CC: US
1208[*] Country: United States
1209[*] RegionCode: VA
1210[*] RegionName: Virginia
1211[*] City: Ashburn
1212[*] ASN: AS9044
1213[*] BGP_PREFIX: 32.0.0.0/3
1214[*] ISP: SOLNET BSE Software GmbH, CH
1215[INFO] SSL/HTTPS certificate detected
1216[*] Issuer: issuer=C = US, ST = Arizona, L = Scottsdale, O = "GoDaddy.com, Inc.", OU = http://certs.godaddy.com/repository/, CN = Go Daddy Secure Certificate Authority - G2
1217[*] Subject: subject=jurisdictionC = US, jurisdictionST = Florida, businessCategory = Private Organization, serialNumber = P13000058433, C = US, ST = Florida, L = Boca Raton, O = "The Geo Group, Inc.", CN = www.geogroup.com
1218[INFO] DNS enumeration:
1219[*] jobs.geogroup.com d1er0gq1fcs5fb.cloudfront.net. 13.224.227.121 13.224.227.32 13.224.227.90 13.224.227.112
1220[*] mail.geogroup.com 8.17.112.16
1221[*] mail2.geogroup.com 8.17.112.16
1222[*] video.geogroup.com 74.11.166.23
1223[*] vpn.geogroup.com 8.44.244.7
1224[*] webmail.geogroup.com 8.17.112.17
1225[INFO] Possible abuse mails are:
1226[*] abuse@geogroup.com
1227[*] abuse@www.geogroup.com
1228[INFO] NO PAC (Proxy Auto Configuration) file FOUND
1229[ALERT] robots.txt file FOUND in http://www.geogroup.com/robots.txt
1230[INFO] Checking for HTTP status codes recursively from http://www.geogroup.com/robots.txt
1231[INFO] Status code Folders
1232[*] 200 http://www.geogroup.com/Activity-Feed/userId/
1233[*] 200 http://www.geogroup.com#
1234[*] 200 http://www.geogroup.com#
1235[INFO] Starting FUZZing in http://www.geogroup.com/FUzZzZzZzZz...
1236[INFO] Status code Folders
1237[*] 200 http://www.geogroup.com/news
1238[ALERT] Look in the source code. It may contain passwords
1239[INFO] Links found from https://www.geogroup.com/ http://52.44.246.60/:
1240[*] http://geogroup.com/Locations#international-services
1241[*] http://geogroup.com/Locations#Non-Residential-Reentry
1242[*] http://geogroup.com/Locations#reentry-services
1243[*] http://geogroup.com/Locations#us-corrections
1244[*] http://geogroup.com/Locations#youth-services
1245[*] http://investors.geogroup.com/
1246[*] http://jobs.geogroup.com/
1247[*] http://nsca.org.au/
1248[*] https://adasitecompliance.com/xap_geo/
1249[*] https://twitter.com/WeAreGeo
1250[*] https://www.facebook.com/GEOGroup
1251[*] https://www.geogroup.com/
1252[*] https://www.geogroup.com/Abraxas_Youth_and_Family_Services
1253[*] https://www.geogroup.com/active_community_engagement
1254[*] https://www.geogroup.com/Benefits
1255[*] https://www.geogroup.com/board_of_directors
1256[*] https://www.geogroup.com/business_conduct_and_ethics
1257[*] https://www.geogroup.com/career_development_and_advancement
1258[*] https://www.geogroup.com/Careers
1259[*] https://www.geogroup.com/commitment_to_training_excellence
1260[*] https://www.geogroup.com/-Communities_We_Serve
1261[*] https://www.geogroup.com/Compliance
1262[*] https://www.geogroup.com/Cultivating_a-Fulfilling_Workplace
1263[*] https://www.geogroup.com/dedicated_compliance_team
1264[*] https://www.geogroup.com/Design_Build_Finance/Lease
1265[*] https://www.geogroup.com/Education
1266[*] https://www.geogroup.com/Electronic_Monitoring
1267[*] https://www.geogroup.com/embracing_diversity_inclusion
1268[*] https://www.geogroup.com/exceeding_quality_compliance
1269[*] https://www.geogroup.com/Foundation
1270[*] https://www.geogroup.com/GEO-Care
1271[*] https://www.geogroup.com/GEO_Care_Leadership_Team
1272[*] https://www.geogroup.com/GEO_Corrections
1273[*] https://www.geogroup.com/GEO_Corrections_Leadership_Team
1274[*] https://www.geogroup.com/GEO_News
1275[*] https://www.geogroup.com/GEONewsletters
1276[*] https://www.geogroup.com/GEOs-Commitment-to-Respect-Human-Rights
1277[*] https://www.geogroup.com/GEOs_Continuum_of_Care
1278[*] https://www.geogroup.com/GEO_Secure_Services
1279[*] https://www.geogroup.com/GEO_Secure_Services_Leadership_Team
1280[*] https://www.geogroup.com/geos_global_human_rights_policy
1281[*] https://www.geogroup.com/GEO_Transport_Inc
1282[*] https://www.geogroup.com/GEO_World
1283[*] https://www.geogroup.com/Hiring-Heroes
1284[*] https://www.geogroup.com/HiringHeroes
1285[*] https://www.geogroup.com/history_timeline
1286[*] https://www.geogroup.com/Home
1287[*] https://www.geogroup.com/Human-Rights-Engagement
1288[*] https://www.geogroup.com/In-Custody_Evidence_Based_Programs
1289[*] https://www.geogroup.com/Industry_leading_Standard
1290[*] https://www.geogroup.com/Industry_leading_Standards
1291[*] https://www.geogroup.com/LOCATIONS
1292[*] https://www.geogroup.com/Locations
1293[*] https://www.geogroup.com/Login?returnurl=/
1294[*] https://www.geogroup.com/mailChamp.html
1295[*] https://www.geogroup.com/Management_and_Operations
1296[*] https://www.geogroup.com/management_team
1297[*] https://www.geogroup.com/Media_Resources
1298[*] https://www.geogroup.com/Newsletters
1299[*] https://www.geogroup.com/Non-Residential_Reentry
1300[*] https://www.geogroup.com/partnerships
1301[*] https://www.geogroup.com/Political_Engagement
1302[*] https://www.geogroup.com/Portals/0/CoC Annual Report 020719 FINAL.pdf
1303[*] https://www.geogroup.com/PREA
1304[*] https://www.geogroup.com/privacy
1305[*] https://www.geogroup.com/Recent-Corporate-Governance-Events
1306[*] https://www.geogroup.com/Reentry-Services
1307[*] https://www.geogroup.com/Register?returnurl=https://www.geogroup.com/
1308[*] https://www.geogroup.com/Residential_Reentry
1309[*] https://www.geogroup.com/Responsible_Governance
1310[*] https://www.geogroup.com/social_responsibility
1311[*] https://www.geogroup.com/Sustainability
1312[*] https://www.geogroup.com/TermsOfUse
1313[*] https://www.geogroup.com/vendors
1314[*] https://www.geogroup.com/Video_Library
1315[*] https://www.geogroup.com/who_we_are
1316[*] https://www.jointcommission.org/
1317[*] https://www.linkedin.com/company/the-geo-group-inc.
1318[*] https://www.youtube.com/user/TheGEOGroupInc
1319[*] http://www.aca.org/
1320[*] http://www.achs.org.au/
1321[*] http://www.appdevelop.com/
1322[*] http://www.ceanational.org/
1323[*] http://www.iso.org/iso/home.html
1324[*] http://www.ncchc.org/
1325[*] http://www.sacs.org/
1326[INFO] GOOGLE has 1,040,000 results (0.19 seconds) about http://www.geogroup.com/
1327[INFO] BING shows 52.44.246.60 is shared with 14 hosts/vhosts
1328[INFO] Shodan detected the following opened ports on 52.44.246.60:
1329[*] 3389
1330[*] 443
1331[*] 50
1332[*] 80
1333[INFO] ------VirusTotal SECTION------
1334[INFO] VirusTotal passive DNS only stores address records. The following domains resolved to the given IP address:
1335[INFO] Latest URLs hosted in this IP address detected by at least one URL scanner or malicious URL dataset:
1336[INFO] Latest files that are not detected by any antivirus solution and were downloaded by VirusTotal from the IP address provided:
1337[INFO] ------Alexa Rank SECTION------
1338[INFO] Percent of Visitors Rank in Country:
1339[INFO] Percent of Search Traffic:
1340[INFO] Percent of Unique Visits:
1341[INFO] Total Sites Linking In:
1342[*] Total Sites
1343[INFO] Useful links related to www.geogroup.com - 52.44.246.60:
1344[*] https://www.virustotal.com/pt/ip-address/52.44.246.60/information/
1345[*] https://www.hybrid-analysis.com/search?host=52.44.246.60
1346[*] https://www.shodan.io/host/52.44.246.60
1347[*] https://www.senderbase.org/lookup/?search_string=52.44.246.60
1348[*] https://www.alienvault.com/open-threat-exchange/ip/52.44.246.60
1349[*] http://pastebin.com/search?q=52.44.246.60
1350[*] http://urlquery.net/search.php?q=52.44.246.60
1351[*] http://www.alexa.com/siteinfo/www.geogroup.com
1352[*] http://www.google.com/safebrowsing/diagnostic?site=www.geogroup.com
1353[*] https://censys.io/ipv4/52.44.246.60
1354[*] https://www.abuseipdb.com/check/52.44.246.60
1355[*] https://urlscan.io/search/#52.44.246.60
1356[*] https://github.com/search?q=52.44.246.60&type=Code
1357[INFO] Useful links related to AS9044 - 32.0.0.0/3:
1358[*] http://www.google.com/safebrowsing/diagnostic?site=AS:9044
1359[*] https://www.senderbase.org/lookup/?search_string=32.0.0.0/3
1360[*] http://bgp.he.net/AS9044
1361[*] https://stat.ripe.net/AS9044
1362[INFO] Date: 26/07/19 | Time: 00:39:59
1363[INFO] Total time: 1 minute(s) and 48 second(s)
1364######################################################################################################################################
1365Trying "geogroup.com"
1366Trying "geogroup.com"
1367;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 45227
1368;; flags: qr rd ra; QUERY: 1, ANSWER: 17, AUTHORITY: 5, ADDITIONAL: 10
1369
1370;; QUESTION SECTION:
1371;geogroup.com. IN ANY
1372
1373;; ANSWER SECTION:
1374geogroup.com. 1800 IN A 52.44.246.60
1375geogroup.com. 1800 IN MX 10 mxb-00217401.gslb.pphosted.com.
1376geogroup.com. 1800 IN MX 10 mxa-00217401.gslb.pphosted.com.
1377geogroup.com. 3600 IN TXT "ym3PKhWfO+YUn21OOMtNljU+4X2e/LecanP1erOL3OH2VnUhgRMCf5oBL5YrVsmV9EQ0+yh6hY+4YHtjLEPnyA=="
1378geogroup.com. 3600 IN TXT "v=spf1 a include:_spf.google.com include:spf.protection.outlook.com include:spf-00217401.pphosted.com ip4:8.17.112.16 ip4:8.17.112.7 ip4:8.44.244.7 ~all"
1379geogroup.com. 3600 IN TXT "@ MS=ms98706971"
1380geogroup.com. 3600 IN TXT "google-site-verification=u5loptN1DWKjoWSkHGkVllzPvuYBhDSJ3UIi_4yPjWY"
1381geogroup.com. 3600 IN TXT "google-site-verification=mp9Tyd2gAoVpYJzKy5ePt1wH0vQZX8smMbtkZhAkjRQ"
1382geogroup.com. 3600 IN TXT "@ MS=F0C5AEC0E4703A199A9B6F336E7FCAA9F660C2D0"
1383geogroup.com. 3600 IN TXT "globalsign-domain-verification=oiM-PiF7SVVL-ozOu6K60tUBN2RhZGaNrD5GG52ES_"
1384geogroup.com. 1800 IN SPF "v=spf1 a include:_spf.google.com include:spf.protection.outlook.com include:spf-00217401.pphosted.com ip4:8.17.112.16 ip4:8.17.112.7 ip4:8.44.244.7 ~all"
1385geogroup.com. 43200 IN SOA ns0.dnsmadeeasy.com. dns.dnsmadeeasy.com. 2008010345 43200 3600 1209600 180
1386geogroup.com. 43200 IN NS ns2.dnsmadeeasy.com.
1387geogroup.com. 43200 IN NS ns0.dnsmadeeasy.com.
1388geogroup.com. 43200 IN NS ns3.dnsmadeeasy.com.
1389geogroup.com. 43200 IN NS ns4.dnsmadeeasy.com.
1390geogroup.com. 43200 IN NS ns1.dnsmadeeasy.com.
1391
1392;; AUTHORITY SECTION:
1393geogroup.com. 43200 IN NS ns4.dnsmadeeasy.com.
1394geogroup.com. 43200 IN NS ns2.dnsmadeeasy.com.
1395geogroup.com. 43200 IN NS ns3.dnsmadeeasy.com.
1396geogroup.com. 43200 IN NS ns1.dnsmadeeasy.com.
1397geogroup.com. 43200 IN NS ns0.dnsmadeeasy.com.
1398
1399;; ADDITIONAL SECTION:
1400ns0.dnsmadeeasy.com. 6604 IN A 208.94.148.2
1401ns0.dnsmadeeasy.com. 1262 IN AAAA 2600:1800::1
1402ns4.dnsmadeeasy.com. 2568 IN A 208.80.127.2
1403ns4.dnsmadeeasy.com. 2568 IN AAAA 2600:1802:4::1
1404ns2.dnsmadeeasy.com. 2568 IN A 208.80.126.2
1405ns2.dnsmadeeasy.com. 2568 IN AAAA 2600:1802:2::1
1406ns3.dnsmadeeasy.com. 2568 IN A 208.80.125.2
1407ns3.dnsmadeeasy.com. 2568 IN AAAA 2600:1801:3::1
1408ns1.dnsmadeeasy.com. 5748 IN A 208.80.124.2
1409ns1.dnsmadeeasy.com. 2568 IN AAAA 2600:1801:1::1
1410
1411Received 1315 bytes from 2001:18c0:121:6900:724f:b8ff:fefd:5b6a#53 in 60 ms
1412#######################################################################################################################################
1413; <<>> DiG 9.11.5-P4-5.1-Debian <<>> +trace geogroup.com any
1414;; global options: +cmd
1415. 83597 IN NS g.root-servers.net.
1416. 83597 IN NS b.root-servers.net.
1417. 83597 IN NS m.root-servers.net.
1418. 83597 IN NS c.root-servers.net.
1419. 83597 IN NS j.root-servers.net.
1420. 83597 IN NS l.root-servers.net.
1421. 83597 IN NS i.root-servers.net.
1422. 83597 IN NS f.root-servers.net.
1423. 83597 IN NS a.root-servers.net.
1424. 83597 IN NS d.root-servers.net.
1425. 83597 IN NS k.root-servers.net.
1426. 83597 IN NS h.root-servers.net.
1427. 83597 IN NS e.root-servers.net.
1428. 83597 IN RRSIG NS 8 0 518400 20190807210000 20190725200000 59944 . NznCfe9KwduWlDfo5GEJBBnxCH7pKTZqJvZnvIZOAFQfr/n0x32xCLvs Niak9lO2DO+fEXgykzc8jit8nRvtr9EPvNbbFrOr909jRStyC249jZ2B gKVOL1QvZm5mDRgd5RfBmgyUatYzJhZsrWt8w7gdi48/mUoqdKDuxo8+ GPF26+4pDKtoRDbPWMLOYtp1ziHe4NaSTKMWRXTcj+TCkWtPMjTlHm0C BrPUx39F1MixvQoC8SzJT9tzCsTVjuyTStXoukDDUI54shCe+UaFoGSh mU4AwV99OnJN72cL6ihsuxatuMNBsPHTBecnC2M+dBbqm0ZqAAs6euxD fyO+dA==
1429;; Received 525 bytes from 185.93.180.131#53(185.93.180.131) in 222 ms
1430
1431com. 172800 IN NS a.gtld-servers.net.
1432com. 172800 IN NS b.gtld-servers.net.
1433com. 172800 IN NS c.gtld-servers.net.
1434com. 172800 IN NS d.gtld-servers.net.
1435com. 172800 IN NS e.gtld-servers.net.
1436com. 172800 IN NS f.gtld-servers.net.
1437com. 172800 IN NS g.gtld-servers.net.
1438com. 172800 IN NS h.gtld-servers.net.
1439com. 172800 IN NS i.gtld-servers.net.
1440com. 172800 IN NS j.gtld-servers.net.
1441com. 172800 IN NS k.gtld-servers.net.
1442com. 172800 IN NS l.gtld-servers.net.
1443com. 172800 IN NS m.gtld-servers.net.
1444com. 86400 IN DS 30909 8 2 E2D3C916F6DEEAC73294E8268FB5885044A833FC5459588F4A9184CF C41A5766
1445com. 86400 IN RRSIG DS 8 1 86400 20190807210000 20190725200000 59944 . u6pzqDSyqyTi/LoTYorI34h6gn6a9TnlR//BS56iByNQ07fJK2V+HTHY nk5tuxKgGjfYf2BdE0uFi5RTPU/s+J9RdOX/qI0Hz4M+zWKvd/m6AOnY atogSZDlN58h61/M/BEJU/gTlNX4TmR5IJuF8qcKdMrVw4E63HqgNQIc IZ7SGIxXRl4lhDcgROUMTPyG8/EEXlkHDPFxG5kuDqrYBq5o6JAF97M1 wBgEPnSCxGqWPSLSu63XDRCAefCV/u5h8YDs3vTCET2alkkCKunjH68U OU52sRBFnB/RRZTc1OGI4wfbYYJS3VCXwF9A7geaWebbo5hWD5hTgQeU T5brbg==
1446;; Received 1172 bytes from 193.0.14.129#53(k.root-servers.net) in 224 ms
1447
1448geogroup.com. 172800 IN NS ns1.dnsmadeeasy.com.
1449geogroup.com. 172800 IN NS ns4.dnsmadeeasy.com.
1450geogroup.com. 172800 IN NS ns3.dnsmadeeasy.com.
1451geogroup.com. 172800 IN NS ns0.dnsmadeeasy.com.
1452geogroup.com. 172800 IN NS ns2.dnsmadeeasy.com.
1453CK0POJMG874LJREF7EFN8430QVIT8BSM.com. 86400 IN NSEC3 1 1 0 - CK0Q1GIN43N1ARRC9OSM6QPQR81H5M9A NS SOA RRSIG DNSKEY NSEC3PARAM
1454CK0POJMG874LJREF7EFN8430QVIT8BSM.com. 86400 IN RRSIG NSEC3 8 2 86400 20190730044548 20190723033548 17708 com. BUDV3J0MsIIcRoOu1UwTqagANxNEaccvt4U6xn/Jxr21esQqJBb1cbOR kTDYRm1ive/Wx8NUF7P9DoVk7iQGwibJRMmH4C5YXpicgozeRDY7Z9kz RB+NcPRItLn9ZfrfAGPObbalGoWq84gfl2NeYYHvuGVixhYOkKL3QKd4 BoI=
1455G8AORGP0V89G6HNUQ5E42G4FNRG61ONA.com. 86400 IN NSEC3 1 1 0 - G8APNSFAE2AM1NAPGL2E13HOVFH1MQLL NS DS RRSIG
1456G8AORGP0V89G6HNUQ5E42G4FNRG61ONA.com. 86400 IN RRSIG NSEC3 8 2 86400 20190731053903 20190724042903 17708 com. z1S9TN2DjAm/9AdmrULE8KloG42nwelKhFmbUvVlfgVPMhjY4xJ4QHgm smHPTTExNxSFEQHMJaEiQTsCurkgmKBVenAfhlppIaD1IRHb+VeqMYjV vPYze+qsBS7fUfWo2E0pp5gTX6uybwfLpsi/RU0iUsyfNyzktP7oNqye nmE=
1457;; Received 848 bytes from 2001:500:856e::30#53(d.gtld-servers.net) in 63 ms
1458
1459geogroup.com. 86400 IN SOA ns0.dnsmadeeasy.com. dns.dnsmadeeasy.com. 2008010345 43200 3600 1209600 180
1460geogroup.com. 1800 IN SPF "v=spf1 a include:_spf.google.com include:spf.protection.outlook.com include:spf-00217401.pphosted.com ip4:8.17.112.16 ip4:8.17.112.7 ip4:8.44.244.7 ~all"
1461geogroup.com. 3600 IN TXT "v=spf1 a include:_spf.google.com include:spf.protection.outlook.com include:spf-00217401.pphosted.com ip4:8.17.112.16 ip4:8.17.112.7 ip4:8.44.244.7 ~all"
1462geogroup.com. 3600 IN TXT "globalsign-domain-verification=oiM-PiF7SVVL-ozOu6K60tUBN2RhZGaNrD5GG52ES_"
1463geogroup.com. 3600 IN TXT "@ MS=ms98706971"
1464geogroup.com. 3600 IN TXT "ym3PKhWfO+YUn21OOMtNljU+4X2e/LecanP1erOL3OH2VnUhgRMCf5oBL5YrVsmV9EQ0+yh6hY+4YHtjLEPnyA=="
1465geogroup.com. 3600 IN TXT "@ MS=F0C5AEC0E4703A199A9B6F336E7FCAA9F660C2D0"
1466geogroup.com. 3600 IN TXT "google-site-verification=mp9Tyd2gAoVpYJzKy5ePt1wH0vQZX8smMbtkZhAkjRQ"
1467geogroup.com. 3600 IN TXT "google-site-verification=u5loptN1DWKjoWSkHGkVllzPvuYBhDSJ3UIi_4yPjWY"
1468geogroup.com. 1800 IN MX 10 mxa-00217401.gslb.pphosted.com.
1469geogroup.com. 1800 IN MX 10 mxb-00217401.gslb.pphosted.com.
1470geogroup.com. 1800 IN A 52.44.246.60
1471geogroup.com. 86400 IN NS ns3.dnsmadeeasy.com.
1472geogroup.com. 86400 IN NS ns0.dnsmadeeasy.com.
1473geogroup.com. 86400 IN NS ns2.dnsmadeeasy.com.
1474geogroup.com. 86400 IN NS ns1.dnsmadeeasy.com.
1475geogroup.com. 86400 IN NS ns4.dnsmadeeasy.com.
1476;; Received 1036 bytes from 2600:1801:3::1#53(ns3.dnsmadeeasy.com) in 40 ms
1477#######################################################################################################################################
1478[*] Processing domain geogroup.com
1479[*] Using system resolvers ['185.93.180.131', '194.187.251.67', '38.132.106.139', '192.168.0.1', '2001:18c0:121:6900:724f:b8ff:fefd:5b6a']
1480[+] Getting nameservers
1481208.80.125.2 - ns3.dnsmadeeasy.com
1482208.94.148.2 - ns0.dnsmadeeasy.com
1483208.80.126.2 - ns2.dnsmadeeasy.com
1484208.80.127.2 - ns4.dnsmadeeasy.com
1485208.80.124.2 - ns1.dnsmadeeasy.com
1486[-] Zone transfer failed
1487
1488[+] TXT records found
1489"ym3PKhWfO+YUn21OOMtNljU+4X2e/LecanP1erOL3OH2VnUhgRMCf5oBL5YrVsmV9EQ0+yh6hY+4YHtjLEPnyA=="
1490"@ MS=F0C5AEC0E4703A199A9B6F336E7FCAA9F660C2D0"
1491"globalsign-domain-verification=oiM-PiF7SVVL-ozOu6K60tUBN2RhZGaNrD5GG52ES_"
1492"google-site-verification=mp9Tyd2gAoVpYJzKy5ePt1wH0vQZX8smMbtkZhAkjRQ"
1493"google-site-verification=u5loptN1DWKjoWSkHGkVllzPvuYBhDSJ3UIi_4yPjWY"
1494"@ MS=ms98706971"
1495"v=spf1 a include:_spf.google.com include:spf.protection.outlook.com include:spf-00217401.pphosted.com ip4:8.17.112.16 ip4:8.17.112.7 ip4:8.44.244.7 ~all"
1496
1497[+] MX records found, added to target list
149810 mxb-00217401.gslb.pphosted.com.
149910 mxa-00217401.gslb.pphosted.com.
1500
1501[*] Scanning geogroup.com for A records
150252.44.246.60 - geogroup.com
15038.17.112.15 - apps.geogroup.com
150440.101.138.24 - autodiscover.geogroup.com
150552.97.150.8 - autodiscover.geogroup.com
150640.101.136.8 - autodiscover.geogroup.com
150740.101.137.56 - autodiscover.geogroup.com
1508216.58.207.51 - calendar.geogroup.com
1509172.217.16.211 - docs.geogroup.com
151052.169.9.87 - enterpriseenrollment.geogroup.com
151151.144.73.160 - enterpriseregistration.geogroup.com
151274.11.166.30 - jabber.geogroup.com
151313.224.227.112 - jobs.geogroup.com
151413.224.227.32 - jobs.geogroup.com
151513.224.227.121 - jobs.geogroup.com
151613.224.227.90 - jobs.geogroup.com
151752.112.194.78 - lyncdiscover.geogroup.com
15188.17.112.16 - mail.geogroup.com
15198.17.112.16 - mail2.geogroup.com
152065.79.174.231 - mail3.geogroup.com
152140.126.1.166 - msoid.geogroup.com
152220.190.129.160 - msoid.geogroup.com
152340.126.1.130 - msoid.geogroup.com
152420.190.129.2 - msoid.geogroup.com
152540.126.1.128 - msoid.geogroup.com
15268.17.112.25 - portal.geogroup.com
15278.44.244.30 - remote.geogroup.com
152852.112.192.11 - sip.geogroup.com
1529216.58.207.51 - sites.geogroup.com
153052.70.15.23 - team.geogroup.com
153152.1.186.30 - team.geogroup.com
153274.11.166.23 - video.geogroup.com
15338.44.244.7 - vpn.geogroup.com
15348.44.244.7 - vpn2.geogroup.com
15354.34.51.229 - vpn3.geogroup.com
15368.17.112.17 - webmail.geogroup.com
153752.44.246.60 - www.geogroup.com
1538######################################################################################################################################
1539
1540
1541
1542 AVAILABLE PLUGINS
1543 -----------------
1544
1545 RobotPlugin
1546 CompressionPlugin
1547 HttpHeadersPlugin
1548 FallbackScsvPlugin
1549 OpenSslCcsInjectionPlugin
1550 SessionRenegotiationPlugin
1551 EarlyDataPlugin
1552 SessionResumptionPlugin
1553 CertificateInfoPlugin
1554 HeartbleedPlugin
1555 OpenSslCipherSuitesPlugin
1556
1557
1558
1559 CHECKING HOST(S) AVAILABILITY
1560 -----------------------------
1561
1562 52.44.246.60:443 => 52.44.246.60
1563
1564
1565
1566
1567 SCAN RESULTS FOR 52.44.246.60:443 - 52.44.246.60
1568 ------------------------------------------------
1569
1570 * OpenSSL Heartbleed:
1571 OK - Not vulnerable to Heartbleed
1572
1573 * OpenSSL CCS Injection:
1574 OK - Not vulnerable to OpenSSL CCS injection
1575
1576 * ROBOT Attack:
1577 OK - Not vulnerable
1578
1579 * Deflate Compression:
1580 OK - Compression disabled
1581
1582 * TLSV1_1 Cipher Suites:
1583 Forward Secrecy OK - Supported
1584 RC4 INSECURE - Supported
1585
1586 Preferred:
1587 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA 256 bits HTTP 200 OK
1588 Accepted:
1589 TLS_RSA_WITH_RC4_128_SHA 128 bits HTTP 200 OK
1590 TLS_RSA_WITH_RC4_128_MD5 128 bits HTTP 200 OK
1591 TLS_RSA_WITH_AES_256_CBC_SHA 256 bits HTTP 200 OK
1592 TLS_RSA_WITH_AES_128_CBC_SHA 128 bits HTTP 200 OK
1593 TLS_RSA_WITH_3DES_EDE_CBC_SHA 112 bits HTTP 200 OK
1594 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA 256 bits HTTP 200 OK
1595 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA 128 bits HTTP 200 OK
1596 TLS_DHE_RSA_WITH_AES_256_CBC_SHA 256 bits HTTP 200 OK
1597 TLS_DHE_RSA_WITH_AES_128_CBC_SHA 128 bits HTTP 200 OK
1598
1599 * TLSV1 Cipher Suites:
1600 Forward Secrecy OK - Supported
1601 RC4 INSECURE - Supported
1602
1603 Preferred:
1604 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA 256 bits HTTP 200 OK
1605 Accepted:
1606 TLS_RSA_WITH_RC4_128_SHA 128 bits HTTP 200 OK
1607 TLS_RSA_WITH_RC4_128_MD5 128 bits HTTP 200 OK
1608 TLS_RSA_WITH_AES_256_CBC_SHA 256 bits HTTP 200 OK
1609 TLS_RSA_WITH_AES_128_CBC_SHA 128 bits HTTP 200 OK
1610 TLS_RSA_WITH_3DES_EDE_CBC_SHA 112 bits HTTP 200 OK
1611 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA 256 bits HTTP 200 OK
1612 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA 128 bits HTTP 200 OK
1613 TLS_DHE_RSA_WITH_AES_256_CBC_SHA 256 bits HTTP 200 OK
1614 TLS_DHE_RSA_WITH_AES_128_CBC_SHA 128 bits HTTP 200 OK
1615
1616 * SSLV2 Cipher Suites:
1617 Server rejected all cipher suites.
1618
1619 * Downgrade Attacks:
1620 TLS_FALLBACK_SCSV: VULNERABLE - Signaling cipher suite not supported
1621
1622 * TLS 1.2 Session Resumption Support:
1623 With Session IDs: OK - Supported (5 successful, 0 failed, 0 errors, 5 total attempts).
1624 With TLS Tickets: NOT SUPPORTED - TLS ticket not assigned.
1625
1626 * Session Renegotiation:
1627 Client-initiated Renegotiation: OK - Rejected
1628 Secure Renegotiation: OK - Supported
1629
1630 * TLSV1_3 Cipher Suites:
1631 Server rejected all cipher suites.
1632
1633 * Certificate Information:
1634 Content
1635 SHA1 Fingerprint: 470bedad3401d588b33eae78059b875438bf0bdb
1636 Common Name: www.geogroup.com
1637 Issuer: Go Daddy Secure Certificate Authority - G2
1638 Serial Number: 6051074336821723073
1639 Not Before: 2018-02-20 04:17:01
1640 Not After: 2020-02-16 21:05:00
1641 Signature Algorithm: sha256
1642 Public Key Algorithm: RSA
1643 Key Size: 2048
1644 Exponent: 65537 (0x10001)
1645 DNS Subject Alternative Names: ['www.geogroup.com', 'geogroup.com']
1646
1647 Trust
1648 Hostname Validation: FAILED - Certificate does NOT match 52.44.246.60
1649 Android CA Store (9.0.0_r9): OK - Certificate is trusted
1650 iOS CA Store (12, macOS 10.14, watchOS 5, and tvOS 12):OK - Certificate is trusted
1651 Java CA Store (jdk-11.0.2): OK - Certificate is trusted
1652 macOS CA Store (12, macOS 10.14, watchOS 5, and tvOS 12):OK - Certificate is trusted
1653 Mozilla CA Store (2018-11-22): OK - Certificate is trusted, Extended Validation
1654 OPENJDK CA Store (jdk-11.0.2): OK - Certificate is trusted
1655 Windows CA Store (2018-12-08): OK - Certificate is trusted
1656 Symantec 2018 Deprecation: OK - Not a Symantec-issued certificate
1657 Received Chain: www.geogroup.com --> Go Daddy Secure Certificate Authority - G2
1658 Verified Chain: www.geogroup.com --> Go Daddy Secure Certificate Authority - G2 --> Go Daddy Root Certificate Authority - G2
1659 Received Chain Contains Anchor: OK - Anchor certificate not sent
1660 Received Chain Order: OK - Order is valid
1661 Verified Chain contains SHA1: OK - No SHA1-signed certificate in the verified certificate chain
1662
1663 Extensions
1664 OCSP Must-Staple: NOT SUPPORTED - Extension not found
1665 Certificate Transparency: OK - 3 SCTs included
1666
1667 OCSP Stapling
1668 OCSP Response Status: successful
1669 Validation w/ Mozilla Store: OK - Response is trusted
1670 Responder Id: C = US, ST = Arizona, L = Scottsdale, O = GoDaddy Inc., CN = Go Daddy Validation Authority - G2
1671 Cert Status: good
1672 Cert Serial Number: 53F9BC0CA3BDBFC1
1673 This Update: Jul 25 14:48:40 2019 GMT
1674 Next Update: Jul 27 02:48:40 2019 GMT
1675
1676 * SSLV3 Cipher Suites:
1677 Forward Secrecy INSECURE - Not Supported
1678 RC4 INSECURE - Supported
1679
1680 Preferred:
1681 TLS_RSA_WITH_3DES_EDE_CBC_SHA 112 bits HTTP 200 OK
1682 Accepted:
1683 TLS_RSA_WITH_RC4_128_SHA 128 bits HTTP 200 OK
1684 TLS_RSA_WITH_RC4_128_MD5 128 bits HTTP 200 OK
1685 TLS_RSA_WITH_3DES_EDE_CBC_SHA 112 bits HTTP 200 OK
1686
1687 * TLSV1_2 Cipher Suites:
1688 Forward Secrecy OK - Supported
1689 RC4 INSECURE - Supported
1690
1691 Preferred:
1692 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 256 bits HTTP 200 OK
1693 Accepted:
1694 TLS_RSA_WITH_RC4_128_SHA 128 bits HTTP 200 OK
1695 TLS_RSA_WITH_RC4_128_MD5 128 bits HTTP 200 OK
1696 TLS_RSA_WITH_AES_256_GCM_SHA384 256 bits HTTP 200 OK
1697 TLS_RSA_WITH_AES_256_CBC_SHA256 256 bits HTTP 200 OK
1698 TLS_RSA_WITH_AES_256_CBC_SHA 256 bits HTTP 200 OK
1699 TLS_RSA_WITH_AES_128_GCM_SHA256 128 bits HTTP 200 OK
1700 TLS_RSA_WITH_AES_128_CBC_SHA256 128 bits HTTP 200 OK
1701 TLS_RSA_WITH_AES_128_CBC_SHA 128 bits HTTP 200 OK
1702 TLS_RSA_WITH_3DES_EDE_CBC_SHA 112 bits HTTP 200 OK
1703 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 256 bits HTTP 200 OK
1704 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA 256 bits HTTP 200 OK
1705 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 128 bits HTTP 200 OK
1706 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA 128 bits HTTP 200 OK
1707 TLS_DHE_RSA_WITH_AES_256_GCM_SHA384 256 bits HTTP 200 OK
1708 TLS_DHE_RSA_WITH_AES_256_CBC_SHA 256 bits HTTP 200 OK
1709 TLS_DHE_RSA_WITH_AES_128_GCM_SHA256 128 bits HTTP 200 OK
1710 TLS_DHE_RSA_WITH_AES_128_CBC_SHA 128 bits HTTP 200 OK
1711
1712
1713 SCAN COMPLETED IN 33.22 S
1714 -------------------------
1715######################################################################################################################################
1716Starting Nmap 7.70 ( https://nmap.org ) at 2019-07-26 00:42 EDT
1717Nmap scan report for ec2-52-44-246-60.compute-1.amazonaws.com (52.44.246.60)
1718Host is up (0.27s latency).
1719Not shown: 470 filtered ports, 3 closed ports
1720Some closed ports may be reported as filtered due to --defeat-rst-ratelimit
1721PORT STATE SERVICE
172280/tcp open http
1723443/tcp open https
17243389/tcp open ms-wbt-server
1725######################################################################################################################################
1726Starting Nmap 7.70 ( https://nmap.org ) at 2019-07-26 00:42 EDT
1727Nmap scan report for ec2-52-44-246-60.compute-1.amazonaws.com (52.44.246.60)
1728Host is up (0.16s latency).
1729Not shown: 2 filtered ports
1730PORT STATE SERVICE
173153/udp open|filtered domain
173267/udp open|filtered dhcps
173368/udp open|filtered dhcpc
173469/udp open|filtered tftp
173588/udp open|filtered kerberos-sec
1736123/udp open|filtered ntp
1737139/udp open|filtered netbios-ssn
1738161/udp open|filtered snmp
1739162/udp open|filtered snmptrap
1740389/udp open|filtered ldap
1741520/udp open|filtered route
17422049/udp open|filtered nfs
1743######################################################################################################################################
1744Starting Nmap 7.70 ( https://nmap.org ) at 2019-07-26 00:42 EDT
1745Nmap scan report for ec2-52-44-246-60.compute-1.amazonaws.com (52.44.246.60)
1746Host is up.
1747
1748PORT STATE SERVICE VERSION
174967/udp open|filtered dhcps
1750|_dhcp-discover: ERROR: Script execution failed (use -d to debug)
1751Too many fingerprints match this host to give specific OS details
1752
1753TRACEROUTE (using proto 1/icmp)
1754HOP RTT ADDRESS
17551 170.66 ms 10.250.200.1
17562 172.05 ms 213.184.122.97
17573 170.85 ms bzq-82-80-246-9.cablep.bezeqint.net (82.80.246.9)
17584 232.52 ms bzq-219-189-185.cablep.bezeqint.net (62.219.189.185)
17595 171.27 ms bzq-114-65-2.cust.bezeqint.net (192.114.65.2)
17606 171.28 ms bzq-179-124-82.cust.bezeqint.net (212.179.124.82)
17617 226.54 ms bzq-179-124-118.cust.bezeqint.net (212.179.124.118)
17628 231.96 ms ae9.cr1-lon2.ip4.gtt.net (46.33.89.185)
17639 288.96 ms et-10-3-0.cr4-nyc2.ip4.gtt.net (213.254.214.10)
176410 288.82 ms a100-gw.ip4.gtt.net (173.205.58.70)
176511 296.16 ms 52.93.1.89
176612 289.50 ms 52.93.1.56
176713 ... 17
176818 297.82 ms 72.21.222.229
176919 ... 28
177029 295.62 ms 52.93.28.184
177130 ...
1772#######################################################################################################################################
1773Starting Nmap 7.70 ( https://nmap.org ) at 2019-07-26 00:44 EDT
1774Nmap scan report for ec2-52-44-246-60.compute-1.amazonaws.com (52.44.246.60)
1775Host is up.
1776
1777PORT STATE SERVICE VERSION
177868/udp open|filtered dhcpc
1779Too many fingerprints match this host to give specific OS details
1780
1781TRACEROUTE (using proto 1/icmp)
1782HOP RTT ADDRESS
17831 169.67 ms 10.250.200.1
17842 166.16 ms 213.184.122.97
17853 165.05 ms bzq-82-80-246-9.cablep.bezeqint.net (82.80.246.9)
17864 226.89 ms bzq-219-189-185.cablep.bezeqint.net (62.219.189.185)
17875 165.35 ms bzq-114-65-2.cust.bezeqint.net (192.114.65.2)
17886 165.37 ms bzq-179-124-82.cust.bezeqint.net (212.179.124.82)
17897 227.51 ms bzq-179-124-118.cust.bezeqint.net (212.179.124.118)
17908 220.60 ms ae9.cr1-lon2.ip4.gtt.net (46.33.89.185)
17919 288.74 ms et-10-3-0.cr4-nyc2.ip4.gtt.net (213.254.214.10)
179210 288.99 ms a100-gw.ip4.gtt.net (173.205.58.70)
179311 292.00 ms 52.93.1.89
179412 289.21 ms 52.93.1.56
179513 ... 17
179618 293.80 ms 72.21.222.229
179719 ... 28
179829 297.56 ms 52.93.28.184
179930 ...
1800######################################################################################################################################
1801Starting Nmap 7.70 ( https://nmap.org ) at 2019-07-26 00:46 EDT
1802Nmap scan report for ec2-52-44-246-60.compute-1.amazonaws.com (52.44.246.60)
1803Host is up.
1804
1805PORT STATE SERVICE VERSION
180669/udp open|filtered tftp
1807Too many fingerprints match this host to give specific OS details
1808
1809TRACEROUTE (using proto 1/icmp)
1810HOP RTT ADDRESS
18111 166.27 ms 10.250.200.1
18122 167.50 ms 213.184.122.97
18133 167.68 ms bzq-82-80-246-9.cablep.bezeqint.net (82.80.246.9)
18144 228.64 ms bzq-219-189-185.cablep.bezeqint.net (62.219.189.185)
18155 166.91 ms bzq-114-65-2.cust.bezeqint.net (192.114.65.2)
18166 167.12 ms bzq-179-124-82.cust.bezeqint.net (212.179.124.82)
18177 228.70 ms bzq-179-124-118.cust.bezeqint.net (212.179.124.118)
18188 222.94 ms ae9.cr1-lon2.ip4.gtt.net (46.33.89.185)
18199 290.39 ms et-10-3-0.cr4-nyc2.ip4.gtt.net (213.254.214.10)
182010 290.48 ms a100-gw.ip4.gtt.net (173.205.58.70)
182111 300.19 ms 52.93.1.89
182212 293.72 ms 52.93.1.56
182313 ... 17
182418 299.71 ms 72.21.222.229
182519 ... 28
182629 299.32 ms 52.93.28.184
182730 ...
1828######################################################################################################################################
1829Starting Nmap 7.70 ( https://nmap.org ) at 2019-07-26 00:48 EDT
1830Nmap scan report for ec2-52-44-246-60.compute-1.amazonaws.com (52.44.246.60)
1831Host is up (0.28s latency).
1832
1833PORT STATE SERVICE VERSION
183480/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
1835|_http-server-header: Microsoft-HTTPAPI/2.0
1836| vulscan: VulDB - https://vuldb.com:
1837| [131683] Microsoft Windows 7 SP1/Server 2008 SP2/Server 2008 R2 SP1 Win32k memory corruption
1838| [131642] Microsoft Windows 7 SP1/Server 2008 SP2/Server 2008 R2 SP1 Active Directory privilege escalation
1839| [127822] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2012 Kernel information disclosure
1840| [125103] Microsoft Windows Server 2008 SP2 Graphics Component information disclosure
1841| [123853] Microsoft Windows 7 SP1/Server 2008 SP2/Server 2008 R2 SP1 Kernel Memory information disclosure
1842| [122858] Microsoft Windows 7 SP1/Server 2008 SP2/Server 2008 R2 SP1 LNK memory corruption
1843| [122833] Microsoft Windows 7 SP1/Server 2008 SP2/Server 2008 R2 SP1 GDI+ memory corruption
1844| [121109] Microsoft Wireless Display Adapter V2 2.0.8350/2.0.8365/2.0.8372 privilege escalation
1845| [120449] Microsoft Forefront Unified Access Gateway 2000 InitParams.aspx Parameter Server-Side Request Forgery
1846| [119469] Microsoft Windows 7 SP1/Server 2008 SP2/Server 2008 R2 SP1 Kernel privilege escalation
1847| [116015] Microsoft Excel 2007 SP3/2010 SP2/2013 SP1/2013 RT SP1 memory corruption
1848| [114563] Microsoft Office 2007 SP3/2010 SP2/2013/2013 RT SP1 memory corruption
1849| [114528] Microsoft Windows 7 SP1/Server 2008 SP2/Server 2008 R2 SP1 GDI privilege escalation
1850| [114524] Microsoft ASP.NET Core 2.0 denial of service
1851| [114523] Microsoft ASP.NET Core 2.0 Kestrel Web Application privilege escalation
1852| [113257] Microsoft Windows 7 SP1/Server 2008 SP2/Server 2012 Kernel information disclosure
1853| [113256] Microsoft Windows 7 SP1/Server 2008 SP2/Server 2012 Kernel information disclosure
1854| [113255] Microsoft Windows 7 SP1/Server 2008 SP2/Server 2012 Kernel information disclosure
1855| [113247] Microsoft Windows 7 SP1/Server 2008 R2 SP1 EOT Font Engine information disclosure
1856| [113246] Microsoft Windows 7 SP1/Server 2008 R2 SP1 EOT Font Engine information disclosure
1857| [113245] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2012 EOT Font Engine information disclosure
1858| [113244] Microsoft Windows 7 SP1/Server 2008 R2 SP1 EOT Font Engine information disclosure
1859| [113235] Microsoft Outlook 2007 SP3/2010 SP2/2013 SP1/2016 privilege escalation
1860| [113234] Microsoft Office 2007 SP2/2010 SP2/2013 SP1/2013 RT SP1/2016 memory corruption
1861| [113216] Microsoft Outlook 2007 SP3/2010 SP2/2013 SP1/2013 RT SP1/2016 memory corruption
1862| [112285] Microsoft Word 2003/2007/2010/2013/2016 Equation Editor memory corruption
1863| [112284] Microsoft Word 2003/2007/2010/2013/2016 Equation Editor memory corruption
1864| [112283] Microsoft Word 2003/2007/2010/2013/2016 Equation Editor memory corruption
1865| [112282] Microsoft Word 2003/2007/2010/2013/2016 Equation Editor memory corruption
1866| [111578] Microsoft Word 2003/2007/2010/2013/2016 Equation Editor memory corruption
1867| [111577] Microsoft Word 2003/2007/2010/2013/2016 Equation Editor memory corruption
1868| [111576] Microsoft Word 2003/2007/2010/2013/2016 Equation Editor memory corruption
1869| [111575] Microsoft Word 2003/2007/2010/2013/2016 Equation Editor memory corruption
1870| [111574] Microsoft Word 2003/2007/2010/2013/2016 Equation Editor memory corruption
1871| [111573] Microsoft Office 2007/2010/2013/2016 Equation Editor memory corruption
1872| [111572] Microsoft Office 2007/2010/2013/2016 Equation Editor memory corruption
1873| [111570] Microsoft Office 2007/2010/2013/2016 Equation Editor memory corruption
1874| [111568] Microsoft Excel 2007/2010/2013/2016 memory corruption
1875| [111566] Microsoft Word 2007/2010/2013/2016 memory corruption
1876| [111565] Microsoft Word 2007/2010/2013 Email Message memory corruption
1877| [111563] Microsoft Outlook 2007/2010/2013/2016 Email Message privilege escalation
1878| [111347] Microsoft Windows 7 SP1/Server 2008 SP2/Server 2008 R2 SP1 Color Management Icm32.dll information disclosure
1879| [109388] Microsoft Office 2007 SP3/2010 SP2/2013 SP1/2016 memory corruption
1880| [109387] Microsoft ASP.NET Core 2.0 privilege escalation
1881| [109386] Microsoft Excel 2007 SP3/2010 SP2/2013 SP1/2013 RT SP1/2016 memory corruption
1882| [109385] Microsoft Excel 2007 SP3/2010 SP2/2013 SP1/2013 RT SP1/2016 Security Feature Macro privilege escalation
1883| [109381] Microsoft Office/Word 2007 SP3/2010 SP2 memory corruption
1884| [107703] Microsoft Office 2007 SP3/2010 SP2/2013 SP1/2013 RT SP1/2016 memory corruption
1885| [106530] Microsoft Excel 2007 SP3/2010 SP2/2013 SP1/2013 RT SP1/2016 memory corruption
1886| [106528] Microsoft PowerPoint 2007 SP3/2010 SP2/2013 SP1/2013 RT SP1/2016 memory corruption
1887| [106515] Microsoft Publisher 2007 SP3/2010 SP2 memory corruption
1888| [106497] Microsoft Windows 7 SP1/Server 2008 SP2/Server 2008 R2 SP1 Uniscribe memory corruption
1889| [106476] Microsoft Excel 2007 SP3/2010 SP2/2013 SP1/2013 RT SP1/2016 memory corruption
1890| [106475] Microsoft Excel 2007 SP3/2010 SP2/2013 SP1/2013 RT SP1/2016 memory corruption
1891| [105051] Microsoft Windows 7 SP1/Server 2008 SP2/Server 2008 R2 SP1 Font Library privilege escalation
1892| [105032] Microsoft Internet Explorer 9/10 on Server 2008/Server 2012 memory corruption
1893| [102513] Microsoft Windows XP SP3/Server 2003 SP2 OLE olecnv32.dll privilege escalation
1894| [102512] Microsoft Windows XP SP3/Server 2003 SP2 rpc privilege escalation
1895| [102511] Microsoft Windows XP SP3/Server 2003 SP2 RDP EsteemAudit privilege escalation
1896| [102447] Microsoft PowerPoint/SharePoint Server 2007 SP3 privilege escalation
1897| [102444] Microsoft Office 2007 SP3/2010 SP2/2013 SP1/2013 RT SP1/2016 privilege escalation
1898| [102442] Microsoft Outlook 2007 SP3/2010 SP2/2013 SP1/2013 RT SP1/2016 Bypass privilege escalation
1899| [102441] Microsoft Outlook 2007 SP3/2010 SP2/2013 SP1/2013 RT SP1/2016 memory corruption
1900| [102401] Microsoft Windows 7 SP1/Server 2008 R2 SP1 GDI USP10!NextCharInLiga Uniscribe Font information disclosure
1901| [101491] Microsoft Windows up to XP SP3/Server 2003 SP2 Remote Desktop Protocol gpkcsp.dll memory corruption
1902| [101017] Microsoft Office 2007 SP3/2010 SP2/2016 memory corruption
1903| [101012] Microsoft Office 2007 SP3/2010 SP2/2011/2013 SP1/2016 memory corruption
1904| [101011] Microsoft Windows 7 SP1/Server 2008 SP2/Server 2008 R2 SP1 ActiveX Object Memory memory corruption
1905| [100854] Microsoft Windows Server 2003 SP2 RRAS ERRATICGOPHER memory corruption
1906| [99904] Microsoft Windows XP SP3/Server 2003 SP2 SmartCard Authentication RDP Packet EsteemAudit privilege escalation
1907| [99698] Microsoft OneNote 2007 SP3/2010 SP2 DLL Loader privilege escalation
1908| [99684] Microsoft Excel 2007 SP3/2010 SP2 Memory information disclosure
1909| [99654] Microsoft Outlook 2007 SP3/2010 SP2/2011/2013 SP1/2016 Email Message privilege escalation
1910| [99653] Microsoft Outlook 2007 SP3/2010 SP2/2011/2013 SP1/2016 Email Message privilege escalation
1911| [99533] Microsoft Office 2007/2010/2013/2016 RTF Document Necurs Dridex memory corruption
1912| [98561] Microsoft IIS 6.0 on Windows Server 2003 WebDAV ScStoragePathFromUrl Long Header memory corruption
1913| [98092] Microsoft SharePoint Server 2007 SP3 memory corruption
1914| [98088] Microsoft SharePoint Server 2007 SP3 memory corruption
1915| [98087] Microsoft Office 2007 SP3/2010 SP2 memory corruption
1916| [98086] Microsoft Office 2007 SP3/2010 SP2/2013 SP1/2013 RT SP1/2016 memory corruption
1917| [98085] Microsoft Excel 2007 SP3 memory corruption
1918| [98084] Microsoft Word 2007 SP3/2010 SP2/2011 memory corruption
1919| [98083] Microsoft Word 2007 SP3/2010 SP2/2011 memory corruption
1920| [98078] Microsoft Word/Excel 2007 SP3 memory corruption
1921| [98072] Microsoft Office 2007 SP3/2010 SP2/Word Viewer Graphics Component privilege escalation
1922| [98071] Microsoft Office 2007 SP3/2010 SP2/Word Viewer GDI+ information disclosure
1923| [98070] Microsoft Office 2007 SP3/2010 SP2/Word Viewer GDI+ information disclosure
1924| [94450] Microsoft Office 2007 SP3/2010 SP2/2011 memory corruption
1925| [94449] Microsoft Office 2007 SP3/2010 SP2/2011/2013 SP1 information disclosure
1926| [94448] Microsoft Office 2007 SP3/2010 SP2/2011/2013 SP1 information disclosure
1927| [94445] Microsoft Office 2007 SP3/2010 SP2/2013 SP1/2013 RT SP1 information disclosure
1928| [94441] Microsoft Office 2007 SP3/2010 SP2/2013 SP1/2013 RT SP1/2016 privilege escalation
1929| [94440] Microsoft Office 2007 SP3/2010 SP2/2013 SP1/2013 RT SP1/2016 memory corruption
1930| [94439] Microsoft Office 2007 SP3/2011 privilege escalation
1931| [94438] Microsoft Office 2007 SP3/2010 SP2/2013 SP1/2013 RT SP1/2016 privilege escalation
1932| [93542] Microsoft Office 2007 SP3/2010 SP2/2013 SP1/2013 RT SP1 memory corruption
1933| [93541] Microsoft Office 2007 SP3 denial of service
1934| [93539] Microsoft Office 2007/2010 SP2/2011 memory corruption
1935| [93538] Microsoft Office 2007/2010 SP2/2011/2013 SP1 memory corruption
1936| [93537] Microsoft Office 2007/2010 SP2/2011 memory corruption
1937| [93396] Microsoft Office 2007/2010/2011 memory corruption
1938| [93395] Microsoft Office 2007/2010/2011 memory corruption
1939| [93394] Microsoft Office 2007/2010 memory corruption
1940| [92596] Microsoft Windows Vista SP2/7 SP1/Server 2008 SP2/Server 2008 R2 Internet Messaging API File information disclosure
1941| [91554] Microsoft Exchange 2007/2010/2013/2016 Email information disclosure
1942| [91553] Microsoft Office 2007/2010/2013/2013 RT/2016 memory corruption
1943| [91552] Microsoft Office 2007/2010/2013/2013 RT/2016 spoofing
1944| [91551] Microsoft Office 2007/2010/2013/2013 RT/2016 memory corruption
1945| [91549] Microsoft Office 2007/2010/2013/2013 RT/2016 memory corruption
1946| [91548] Microsoft Office 2007/2010/2013/2013 RT/2016 memory corruption
1947| [91546] Microsoft Office 2007/2010/2013/2013 RT memory corruption
1948| [91545] Microsoft Office 2007/2010 memory corruption
1949| [91544] Microsoft Office 2007/2010/2013/2013 RT/2016 memory corruption
1950| [91542] Microsoft Office 2007/2010/2013/2013 RT/2016 information disclosure
1951| [90707] Microsoft OneNote 2007/2010/2013/2013 RT/2016 information disclosure
1952| [90706] Microsoft Office 2007/2010/2013/2013 RT Graphics memory corruption
1953| [90705] Microsoft Office 2007/2010/2011 memory corruption
1954| [90703] Microsoft Office 2007/2010/2013/2013 RT/2016 memory corruption
1955| [89039] Microsoft Office 2007 SP3/2010 SP2/2011/2013 SP1/2013 RT SP1 memory corruption
1956| [89034] Microsoft Windows Vista SP2/Server 2008 JScript/VBScript memory corruption
1957| [87960] Microsoft Windows Server 2008 R2/Server 2012/Server 2012 R2 Active Directory denial of service
1958| [87955] Microsoft Exchange 2007/2010/2013/2016 Oracle Outside In Libraries privilege escalation
1959| [87954] Microsoft Exchange 2007/2010/2013/2016 Oracle Outside In Libraries privilege escalation
1960| [87953] Microsoft Exchange 2007/2010/2013/2016 Oracle Outside In Libraries privilege escalation
1961| [87939] Microsoft Office 2007 SP3/2010 SP2/2013 SP1/2013 RT SP1/2016 OLE DLL memory corruption
1962| [87938] Microsoft Office 2007 SP3/2010 SP2/2011 information disclosure
1963| [87937] Microsoft Office 2007 SP3/2010 SP2/2011 memory corruption
1964| [87935] Microsoft Windows Vista SP2/Server 2008 SP2/Server 2008 R2 SP1 VBScript/JScript memory corruption
1965| [87934] Microsoft Windows Vista SP2/Server 2008 SP2/Server 2008 R2 SP1 VBScript/JScript memory corruption
1966| [87933] Microsoft Windows Vista SP2/Server 2008 SP2/Server 2008 R2 SP1 VBScript/JScript memory corruption
1967| [87147] Microsoft Office 2007/2010 memory corruption
1968| [87145] Microsoft Windows Vista SP2/Server 2008 JScript/VBScript memory corruption
1969| [87144] Microsoft Windows Vista SP2/Server 2008 JScript/VBScript memory corruption
1970| [82228] Microsoft Excel 2007 SP3/2010 SP2 Office Document memory corruption
1971| [82225] Microsoft Word 2007 SP3/2010 SP2/2013 SP1/2013 RT SP1 Office Document memory corruption
1972| [82224] Microsoft Excel 2007 SP3/2010 SP2/2013 SP1/2013 RT SP1/2016 Office Document memory corruption
1973| [81273] Microsoft Office 2007/2010/2013/2016 memory corruption
1974| [81272] Microsoft Office 2007/2010/2013 memory corruption
1975| [81265] Microsoft Windows Vista SP2/Server 2008 Library Loader memory corruption
1976| [80872] Microsoft Office 2007 SP3/2010 SP2/2013 SP1/2013 RT SP1/2016 memory corruption
1977| [80871] Microsoft Office 2007 SP3/2010 SP2/2013 SP1/2013 RT SP1/2016 memory corruption
1978| [80869] Microsoft Office 2007 SP3/2010 SP2/2013 SP1/2013 RT SP1/2016 memory corruption
1979| [79506] Microsoft Windows Vista/7/Server 2008/Server 2008 R2 Library Loader memory corruption
1980| [79505] Microsoft Office 2007 memory corruption
1981| [79504] Microsoft Office 2007/2010/2013/2016 memory corruption
1982| [79503] Microsoft Office 2007/2010/2013 memory corruption
1983| [79502] Microsoft Office 2007/2010/2011 memory corruption
1984| [79501] Microsoft Office 2007/2010 memory corruption
1985| [79499] Microsoft Windows 7/Server 2008 R2 Uniscribe memory corruption
1986| [79493] Microsoft Windows Vista/Server 2008 Graphics memory corruption
1987| [79190] Microsoft Word 2007 SP3/2010 SP2/2013 SP1/2013 RT SP1/2016 Office Document memory corruption
1988| [79189] Microsoft Office 2007 SP3/2010 SP2/2013 SP1/2013 RT SP1/2016 Office Document memory corruption
1989| [79187] Microsoft Office 2007 SP3/2010 SP2/2013 SP1/2016 Sandbox privilege escalation
1990| [79167] Microsoft Windows Vista/7/Server 2008/Server 2008 R2 Journal memory corruption
1991| [78372] Microsoft Visio 2007 SP3/2010 SP2 UML Data memory corruption
1992| [78371] Microsoft SharePoint Server 2007 SP3/2010 SP2 InfoPath Forms Services XXE information disclosure
1993| [77646] Microsoft Office 2007 SP3/2010 SP2/2013 SP1/2013 RT SP1 EPS Image memory corruption
1994| [77629] Microsoft Excel 2007 SP3/2010 SP2/2011/2016 Office Document memory corruption
1995| [77627] Microsoft Excel 2007 SP3/2010 SP2 Office Document memory corruption
1996| [77626] Microsoft Excel 2007 SP3/2010 SP2/2011/2016 Office Document memory corruption
1997| [77617] Microsoft Office 2007 SP3/2010 SP2 OpenType Font memory corruption
1998| [77252] Microsoft Office 2007 SP3/2010 SP2 Office Graphics Library Font memory corruption
1999| [77038] Microsoft Windows Server 2008 SP2 UDDI Services cross site scripting
2000| [76497] Microsoft PowerPoint 2007 SP3/2010 SP2/2013 SP1 Office Document memory corruption
2001| [76491] Microsoft Excel 2007 SP3/2010 SP2/2013 SP1/2013 RT SP1 Office Document memory corruption
2002| [76467] Microsoft Word 2007 SP3/2010 SP2/2011/2013 SP1/2013 RT SP1 Office Document memory corruption
2003| [76466] Microsoft Word 2007 SP3/2010 SP2/2011/2013 SP1/2013 RT SP1 Office Document memory corruption
2004| [76464] Microsoft Excel 2007 SP3/2010 SP2/2013 SP1/2013 RT SP1 Office Document memory corruption
2005| [76463] Microsoft Excel 2007 SP3/2010 SP2/2011/2013 SP1/2013 RT SP1 Office Document memory corruption
2006| [76449] Microsoft Windows 8/8.1/Server 2008/Server 2012/Server 2012 R2 Hyper-V memory corruption
2007| [76440] Microsoft SQL Server 2008/2008 R2/2012/2014 Virtual Function Uninitialized Memory memory corruption
2008| [76439] Microsoft SQL Server 2008/2008 R2/2012/2014 Uninitialized Memory memory corruption
2009| [76438] Microsoft SQL Server 2008/2008 R2/2012/2014 Pointer Casting privilege escalation
2010| [75783] Microsoft Windows Server 2008/Server 2012 Active Directory Federation Services cross site scripting
2011| [75338] Microsoft SharePoint 2007/2010/2013 Content privilege escalation
2012| [75337] Microsoft Office 2007 SP3/2010 SP2/2011/2013 SP1/2013 RT SP1 memory corruption
2013| [75336] Microsoft Office 2007 SP3/2010 SP2/2011/2013 SP1/2013 RT SP1 memory corruption
2014| [74845] Microsoft Office 2007/2010/2013 Document Use-After-Free memory corruption
2015| [74844] Microsoft Office 2007/2010 Document Use-After-Free memory corruption
2016| [74837] Microsoft Office 2007/2010/2011/2013 RTF Document Use-After-Free privilege escalation
2017| [73979] Microsoft Exchange Server 2003 SP1/2003 CU7 Meeting privilege escalation
2018| [73978] Microsoft Exchange Server 2003 SP1/2003 CU7 cross site scripting
2019| [73977] Microsoft Exchange Server 2003 SP1/2003 CU7 cross site scripting
2020| [73976] Microsoft Exchange Server 2003 SP1/2003 CU7 cross site scripting
2021| [73975] Microsoft Exchange Server 2003 SP1/2003 CU7 cross site scripting
2022| [73964] Microsoft SharePoint 2007/2010/2013 cross site scripting
2023| [69158] Microsoft Office 2007/2010/2013 Use-After-Free memory corruption
2024| [69157] Microsoft Office 2007/2010/2013 OneTableDocumentStream memory corruption
2025| [69155] Microsoft Excel 2007/2010/2013/- Object memory corruption
2026| [68416] Microsoft Exchange 2007/2010/2013 Outlook Web Access Token spoofing
2027| [68409] Microsoft Office 2007/2010/2013 Use-After-Free memory corruption
2028| [68408] Microsoft Excel 2007/2010/2013 memory corruption
2029| [68407] Microsoft Excel 2007/2010 memory corruption
2030| [68405] Microsoft Word 2007/2010 Index Use-After-Free memory corruption
2031| [68195] Microsoft Windows Vista/7/Server 2003/Server 2008 Input Method Editor Sandbox privilege escalation
2032| [68189] Microsoft Windows Server 2003 SP2 TCP/IP Stack Stack-Based memory corruption
2033| [68188] Microsoft Word 2007 File memory corruption
2034| [68187] Microsoft Word 2007 File memory corruption
2035| [68186] Microsoft Word 2007 File memory corruption
2036| [67829] Microsoft Office 2007/2010/2011 Object memory corruption
2037| [67825] Microsoft .NET Framework 2.0/3.5/3.5.1 ASLR privilege escalation
2038| [71337] Microsoft Office 2000/2004/XP memory corruption
2039| [67355] Microsoft OneNote 2007 File Processing privilege escalation
2040| [67354] Microsoft SQL Server 2008 SP3/2008 R2 SP2/2012 SP1/2014 SQL Master Data Services cross site scripting
2041| [67353] Microsoft SQL Server 2008 SP3/2008 R2 SP2/2012 SP1/2014 T-SQL Query Stack-Based memory corruption
2042| [67018] Microsoft Windows Server 2008/Server 2012/Server 2012 R2 Service Bus AMQP Message denial of service
2043| [13545] Microsoft Word 2007 Embedded Font memory corruption
2044| [13397] Microsoft Windows XP/2000/Server 2003 DHCP Response DHCP ACK spoofing
2045| [13462] Microsoft Visual Studio 2002/2003/2005/2010 Debug Interface msdia.dll PDB File memory corruption
2046| [13229] Microsoft Office 2007/2010/2013 Common Control Library MSCOMCTL.OCX privilege escalation
2047| [13227] Microsoft Office 2007/2010/2013 Chinese Grammar Checker Library privilege escalation
2048| [13226] Microsoft SharePoint Server 2007/2010/2013 Page memory corruption
2049| [13225] Microsoft SharePoint Server 2007/2010/2013 cross site scripting
2050| [13224] Microsoft SharePoint Server 2007/2010/2013 Page memory corruption
2051| [12859] Microsoft Word 2003 Office Document Stack-Based memory corruption
2052| [12852] Microsoft Publisher 2003/2007 Publisher File pubconv.dll memory corruption
2053| [12845] Microsoft Word 2003 Office File Stack-Based memory corruption
2054| [12844] Microsoft Word 2007/2010 Office File memory corruption
2055| [12843] Microsoft Office 2007/2010/2011/2013 XML Parser Nested Entities Memory Consumption denial of service
2056| [12687] Microsoft Word/Office/Outlook 2003/2007/2010/2013 RTF Document memory corruption
2057| [12530] Microsoft Windows XP/Vista/Server 2003/Server 2008/Server 2012 Security Account Manager Lockout privilege escalation
2058| [12266] Microsoft .NET Framework 2.0 SP2/3.5.1 ASLR Bypass privilege escalation
2059| [12070] Apple Pages 2.0/2.0.1/2.0.2/5.0/5.0.1 on Mac Microsoft Word Document memory corruption
2060| [11950] Microsoft Office Compability Pack/Word 2007 SP3 File memory corruption
2061| [11949] Microsoft Word Viewer/Office Compatibility Pack/Word 2003 SP3/2007 SP3 File memory corruption
2062| [11448] Microsoft Office 2007/2010 Address Space Layout Randomization privilege escalation
2063| [11151] Microsoft Outlook 2007/2010/2013/- S/MIME Certificate Metadata Expansion memory corruption
2064| [11149] Microsoft Office 2003/2007/2010/2013/- WordPerfect Document epsimp32.flt memory corruption
2065| [11148] Microsoft Office 2003/2007 WordPerfect Document epsimp32.flt memory corruption
2066| [11146] Microsoft Office 2003/2007 epsimp32.flt memory corruption
2067| [11230] Microsoft Word 2003 DOC Document Embedded Image denial of service
2068| [11081] Microsoft Windows Vista/Server 2008 TIFF Image memory corruption
2069| [10648] Microsoft Word 2007 Word File memory corruption
2070| [10647] Microsoft Word 2003 Word File memory corruption
2071| [10643] Microsoft SharePoint Server 2007/2010/2013 Input Sanitizer memory corruption
2072| [10642] Microsoft SharePoint Server 2007/2010 Content Display in Frames privilege escalation
2073| [10247] Microsoft SharePoint Server 2007/2010/2013 Online Cloud cross site scripting
2074| [10245] Microsoft Office 2003/2007/2010 Word File memory corruption
2075| [10244] Microsoft Office 2003 SP3 Word File memory corruption
2076| [10243] Microsoft Office 2003/2007 Word File memory corruption
2077| [10242] Microsoft Office 2007 Word File memory corruption
2078| [10241] Microsoft Office 2007 Word File memory corruption
2079| [10240] Microsoft Office 2003/2007/2010 Word File memory corruption
2080| [10239] Microsoft Office 2003/2007 Word File memory corruption
2081| [10238] Microsoft Excel 2003/2007 XML External Entity Data information disclosure
2082| [10237] Microsoft Excel 2003/2007/2010 XML External Entity Data information disclosure
2083| [10236] Microsoft Word/Office 2003/2007 XML External Entity Data information disclosure
2084| [10234] Microsoft Word/Sharepoint 2003 SP3/2007 SP3/2010 SP1 Office File memory corruption
2085| [10232] Microsoft Word/Sharepoint 2003 SP3/2007 SP3/2010 SP1 Office File memory corruption
2086| [10231] Microsoft Word/Sharepoint 2003 SP3/2007 SP3/2010 SP1 Office File memory corruption
2087| [10230] Microsoft Word/Sharepoint 2003 SP3/2007 SP3/2010 SP1 Office File memory corruption
2088| [10229] Microsoft Access 2007/2010/2013 Access File ACCDB File memory corruption
2089| [10228] Microsoft Access 2007/2010/2013 Access File ACCDB File memory corruption
2090| [10227] Microsoft Access 2007/2010/2013 Access File ACCDB File memory corruption
2091| [10192] Microsoft Windows XP SP3/Vista/7/2000/Server 2003 SP2 Windows Theme File privilege escalation
2092| [10191] Microsoft Windows XP/Server 2003 OLE Object privilege escalation
2093| [10190] Microsoft Windows Vista/7/8/Server 2008 Active Directory denial of service
2094| [10189] Microsoft Outlook 2007/2010 S/MIME privilege escalation
2095| [9941] Microsoft Windows XP/Server 2003 Unicode Scripts Processor USP10.DLL Uniscribe Font memory corruption
2096| [9929] Microsoft Windows Server 2008/Server 2012 Active Directory Federation Services Unspecified Account information disclosure
2097| [9715] Microsoft PowerPoint 2007 DirectShow Runtime quartz.dll GetMaxSampleSize denial of service
2098| [9397] Microsoft .NET Framework 2.0 SP2/3.5/3.5.1/4/4.5 Array privilege escalation
2099| [9394] Microsoft .NET Framework 2.0 SP2/3.5/3.5.1/4/4.5 on 64-bit Array memory corruption
2100| [9393] Microsoft .NET Framework 2.0 SP2/3.5/3.5.1/4/4.5 Permission privilege escalation
2101| [8738] Microsoft Visio 2003 SP3/2007 SP3/2010 SP1 XML Parser File information disclosure
2102| [8737] Microsoft Word 2003 SP3 Shape Data Parser File memory corruption
2103| [8736] Microsoft Publisher 2003 SP3 PUB File memory corruption
2104| [8735] Microsoft Publisher 2003 SP3/2007 SP3/2010 SP1 PUB File memory corruption
2105| [8734] Microsoft Publisher 2003 SP3 PUB File memory corruption
2106| [8733] Microsoft Publisher 2003 SP3 PUB File memory corruption
2107| [8732] Microsoft Publisher 2003 SP3 PUB File memory corruption
2108| [8731] Microsoft Publisher 2003 SP3 PUB File memory corruption
2109| [8730] Microsoft Publisher 2003 SP3 PUB File memory corruption
2110| [8729] Microsoft Publisher 2003 SP3 PUB File memory corruption
2111| [8728] Microsoft Publisher 2003 SP3 PUB File memory corruption
2112| [8727] Microsoft Publisher 2003 SP3 PUB File memory corruption
2113| [8726] Microsoft Publisher 2003 PUB File Eingabe memory corruption
2114| [8723] Microsoft .NET Framework 2.0 SP2/3.5/3.5.1/4/4.5 XML File spoofing
2115| [7643] Microsoft Windows Server 2008 R2/Server 2012 NFS Server NULL Pointer Dereference denial of service
2116| [7642] Microsoft Exchange 2007/2010 Outlook Web Access vspdx.dll) privilege escalation
2117| [7641] Microsoft Windows XP/Vista/Server 2003/Server 2008 DirectShow Quartz.dll memory corruption
2118| [8589] Microsoft System Center Operations Manager 2007 SP1/2007 R2 ViewTypeManager.aspx cross site scripting
2119| [7252] Microsoft System Center Operations Manager 2007 ExecuteTask.aspx cross site scripting
2120| [7251] Microsoft System Center Operations Manager 2007 cross site scripting
2121| [7248] Microsoft Windows 7/Server 2008 R2 Print Spooler privilege escalation
2122| [7121] Microsoft Exchange 2007/2010 RSS Feed denial of service
2123| [7118] Microsoft Windows Server 2008 R2/Server 2012 IP-HTTPS unknown vulnerability
2124| [62914] Microsoft Office 2003 SP3/2007 SP3/2008/2010 SP1/2011 Spreadsheet Use-After-Free memory corruption
2125| [7058] Microsoft Windows 7/Server 2008 R2 DHCPv6 Message denial of service
2126| [6935] Microsoft Office Excel 2003/2007/2010 Input Sanitizer File Stack-based memory corruption
2127| [6934] Microsoft Office Excel 2003/2007/2010 Input Sanitizer memory corruption
2128| [6933] Microsoft Office Excel 2003/2007/2010 SerAuxErrBar File memory corruption
2129| [6929] Microsoft .NET Framework 2.0 SP2/3.5/3.5.1/4/4.5 Web Proxy Setting Auto-Discovery memory corruption
2130| [6927] Microsoft .NET Framework 2.0 SP2/3.5.1 Trusted Code Function information disclosure
2131| [6918] Microsoft Excel 2007 SP2 Input Sanitizer File memory corruption
2132| [6830] Microsoft Word 2007/2010 File memory corruption
2133| [6819] Microsoft Excel 2007 File memory corruption
2134| [6627] Microsoft Windows 7/Server 2008 R2 Kerberos denial of service
2135| [6626] Microsoft SharePoint/Lync/Infopath 2007/2010 HTML Sanitization cross site scripting
2136| [6622] Microsoft Word 2003/2007/2010/- RTF Document memory corruption
2137| [6621] Microsoft Word 2007 PAPX memory corruption
2138| [62239] Microsoft Systems Management Server 2003 Configuration Manager Reflected cross site scripting
2139| [5945] Microsoft Office 2007/2010 Computer Graphics Metafile memory corruption
2140| [5939] Microsoft Windows XP/Vista/7/Server 2003/Server 2008 R2 Print Spooler Service memory corruption
2141| [5938] Microsoft Windows XP/Vista/7/Server 2003/Server 2008 R2 Remote Administration Protocol netapi32.dll RAP Request denial of service
2142| [5933] Microsoft SQL Server 2000/2005/2008/2008 R2 Common Controls TabStrip ActiveX MSCOMCTL.OCX memory corruption
2143| [5932] Microsoft Office 2003/2007/2010 Common Controls TabStrip ActiveX MSCOMCTL.OCX memory corruption
2144| [5654] Microsoft Windows XP/Vista/7/Server 2003/Server 2008 information disclosure
2145| [5653] Microsoft Windows XP/Vista/7/Server 2003/Server 2008 win32k.sys memory corruption
2146| [5652] Microsoft Windows XP/Vista/7/Server 2003/Server 2008 win32k.sys memory corruption
2147| [5650] Microsoft Windows XP/Vista/7/Server 2003/Server 2008 memory corruption
2148| [5649] Microsoft Office 2003/2007/2010 libraries memory corruption
2149| [5645] Microsoft SharePoint 2007/2010/3.0 Reflected cross site scripting
2150| [5643] Microsoft SharePoint 2007/2010 information disclosure
2151| [5642] Microsoft SharePoint 2007 cross site request forgery
2152| [5553] Microsoft Windows XP/Vista/7/Server 2003/Server 2008 OpenType Font atmfd.dll denial of service
2153| [5524] Microsoft Windows XP/Vista/7/Server 2003/Server 2008 memory corruption
2154| [5518] Microsoft .NET Framework 2.0 SP2/3.5/3.5.1/4/4.5 memory corruption
2155| [5362] Microsoft Office 2003/2007 GDI+ memory corruption
2156| [5291] Microsoft Visual Studio 2008 Incremental Linker link.exe ConvertRgImgSymToRgImgSymEx memory corruption
2157| [5268] Microsoft Office 2008 on Mac RTF Pfragment File memory corruption
2158| [5080] Microsoft SQL Server 2005/2008/2008R2 CREATE DATABASE sql injection
2159| [5050] Microsoft Office 2007 WPS Converter Heap-based memory corruption
2160| [5049] Microsoft SQL Server 2000/2005/2008 MSCOMCTL.OCX privilege escalation
2161| [5048] Microsoft Office 2003/2007/2010 MSCOMCTL.OCX privilege escalation
2162| [5046] Microsoft Windows XP/Vista/7/Server 2003/Server 2008 Windows Authenticode Signature Verification WinVerifyTrust Signature privilege escalation
2163| [4803] Microsoft Windows Server 2003/Server 2008 DNS Server Domain Resource Record Query Parser denial of service
2164| [4802] Microsoft Windows XP/Vista/7/Server 2003/Server 2008 Remote Desktop Protocol denial of service
2165| [4798] Microsoft Windows XP/Vista/7/Server 2003/Server 2008 Remote Desktop Service memory corruption
2166| [60205] Microsoft .NET Framework 2.0 SP2/3.5.1 Heap-based memory corruption
2167| [4642] Microsoft .NET Framework 2.0 SP2/3.5.1/4 XAML Browser Application memory corruption
2168| [60065] Microsoft Windows 2000 mod_sql unknown vulnerability
2169| [4535] Microsoft Windows XP/Server 2003 Object Packager packager.exe privilege escalation
2170| [4534] Microsoft Windows XP/Vista/7/Server 2003/Server 2008 Line21 DirectShow Filter Quartz.dll/Qdvd.dll Media File memory corruption
2171| [4533] Microsoft Windows XP/Vista/7/Server 2003/Server 2008 Multimedia Library winmm.dll MIDI File memory corruption
2172| [4507] Microsoft .NET Framework 2.0 SP2/3.5 SP1/3.5.1/4.0 Forms Authentication Redirect
2173| [59666] Microsoft Publisher 2003/2007 "Publisher memory corruption
2174| [4482] Microsoft Word 2007/2010/2011 Document Parser memory corruption
2175| [4480] Microsoft Excel 2003 memory corruption
2176| [4478] Microsoft Windows XP/Server 2003 OLE Objects Memory Management memory corruption
2177| [4477] Microsoft PowerPoint 2007 OfficeArt Use-After-Free memory corruption
2178| [4474] Microsoft Windows XP/Vista/7/Server 2003/Server 2008 Active Directory Query memory corruption
2179| [4473] Microsoft Powerpoint 2007/2010 DLL-Loader memory corruption
2180| [4471] Microsoft Office 2003/2007 Publisher Out-of-Bounds memory corruption
2181| [4470] Microsoft Office 2003 SP3 memory corruption
2182| [4453] Microsoft Excel 2003 Record Parser memory corruption
2183| [4446] Microsoft Office 2008/2007 OfficeArt Record Parser memory corruption
2184| [4445] Microsoft Office 2007/2010/2011 Word Document Parser memory corruption
2185| [4438] Microsoft Windows Vista/7/Server 2008 TCP/IP Reference Counter denial of service
2186| [5358] Microsoft Windows XP/Vista/7/Server 2003/Server 2008 TrueType Font Handling memory corruption
2187| [59005] Microsoft Host Integration Server 2004 denial of service
2188| [58492] Microsoft SharePoint Server 2007 Spreadsheet memory corruption
2189| [58491] Microsoft Office 2004/2007/2008/2010/2011 Spreadsheet memory corruption
2190| [58490] Microsoft Office Compatibility Pack 2007 Spreadsheet memory corruption
2191| [58489] Microsoft Office 2004/2007/2008/2010/2011 Spreadsheet memory corruption
2192| [58488] Microsoft Office 2007/2010 memory corruption
2193| [4412] Microsoft Office 2003/2007 Library Loader Designfehler
2194| [4411] Microsoft Excel 2003 memory corruption
2195| [4409] Microsoft Windows Server 2003/Server 2008 WINS unknown vulnerability
2196| [58240] Microsoft Visio 2003/2007 memory corruption
2197| [58237] Microsoft Visio 2003/2007/2010 memory corruption
2198| [4396] Microsoft Windows Vista/7/Server 2008 TCP/IP Stack denial of service
2199| [4393] Microsoft Windows Server 2008 DNS Service memory corruption
2200| [4391] Microsoft .NET Framework 2.0 SP2/3.5.1/4 Socket Restriction privilege escalation
2201| [4390] Microsoft Windows Server 2008 Remote Desktop Web Access cross site scripting
2202| [4388] Microsoft Windows Vista/7/Server 2008 File Metadata Parser denial of service
2203| [57691] Microsoft SQL Server 2008 Web Service information disclosure
2204| [57690] Microsoft Excel 2002/2003 Spreadsheet memory corruption
2205| [57689] Microsoft Excel 2002 Spreadsheet memory corruption
2206| [57688] Microsoft Excel 2002 Spreadsheet memory corruption
2207| [57687] Microsoft Excel 2002/2003/2007 Spreadsheet memory corruption
2208| [57686] Microsoft Excel 2002 Spreadsheet memory corruption
2209| [57685] Microsoft Excel 2002/2003/2007 Array Access memory corruption
2210| [57684] Microsoft Excel 2002/2003/2007/2010 Spreadsheet memory corruption
2211| [4369] Microsoft Excel 2002/2003/2007 memory corruption
2212| [4367] Microsoft Windows Server 2008 Hyper-V VMBus denial of service
2213| [4362] Microsoft Windows Vista/7/Server 2008 denial of service
2214| [57420] Microsoft PowerPoint 2002/2003 memory corruption
2215| [4349] Microsoft Office 2004/2008/2007 Presentation File Parser memory corruption
2216| [4348] Microsoft Powerpoint 2002/2003/2007 memory corruption
2217| [57077] Microsoft Excel 2002 Uninitialized Memory memory corruption
2218| [57078] Microsoft Office 2003/2007/Xp docx unknown vulnerability
2219| [57079] Microsoft PowerPoint 2002/2003/2007/2010 memory corruption
2220| [57076] Microsoft Excel 2002/2003 memory corruption
2221| [57075] Microsoft Excel 2002/2003 memory corruption
2222| [57074] Microsoft Excel 2002 memory corruption
2223| [57073] Microsoft Excel 2002/2003/2007/2010 memory corruption
2224| [4334] Microsoft .NET Framework 2.0 SP2/3.5 SP1/3.5.1/4.0 JIT Compiler memory corruption
2225| [4301] Microsoft Windows Server 2003 SMB Browser Heap-based denial of service
2226| [56475] Microsoft Office 2004/2008 memory corruption
2227| [56414] Microsoft Visio 2002/2003/2007 ELEMENTS.DLL memory corruption
2228| [56413] Microsoft Visio 2002/2003/2007 Exception ORMELEMS.DLL memory corruption
2229| [4298] Microsoft Windows 7/Server 2008 JScript/VBScript Engine information disclosure
2230| [4297] Microsoft Windows XP/Vista/7/Server 2003/Server 2008 OpenType Compact Font Format Driver privilege escalation
2231| [4296] Microsoft Windows XP/Server 2003 LSASS Authentication Request unknown vulnerability
2232| [4295] Microsoft Windows 7/Server 2008 Kerberos weak authentication
2233| [4294] Microsoft Windows XP/Vista/7/Server 2003/Server 2008 Driver win32k.sys unknown vulnerability
2234| [4293] Microsoft Windows XP/Server 2003 Kerberos CRC32 Checksum privilege escalation
2235| [4292] Microsoft Windows XP/Server 2003 CSRSS Logoff privilege escalation
2236| [4289] Microsoft Excel 2007 Shape Data Parser memory corruption
2237| [4286] Microsoft Powerpoint 2007 OfficeArt Container Parser memory corruption
2238| [4279] Microsoft Windows XP/Vista/7/Server 2003/Server 2008 MHTML cross site scripting
2239| [56176] Microsoft Windows XP/7/Server 2003 fxscover.exe CDrawPoly::Serialize memory corruption
2240| [55772] Microsoft Publisher 2002 pubconv.dll memory corruption
2241| [55771] Microsoft Publisher 2002/2003/2010 memory corruption
2242| [55765] Microsoft Office 2003/Xp Integer memory corruption
2243| [55764] Microsoft Office 2003/Xp memory corruption
2244| [55750] Microsoft Publisher 2002/2003 pubconv.dll memory corruption
2245| [55749] Microsoft Publisher 2002/2003/2007/2010 pubconv.dll memory corruption
2246| [55748] Microsoft Publisher 2002/2003/2007 pubconv.dll memory corruption
2247| [4230] Microsoft Exchange 2007 on 64-bit RPC store.exe MAPI Request denial of service
2248| [4229] Microsoft SharePoint 2007 Document Conversion Launcher Service Eingabeung\xC3\xBCltigkeit
2249| [4228] Microsoft Windows Server 2008 Hyper-V VMBus denial of service
2250| [4224] Microsoft Windows Vista/7/Server 2008 Consent User Interface privilege escalation
2251| [4231] Microsoft Windows XP/Vista/7/Server 2003/Server 2008 Driver win32k.sys GreEnableEUDC denial of service
2252| [55420] Microsoft Office 2007/2010 memory corruption
2253| [55419] Microsoft Office 2004/2008/2011/Xp memory corruption
2254| [55412] Microsoft PowerPoint Viewer 2007 memory corruption
2255| [55411] Microsoft PowerPoint 2002/2003 memory corruption
2256| [4204] Microsoft Windows Server 2008 Color Control Panel Eingabeung\xC3\xBCltigkeit
2257| [54995] Microsoft Office 2004/2008 memory corruption
2258| [54994] Microsoft Office 2004/2008 Out-of-Bounds memory corruption
2259| [54993] Microsoft Office Compatibility Pack 2007 memory corruption
2260| [54992] Microsoft Excel 2002 memory corruption
2261| [54991] Microsoft Office 2004 Future memory corruption
2262| [54990] Microsoft Office 2004 memory corruption
2263| [54989] Microsoft Office 2004/2008 memory corruption
2264| [54988] Microsoft Excel 2002 memory corruption
2265| [54987] Microsoft Excel 2002 memory corruption
2266| [54986] Microsoft Excel 2002/2003 memory corruption
2267| [54985] Microsoft Office Compatibility Pack 2003/2004/2007/2008 memory corruption
2268| [54984] Microsoft Office 2004/2008 memory corruption
2269| [54983] Microsoft Excel 2002 Integer memory corruption
2270| [54980] Microsoft Word 2002/2003 memory corruption
2271| [54979] Microsoft Word 2002 memory corruption
2272| [54978] Microsoft Word 2002 memory corruption
2273| [54977] Microsoft Word 2002 Heap-based memory corruption
2274| [54976] Microsoft Word 2002 memory corruption
2275| [54975] Microsoft Word 2002 memory corruption
2276| [54974] Microsoft Word 2002 memory corruption
2277| [54973] Microsoft Word 2002 memory corruption
2278| [54972] Microsoft Word 2002 memory corruption
2279| [54971] Microsoft Word 2002 memory corruption
2280| [4197] Microsoft SharePoint 2007/3.0 cross site scripting
2281| [4196] Microsoft Word 2002/2003/2007/2010 Stack-based memory corruption
2282| [4194] Microsoft Windows Vista/7/Server 2008 SChannel Client Certificate Request denial of service
2283| [54774] Microsoft Word 2003 word_crash_11.8326.8324_poc.doc denial of service
2284| [54757] Microsoft SharePoint Server 2007 HTML Sanitization SafeHTML cross site scripting
2285| [4186] Microsoft Outlook 2002/2003/2007 Content Parser Heap-based memory corruption
2286| [54584] Microsoft Visual C++ 2005 AtlTraceTool8.exe unknown vulnerability
2287| [54554] Microsoft Groove 2007 mso.dll memory corruption
2288| [4187] Microsoft Windows Vista/7/Server 2008 TCP/IP Stack Ipv4SetEchoRequestCreate() denial of service
2289| [54322] Microsoft Word 2002/2003 memory corruption
2290| [54321] Microsoft Office Compatibility Pack 2007 memory corruption
2291| [54320] Microsoft Office Compatibility Pack 2007 memory corruption
2292| [54319] Microsoft Office Compatibility Pack 2007 memory corruption
2293| [54318] Microsoft .NET Framework 2.0 SP1/2.0 SP2/3.5/3.5 SP1/3.5.1 Interfaces memory corruption
2294| [4165] Microsoft Windows Vista/7/Server 2008 TCP/IP Stack denial of service
2295| [4162] Microsoft Windows Vista/7/Server 2008 Kernel memory corruption
2296| [4159] Microsoft Excel 2002/2003 SXDB PivotTable Cache Data Record memory corruption
2297| [4149] Microsoft Windows XP/Vista/7/Server 2003/Server 2008 Shell Shortcut Parser memory corruption
2298| [54083] Microsoft Access 2003 ActiveX Control ACCWIZ.dll memory corruption
2299| [4146] Microsoft Outlook 2002/2003/2007 SMB Attachment PR_ATTACH_METHOD memory corruption
2300| [4145] Microsoft Access 2003/2007 ActiveX ACCWIZ.dll memory corruption
2301| [54617] Microsoft Outlook Web Access up to 2007 cross site request forgery
2302| [4151] Microsoft Windows Vista/Server 2008 NtUserCheckAccessForIntegrityLevel memory corruption
2303| [53591] Microsoft Windows Server 2003 GetServerName cross site scripting
2304| [53505] Microsoft Excel 2002/2007 memory corruption
2305| [53501] Microsoft Excel 2002 memory corruption
2306| [53500] Microsoft Excel 2002 memory corruption
2307| [53499] Microsoft Excel 2002 memory corruption
2308| [53495] Microsoft Excel 2002/2003/2007 memory corruption
2309| [53494] Microsoft Excel 2002 Stack-based memory corruption
2310| [53504] Microsoft Excel 2002 memory corruption
2311| [53503] Microsoft Excel 2002 Stack-Based memory corruption
2312| [53502] Microsoft Excel 2002 Heap-based memory corruption
2313| [53498] Microsoft Excel 2002 Stack-based memory corruption
2314| [53497] Microsoft Excel 2002 memory corruption
2315| [53496] Microsoft Excel 2002 memory corruption
2316| [53493] Microsoft Excel 2002/2003/2007 memory corruption
2317| [4133] Microsoft Office 2003/2007/Xp COM Object Instantiator memory corruption
2318| [53366] Microsoft ASP.NET 2.0 cross site scripting
2319| [53385] Microsoft Exchange Server 2007 Outlook Web Access cross site scripting
2320| [53164] Microsoft Office 2003/2007/Xp ActiveX Control VBE6.DLL memory corruption
2321| [53054] Microsoft VISIO 2002/2003/2007 VISIODWG.DLL memory corruption
2322| [4125] Microsoft SharePoint 2007/3.0 help.aspx cross site scripting
2323| [52777] Microsoft Publisher 2002/2003/2007 memory corruption
2324| [52773] Microsoft Visio 2002/2003/2007 memory corruption
2325| [52772] Microsoft Visio 2002/2003/2007 memory corruption
2326| [4107] Microsoft Windows 7/Server 2008 Kernel denial of service
2327| [4103] Microsoft Windows Server 2003 Media Services Stack-based memory corruption
2328| [52543] Microsoft Virtual PC 2007 unknown vulnerability
2329| [52148] Microsoft Office 2004/2008/2007 Uninitialized Memory memory corruption
2330| [52147] Microsoft Office 2004/2008/2007 Spreadsheet Uninitialized Memory memory corruption
2331| [52146] Microsoft Office 2004/2008/2007 Spreadsheet Heap-based memory corruption
2332| [52145] Microsoft Office 2004/2008/2007 Spreadsheet Heap-based memory corruption
2333| [52144] Microsoft Office 2004/2008/2007 Spreadsheet memory corruption
2334| [52143] Microsoft Office 2004/2008/2007 Spreadsheet memory corruption
2335| [4090] Microsoft Excel 2002/2003/2007 memory corruption
2336| [52036] Microsoft Windows 2000 MsgBox memory corruption
2337| [51995] Microsoft SharePoint Server up to 2006 cross site scripting
2338| [51810] Microsoft Office 2004/Xp MSO.DLL memory corruption
2339| [51802] Microsoft PowerPoint 2003 Stack-based memory corruption
2340| [51801] Microsoft PowerPoint 2003 Stack-based memory corruption
2341| [51800] Microsoft PowerPoint 2002/2003 Use-After-Free memory corruption
2342| [51799] Microsoft PowerPoint 2002/2003 memory corruption
2343| [51798] Microsoft PowerPoint 2002/2003 Heap-based memory corruption
2344| [4082] Microsoft Powerpoint 2002 memory corruption
2345| [54550] Microsoft PowerPoint 2007 rpawinet.dll memory corruption
2346| [54556] Microsoft Visio 2003 mfc71enu.dll unknown vulnerability
2347| [51497] Microsoft Windows Live Messenger 2009 ActiveX Control msnmsgr.exe denial of service
2348| [51133] Microsoft Windows 2000 SP4/XP SP2/SP3/Server 2003 SP2 memory corruption
2349| [51074] Microsoft Office 2002/2003 Integer memory corruption
2350| [4069] Microsoft Project 2007/2003 Project Memory Validator memory corruption
2351| [50794] Microsoft Office 2004/2008 Spreadsheet memory corruption
2352| [50793] Microsoft Office 2004/2008 Spreadsheet memory corruption
2353| [50792] Microsoft Office 2004/2008 Spreadsheet memory corruption
2354| [50791] Microsoft Office 2004/2008 Spreadsheet memory corruption
2355| [50790] Microsoft Office 2004/2008 Spreadsheet Heap-based memory corruption
2356| [50788] Microsoft Office 2004/2008 Spreadsheet memory corruption
2357| [50787] Microsoft Office 2004/2008 Spreadsheet memory corruption
2358| [50786] Microsoft Windows 2000 llssrv.exe memory corruption
2359| [50789] Microsoft Office 2004/2008 Spreadsheet memory corruption
2360| [4056] Microsoft Word 2002/2003 File Information Block Parser Stack-based memory corruption
2361| [50660] Microsoft SharePoint Server 2007 unknown vulnerability
2362| [50443] Microsoft Office Powerpoint 2007 Integer memory corruption
2363| [50432] Microsoft .NET Framework 2.0/2.0 SP1/2.0 SP2/3.5/3.5 SP1 memory corruption
2364| [49866] Microsoft Windows Server 2003 memory corruption
2365| [4031] Microsoft Windows Vista/Server 2008 SMB Processor EducatedScholar memory corruption
2366| [4030] Microsoft Windows Vista/Server 2008 Wireless LAN AutoConfig Service Heap-based memory corruption
2367| [4029] Microsoft Windows 2000/XP TCP/IP Window Size denial of service
2368| [49745] Microsoft Windows Server 2003 denial of service
2369| [49394] Microsoft Windows Server 2003 memory corruption
2370| [49198] Microsoft Visual Studio 2005 information disclosure
2371| [49047] Microsoft Virtual Server 2005 privilege escalation
2372| [49046] Microsoft Windows Server 2003 quartz.dll memory corruption
2373| [49045] Microsoft Windows Server 2003 quartz.dll memory corruption
2374| [49044] Microsoft ISA Server 2006 privilege escalation
2375| [3999] Microsoft Office 2007 Pointer memory corruption
2376| [4000] Microsoft Office 2003/Xp/Sp3 Web Components memory corruption
2377| [48894] Microsoft Windows Server 2003 msvidctl.dll memory corruption
2378| [48572] Microsoft Office Powerpoint 2002 FL21WIN.DLL memory corruption
2379| [48517] Microsoft Windows 2000 Memory Leak memory corruption
2380| [48516] Microsoft Windows Server 2008 unknown vulnerability
2381| [48512] Microsoft Windows Server 2008 unknown vulnerability
2382| [48515] Microsoft Office Word Viewer 2003 memory corruption
2383| [48514] Microsoft Office Word Viewer 2003 Stack-based memory corruption
2384| [48554] Microsoft Excel 2000/2003/2007 memory corruption
2385| [48157] Microsoft Office PowerPoint 2002 Sound memory corruption
2386| [48156] Microsoft Office PowerPoint 2000 Stack-based memory corruption
2387| [48154] Microsoft Office PowerPoint 2002 Sound PP7X32.DLL memory corruption
2388| [48152] Microsoft Office PowerPoint 2002 PP4X32.DLL memory corruption
2389| [48150] Microsoft Office PowerPoint 2002 Sound memory corruption
2390| [48147] Microsoft Office PowerPoint 2002 Sound memory corruption
2391| [48146] Microsoft Office PowerPoint 2002 Integer memory corruption
2392| [48155] Microsoft Office PowerPoint 2002 Notes Container Heap-based memory corruption
2393| [48153] Microsoft Office PowerPoint 2002 Sound memory corruption
2394| [48151] Microsoft Office PowerPoint 2002 Stack-based memory corruption
2395| [48149] Microsoft Office PowerPoint 2002 memory corruption
2396| [48148] Microsoft Office PowerPoint 2002 Sound memory corruption
2397| [3974] Microsoft Powerpoint 2000/2002/2003 Sound Data Stack-based memory corruption
2398| [3973] Microsoft Powerpoint 2000/2002/2003 Notes Container Stack-based memory corruption
2399| [3972] Microsoft Powerpoint 2000/2002/2003 BuildList memory corruption
2400| [3971] Microsoft Powerpoint 2000/2002/2003 Object Stack-based memory corruption
2401| [3970] Microsoft Powerpoint 2000/2002/2003 Paragraph Stack-based memory corruption
2402| [3969] Microsoft Powerpoint 2000/2002/2003 Atom Stack-based memory corruption
2403| [47719] Microsoft Windows 2000 Stack-based memory corruption
2404| [47720] Microsoft Internet Security And Acceleration Server 2006 Forms Authentication cookieauth.dll cross site scripting
2405| [47716] Microsoft Office Converter Pack 2003 WPFT632.CNV memory corruption
2406| [47715] Microsoft Windows 2000 Wordpad memory corruption
2407| [47718] Microsoft Excel 2000/2002/2003/2007 Spreadsheet memory corruption
2408| [3960] Microsoft Windows XP/2000/Server 2003 DirectShow MJPEG memory corruption
2409| [3952] Microsoft ISA Server 2004/2006 denial of service
2410| [3946] Microsoft PowerPoint 2004/2000/2002/2003 memory corruption
2411| [47091] Microsoft Windows Server 2008 unknown vulnerability
2412| [47090] Microsoft Windows Server 2008 unknown vulnerability
2413| [3939] Microsoft Windows 2000 DNS Designfehler
2414| [3938] Microsoft Windows 2000 SSL weak authentication
2415| [3937] Microsoft Windows 2000 memory corruption
2416| [3932] Microsoft Excel 2004/2000/2002/2003/2007 Object Reference Designfehler
2417| [46620] Microsoft Windows Live Messenger 2009 msnmsgr.exe denial of service
2418| [46455] Microsoft Exchange Server 2007 denial of service
2419| [46454] Microsoft Exchange Server 2007 memory corruption
2420| [46453] Microsoft Visio 2002/2003/2007 memory corruption
2421| [46452] Microsoft Visio 2002/2003/2007 memory corruption
2422| [46451] Microsoft Visio 2002/2003/2007 memory corruption
2423| [46327] Microsoft Word 2007 information disclosure
2424| [45758] Microsoft Money 2006 ActiveX Control prtstb06.dll denial of service
2425| [45381] Microsoft Windows Vista SP1/Server 2008 Explorer memory corruption
2426| [45380] Microsoft Windows Vista SP1/Server 2008 Search memory corruption
2427| [45379] Microsoft Office SharePoint Server 2007 denial of service
2428| [3896] Microsoft SQL Server up to 2005 sp_replwritetovarbin memory corruption
2429| [3892] Microsoft Excel 2000/2002/2003 Formula memory corruption
2430| [3891] Microsoft Excel 2000/2002/2003 memory corruption
2431| [3890] Microsoft Excel 2000/2002/2003 NAME Index memory corruption
2432| [3889] Microsoft Word 2000/2002/2003/2007 Table Property Stack-based memory corruption
2433| [3888] Microsoft Word 2000/2002/2003/2007 RTF Stylesheet memory corruption
2434| [3887] Microsoft Word 2000/2002/2003/2007 memory corruption
2435| [3886] Microsoft Word 2000/2002/2003/2007 ControlWord Heap-based memory corruption
2436| [3885] Microsoft Word 2000/2002/2003/2007 memory corruption
2437| [3884] Microsoft Word 2000/2002/2003/2007 memory corruption
2438| [3883] Microsoft Word 2000/2002/2003/2007 RTF Heap-based memory corruption
2439| [3882] Microsoft Word 2000/2002/2003/2007 LFO memory corruption
2440| [3880] Microsoft Visual Basic up to 2003 ActiveX Control Mschrt20.ocx memory corruption
2441| [3879] Microsoft Visual Basic up to 2003 ActiveX Control mscomct2.ocx memory corruption
2442| [3878] Microsoft Visual Basic up to 2003 ActiveX Control mshflxgd.ocx memory corruption
2443| [3877] Microsoft Visual Basic up to 2003 ActiveX Control msflxgrd.ocx memory corruption
2444| [3876] Microsoft Visual Basic up to 2003 ActiveX Control msdatgrd.ocx memory corruption
2445| [45197] Microsoft Windows 2000 nskey.dll memory corruption
2446| [45063] Microsoft Windows Server 2003 Active Directory unknown vulnerability
2447| [45040] Microsoft .NET Framework 2.0.50727 Code Access Security unknown vulnerability
2448| [44855] DjVu Activex Control For Microsoft Office 2000 3.0 ActiveX Control DjVu_ActiveX_MSOffice.dll memory corruption
2449| [44665] Microsoft Peachtree Accounting 2004 ActiveX Control PAWWeb11.ocx unknown vulnerability
2450| [44589] Microsoft Exchange Server 2003 Outlook Web Access unknown vulnerability
2451| [3845] Microsoft Windows 2000 SP4 Active Directory memory corruption
2452| [44533] Microsoft Windows 2000 mqsvc.exe memory corruption
2453| [3844] Microsoft Excel 2003 REPT memory corruption
2454| [3843] Microsoft Excel up to 2007 BIFF File Heap-based memory corruption
2455| [3842] Microsoft Excel 2003 VBA Performance Cache Stack-based Eingabeung\xC3\xBCltigkeit
2456| [44405] Microsoft Digital Image 2006 ActiveX Control PipPPush.DLL unknown vulnerability
2457| [44047] Microsoft SQL Server 2000 ActiveX Control SQLVDIRLib.SQLVDirControl memory corruption
2458| [43981] Microsoft Organization Chart 2.00 orgchart.exe memory corruption
2459| [43957] Microsoft Office 2003/2007/Xp gdiplus.dll memory corruption
2460| [43956] Microsoft Office 2003/2007/Xp gdiplus.dll memory corruption
2461| [43955] Microsoft Office 2003/2007/Xp gdiplus.dll memory corruption
2462| [43952] Microsoft Office 2003/2007/Xp URI memory corruption
2463| [43676] Microsoft Windows XP/Vista/2000/Server 2003 memory corruption
2464| [43675] Microsoft Windows XP/Vista/2000/Server 2003 of memory corruption
2465| [43662] Microsoft Office Powerpoint Viewer up to 2003 memory corruption
2466| [43661] Microsoft Office Powerpoint Viewer 2003 memory corruption
2467| [43660] Microsoft Office Powerpoint Viewer 2003 Integer memory corruption
2468| [43657] Microsoft Office 2000/2003/Xp memory corruption
2469| [43654] Microsoft SharePoint Server 2007 memory corruption
2470| [43653] Microsoft Office 2000/2002/2004/2008 memory corruption
2471| [43652] Microsoft Office 2000/2002/2003/2004/2008 memory corruption
2472| [3797] Microsoft Windows Vista/Server 2008 IPsec Policy Designfehler
2473| [3796] Microsoft Office 2000 WPG memory corruption
2474| [3795] Microsoft Office 2000/2003/Xp BMP Image BMPIMP32.FLT memory corruption
2475| [3794] Microsoft Office 2000/2003/Xp PICT bits_per_pixel memory corruption
2476| [3793] Microsoft Office 2000/2003/Xp PICT memory corruption
2477| [3792] Microsoft Office 2000 EPS File memory corruption
2478| [3783] Microsoft Word 2002 memory corruption
2479| [43103] Microsoft Exchange Srv 2007 Sp1 Outlook Web Access cross site scripting
2480| [43102] Microsoft Windows 2000 SP4/Server 2003 SP2/Server 2008 DNS Cache privilege escalation
2481| [3778] Microsoft Exchange 2003/2007 Outlook Web Access cross site scripting
2482| [3777] Microsoft Windows Vista SP1/Server 2008 Explorer memory corruption
2483| [43087] Microsoft Office Snapshot Viewer ActiveX up to Office 2003 Snapshot Viewer ActiveX Control snapview.ocx memory corruption
2484| [43096] Microsoft Publisher 2003/2007 Crypto API unknown vulnerability
2485| [42816] Microsoft Word 2000/2003 memory corruption
2486| [42732] Microsoft Windows XP/Vista/Server 2003 denial of service
2487| [42731] Microsoft Windows Server 2003 denial of service
2488| [3732] Microsoft Windows 2000/Server 2003 WINS memory corruption
2489| [3701] Microsoft Word 2003 CSS Heap-based memory corruption
2490| [3700] Microsoft Word 2003 RTF Document Heap-based memory corruption
2491| [42065] Microsoft SharePoint Server 2.0 Rich Text Editor cross site scripting
2492| [41881] Microsoft Office 2003/2007/2007 Sp1/Xp memory corruption
2493| [41880] Microsoft Project 2000/2002/2003 memory corruption
2494| [41879] Microsoft Windows 2000/Server 2003/Vista Stack-based memory corruption
2495| [41878] Microsoft Windows 2000/Server 2003/Vista spoofing
2496| [41877] Microsoft Windows Server 2003 vbscript.dll memory corruption
2497| [3671] Microsoft Visio 2002/2003/2003 Sp3/2007/2007 Sp1 memory corruption
2498| [3670] Microsoft Visio 2002/2003/2003 Sp3/2007/2007 Sp1 Object memory corruption
2499| [41455] Microsoft Office 2000/2003/2004/Xp memory corruption
2500| [41454] Microsoft Excel 2000/2002/2003/2007 memory corruption
2501| [41453] Microsoft Excel 2000/2002/2003 memory corruption
2502| [41452] Microsoft Excel 2000/2002/2003/2007 memory corruption
2503| [41451] Microsoft Excel 2000/2002/2003 memory corruption
2504| [41450] Microsoft Excel 2000 memory corruption
2505| [41449] Microsoft Excel 2000/2002/2003 memory corruption
2506| [41448] Microsoft Office 2000/Xp Office Web Components memory corruption
2507| [3648] Microsoft Excel 2003 memory corruption
2508| [3647] Microsoft Outlook up to 2007 mailto URI memory corruption
2509| [41003] Microsoft Office 2000/2003/2004/Xp memory corruption
2510| [41002] Microsoft Office 2000/2003/Xp memory corruption
2511| [41001] Microsoft Works 2005/8.0 wkcvqd01.dll memory corruption
2512| [41000] Microsoft Works 2005/8.0 memory corruption
2513| [40998] Microsoft Publisher 2000/2002/2003 memory corruption
2514| [40994] Microsoft Works 2005/8.0 wkcvqd01.dll memory corruption
2515| [40987] Microsoft Windows 2000 denial of service
2516| [40736] Microsoft ActiveX 2.0 ActiveX Control privilege escalation
2517| [3552] Microsoft Excel 2000/2002/2003 File memory corruption
2518| [40242] Microsoft Publisher 2000/2002/2003/2007 Crash denial of service
2519| [40020] Microsoft Office 2007 ZIP Container unknown vulnerability
2520| [39769] Microsoft Windows 2000 cryptgenrandom weak encryption
2521| [39749] Microsoft Windows 2000 msjet40.dll memory corruption
2522| [39655] Microsoft Windows Server 2003 spoofing
2523| [39324] Microsoft Windows Mobile 2005 SMS unknown vulnerability
2524| [3373] Microsoft Word 2000/2002 memory corruption
2525| [38999] Microsoft Windows Server 2003 explorer.exe denial of service
2526| [38899] Microsoft ISA Server 2004 information disclosure
2527| [38728] Microsoft SQL Server 2005 Enterprise Manager sqldmo.dll memory corruption
2528| [38326] Microsoft Windows 2000 attemptwrite memory corruption
2529| [3241] Microsoft Excel 2000/2003/2004/XP SP3 rtWnDesk memory corruption
2530| [3223] Microsoft Windows XP/Server 2003 URI Eingabeung\xC3\xBCltigkeit
2531| [3212] Microsoft DirectX February 2006 RLE Compression Targa Files Heap-based memory corruption
2532| [37739] Microsoft Excel 2000/2002/2003/2004/2007 memory corruption
2533| [37738] Microsoft Office 2002/2003 memory corruption
2534| [3176] Microsoft Excel 2000/2002/2003/2007 File Attribute memory corruption
2535| [3175] Microsoft Excel 2000/2002/2003/2007 Active Worksheet memory corruption
2536| [3174] Microsoft Excel 2000/2002/2003/2007 Version Information memory corruption
2537| [3172] Microsoft Office Publisher 2007 Pointer memory corruption
2538| [37566] Microsoft Excel 2003 unknown vulnerability
2539| [37526] Microsoft Windows 2000/Server 2003 denial of service
2540| [37248] Microsoft Visio 2002 Packaging memory corruption
2541| [37251] Microsoft Windows 2000 memory corruption
2542| [3119] Microsoft Visio 2002 Object memory corruption
2543| [3118] Microsoft Visio 2002 Data memory corruption
2544| [37093] Microsoft Windows Server 2003 Error Message unknown vulnerability
2545| [37010] Microsoft Office 2000 ActiveX Control ouactrl.ocx memory corruption
2546| [36628] Microsoft Word 2000/2002/2003/2004 winword.exe memory corruption
2547| [36616] Microsoft Works 2004/2005/2006 memory corruption
2548| [36621] Microsoft Exchange Server 2000 Integer denial of service
2549| [36620] Microsoft Exchange Server 2000 Outlook Web Access cross site scripting
2550| [36619] Microsoft Exchange Server 2000/2003/2007 memory corruption
2551| [36618] Microsoft Exchange Server 2000 NULL Pointer Dereference denial of service
2552| [36617] Microsoft Excel 2000/2002/2003/2004 memory corruption
2553| [36623] Microsoft BizTalk Server 2004 ActiveX Control capicom.dll memory corruption
2554| [3067] Microsoft Office 2000/2003/2004/2007/Xp Drawing Object memory corruption
2555| [3065] Microsoft Excel 2000/2002/2003/2007 Filter Stack-based memory corruption
2556| [3064] Microsoft Excel 2000/2002/2003/2004/2007 set Font memory corruption
2557| [3063] Microsoft Excel 2000/2002/2003/2007 BIFF Record Stack-based memory corruption
2558| [3012] Microsoft Windows 2000/Server 2003 DNS Service Stack-based memory corruption
2559| [36039] Microsoft Content Management Server 2001 memory corruption
2560| [36052] Microsoft Windows 2000 Heap-based memory corruption
2561| [36051] Microsoft Word 2007 file798-1.doc memory corruption
2562| [36050] Microsoft Word 2007 file789-1.doc memory corruption
2563| [36040] Microsoft Content Management Server 2001 cross site scripting
2564| [3004] Microsoft Windows up to 2003/XP URL Parser memory corruption
2565| [36041] Microsoft .NET Framework 2.0.50727.42 cross site scripting
2566| [2990] Microsoft Windows 2000/XP/Vista Animated Cursor Stack-based memory corruption
2567| [36515] Microsoft Windows 2000/XP/Server 2003 memory corruption
2568| [35846] Microsoft Windows 2000/Server 2003 Default Configuration information disclosure
2569| [35373] Microsoft Excel 2003 denial of service
2570| [35372] Microsoft Office 2003 denial of service
2571| [35206] Microsoft Windows XP/Server 2003 Crash denial of service
2572| [35161] Microsoft ISA Server 2004 unknown vulnerability
2573| [35236] Microsoft Publisher 2007 memory corruption
2574| [2939] Microsoft Word 2000 memory corruption
2575| [34994] Microsoft Windows 2000 OLE Dialog memory corruption
2576| [34993] Microsoft Office 2000/2003/Xp memory corruption
2577| [35001] Microsoft Office 2000/2003/2004/Xp memory corruption
2578| [35000] Microsoft Word 2000/2002/2003 memory corruption
2579| [2933] Microsoft Windows XP SP2/2000 SP4/Server 2003 SP1 OLE Dialog Stack-based memory corruption
2580| [2894] Microsoft Office 2000/2003/2004/Xp Undefined String Format String
2581| [2884] Microsoft Word 2000/2002/2003 memory corruption
2582| [34321] Microsoft Office 2000/2003/2004/Xp Spreadsheet Heap-based memory corruption
2583| [34320] Microsoft Office 2000/2003/2004/Xp memory corruption
2584| [34319] Microsoft Office 2000/2003/2004/Xp memory corruption
2585| [34318] Microsoft Office 2000/2003/2004/Xp memory corruption
2586| [34322] Microsoft Office 2000/2003/Xp memory corruption
2587| [2811] Microsoft Windows 2000/XP/Server 2003 VML Vector Markup Language Integer memory corruption
2588| [2810] Microsoft Outlook 2000/2002/2003 Office Saved Search OSS File memory corruption
2589| [2809] Microsoft Outlook 2000/2002/2003 Header denial of service
2590| [2808] Microsoft Outlook 2000/2002/2003 Meeting VEVENT memory corruption
2591| [2807] Microsoft Excel 2000/2002/2003 XLS File memory corruption
2592| [34126] Microsoft Office 2003 memory corruption
2593| [34122] Microsoft Office Web Components 2000 memory corruption
2594| [2789] Microsoft Windows 2000/XP RPC Request NetrWkstaUserEnum() denial of service
2595| [2765] Microsoft Project Server 2003 pdsrequest.asp weak authentication
2596| [33851] Microsoft Word 2000/2002/2003 12122006-djtest.doc memory corruption
2597| [2739] Microsoft Windows 2000 Remote Installation Service Fehlende Authentifizierung
2598| [2738] Microsoft Windows 2000/XP/Server 2003 SNMP memory corruption
2599| [2737] Microsoft Windows XP/Server 2003 Manifest denial of service
2600| [33766] Microsoft Word 2000/2002/2003 memory corruption
2601| [2718] Microsoft Word 2000/2002/2003 DOC Document memory corruption
2602| [2717] Microsoft Windows 2000 Print Spooler Memory Consumption denial of service
2603| [2689] Microsoft Windows up to 2000 SP4 Active Directory denial of service
2604| [2688] Microsoft Windows 2000/XP/Server 2003 Client Service for Netware denial of service
2605| [2687] Microsoft Windows 2000/XP/Server 2003 Agent ActiveX ACF File Heap-based memory corruption
2606| [2686] Microsoft Windows 2000/XP/Server 2003 Client Service for Netware memory corruption
2607| [2684] Microsoft Windows 2000/XP Workstation Service Stack-based memory corruption
2608| [2659] Microsoft Windows 2000/XP GDI Crash Designfehler
2609| [2655] Microsoft Windows 2000/XP/Server 2003 XML Core Services Designfehler
2610| [33067] Microsoft Visual Studio .net 2005 ActiveX Control wmiscriptutils.dll memory corruption
2611| [2610] Microsoft PowerPoint 2003 PPT Document NULL Pointer Dereference denial of service
2612| [32693] Microsoft Word 2004 memory corruption
2613| [32686] Microsoft Office 2000/2001/2003/2004 Integer memory corruption
2614| [32690] Microsoft Office 2000/2003/2004/Xp memory corruption
2615| [32676] Microsoft Office 2000/2001/2003/2004 memory corruption
2616| [32675] Microsoft Office 2000/2003/2004/Xp memory corruption
2617| [32694] Microsoft Windows 2000 memory corruption
2618| [32689] Microsoft Excel 2000/2002/2003/2004/XP memory corruption
2619| [32688] Microsoft Excel 2000/2002/2003/2004/XP memory corruption
2620| [32687] Microsoft Word 2000/2002 memory corruption
2621| [32685] Microsoft Office 2000/2001/2003/2004 memory corruption
2622| [2601] Microsoft Windows XP/Server 2003 IPv6 Stack denial of service
2623| [2600] Microsoft Windows XP/Server 2003 IPv6 Stack TCP denial of service
2624| [2599] Microsoft Windows XP/Server 2003 IPv6 Stack ICMP denial of service
2625| [2598] Microsoft Windows XP/Server 2003 Object Packager Designfehler
2626| [2597] Microsoft Office 2003/Xp Smart-Tag Parser memory corruption
2627| [2596] Microsoft Office 2000/2003/2004/Xp Value Read memory corruption
2628| [2595] Microsoft Office 2000/2001/2003/2004 Diagram Value memory corruption
2629| [2594] Microsoft Office 2000/2001/2003/2004 Document memory corruption
2630| [2593] Microsoft ASP.NET 2.0 cross site scripting
2631| [2571] Microsoft PowerPoint up to 2003 Document memory corruption
2632| [2554] Microsoft PowerPoint 2000 memory corruption
2633| [2522] Microsoft Windows 2000/XP/Server 2003 Indexing Service cross site scripting
2634| [2521] Microsoft Publisher 2000/2002/2003 PUB File Stack-based memory corruption
2635| [2508] Microsoft Word 2000 memory corruption
2636| [2478] Microsoft Internet Explorer up to 6 on Win 2000 HTTP 1.1 Compression Heap-based memory corruption
2637| [31692] Microsoft PowerPoint 2000/2001/2002/2003 memory corruption
2638| [2436] Microsoft Windows 2000/XP/Server 2003 Kernel memory corruption
2639| [2435] Microsoft Windows 2000/XP/Server 2003 Exception memory corruption
2640| [2434] Microsoft Windows 2000/XP/Server 2003 Winlogon race condition
2641| [2433] Microsoft Windows 2000 Management Console cross site scripting
2642| [2432] Microsoft Windows 2000/XP/Server 2003 DNS Resolver Heap-based memory corruption
2643| [2431] Microsoft Windows 2000/XP/Server 2003 Winsock API memory corruption
2644| [2430] Microsoft Windows 2000/XP/Server 2003 RPC ELV memory corruption
2645| [2426] Microsoft Windows 2000/XP/Server 2003 WMF File gdi32.dll denial of service
2646| [2415] Microsoft Windows 2000/XP/Server 2003 SMB File srv.sys denial of service
2647| [31527] Microsoft Internet Explorer 6.0 on Win 2000 ActiveX Object Stack-Based denial of service
2648| [31358] Microsoft PowerPoint 2003 powerpnt.exe denial of service
2649| [31354] Microsoft PowerPoint 2003 memory corruption
2650| [31351] Microsoft ISA Server 2004 Filters unknown vulnerability
2651| [2382] Microsoft PowerPoint up to 2003 Presentation Open/Close memory corruption
2652| [2378] Microsoft PowerPoint 2000/2002/2003 Document Parser memory corruption
2653| [31318] Microsoft Excel 2000/2002/2003/2004/XP memory corruption
2654| [31317] Microsoft Excel 2000/2002/2003/2004/XP memory corruption
2655| [31316] Microsoft Excel 2000/2002/2003/2004/XP memory corruption
2656| [31313] Microsoft Excel 2000/2002/2003/2004/XP memory corruption
2657| [31312] Microsoft Excel 2000/2002/2003/2004/XP memory corruption
2658| [31311] Microsoft Excel 2000/2002/2003/XP memory corruption
2659| [31310] Microsoft Excel 2000/2002/2003/2004/XP memory corruption
2660| [31237] Microsoft Office 2000/2003/Xp memory corruption
2661| [31235] Microsoft Office 2000/2003/Xp memory corruption
2662| [2371] Microsoft NET Framework up to 2.0 URL Validator unknown vulnerability
2663| [2370] Microsoft Windows 2000/XP/Server 2003 Server Protocol Driver Server Message Block Heap-based memory corruption
2664| [2369] Microsoft Windows 2000/XP/Server 2003 Server Service Mailslot Heap-based memory corruption
2665| [2367] Microsoft Office 2000/2003/XP Document String memory corruption
2666| [2366] Microsoft Windows 2000/XP/Server 2003 DHCP Client memory corruption
2667| [2365] Microsoft Office 2000/2003/XP PNG Image memory corruption
2668| [2364] Microsoft Office 2000/2003/XP GIF Image memory corruption
2669| [31233] Microsoft Office 2000/2003/Xp mso.dll lscreateline memory corruption
2670| [31238] Microsoft Internet Explorer 6.0 on Win 2000 Crash denial of service
2671| [2357] Microsoft Excel up to 2003 on Asian System Document Repair Style memory corruption
2672| [31133] Microsoft Windows XP/Server 2003 explorer.exe memory corruption
2673| [2325] Microsoft Excel up to 2003 Hyperlink hlink.dll Long Hyperlink memory corruption
2674| [2324] Microsoft Excel 2000/2002/2003/2004 XLS File memory corruption
2675| [30801] Microsoft Windows up to 2000 Connection Manager Stack-based memory corruption
2676| [2312] Microsoft Exchange 2000 Outlook Web Access cross site scripting
2677| [2311] Microsoft Windows 2000/XP/Server 2003 MRXSMB.SYS MRxSmbCscIoctlOpenForCopyChunk memory corruption
2678| [2310] Microsoft Windows 2000 RPC spoofing
2679| [2309] Microsoft Windows 2000/XP/Server 2003 Routing and Remote Access Service RPC Request memory corruption
2680| [2308] Microsoft PowerPoint 2000/2002/2003/2004 PPT Document memory corruption
2681| [2307] Microsoft Windows 2000/XP/Server 2003 JScript Object memory corruption
2682| [2306] Microsoft Windows 2000/XP/Server 2003 IP Source Routing memory corruption
2683| [2305] Microsoft Windows XP/Server 2003 ART Image Heap-based memory corruption
2684| [2294] Microsoft Word up to 2003 DOC Document Backdoor Designfehler
2685| [2275] Microsoft Windows XP/Server 2003 mhtml URI inetcomm.dll memory corruption
2686| [2253] Microsoft Word up to 2003 Backdoor memory corruption
2687| [2221] Microsoft Windows 2000/XP CHM Archive itss.dll memory corruption
2688| [30131] Microsoft Windows NT 4.0/XP/2000/Server 2003 Distributed Transaction Coordinator Crash denial of service
2689| [2218] Microsoft Windows 2000/XP/Server 2003 MSDTC Heap-based denial of service
2690| [2217] Microsoft Exchange 2000/2003 Calender Collaboration Data Object memory corruption
2691| [2190] Microsoft Office 2003 mailto URI unknown vulnerability
2692| [2147] Microsoft Windows 2000/XP/Server 2003 COM Object memory corruption
2693| [2135] Microsoft FrontPage Server Extensions 2002 cross site scripting
2694| [29524] Microsoft ISA Server 2004 unknown vulnerability
2695| [134750] Microsoft ASP.NET Core 2.1/2.2 denial of service
2696| [134745] Microsoft SharePoint Foundation 2013 SP1 cross site scripting
2697| [134744] Microsoft Windows up to Server 2019 GDI information disclosure
2698| [134743] Microsoft SharePoint Server 2013 SP1/2016 cross site scripting
2699| [134742] Microsoft SharePoint Enterprise Server 2016/2019 cross site scripting
2700| [134741] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
2701| [134740] Microsoft SharePoint Enterprise Server 2013 SP1/2016 privilege escalation
2702| [134739] Microsoft SharePoint Foundation 2010 SP2/2013 SP2 cross site scripting
2703| [134738] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
2704| [134737] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
2705| [134736] Microsoft Office 2010 SP2 Access Connectivity Engine memory corruption
2706| [134735] Microsoft Office up to 2019 Access Connectivity Engine memory corruption
2707| [134734] Microsoft Office up to 2019 Access Connectivity Engine memory corruption
2708| [134733] Microsoft Windows up to Server 2019 Unified Write Filter privilege escalation
2709| [134731] Microsoft Windows up to Server 2019 Symlink privilege escalation
2710| [134729] Microsoft Windows up to Server 2019 Storage Service privilege escalation
2711| [134725] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
2712| [134724] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
2713| [134723] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
2714| [134722] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
2715| [134721] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
2716| [134720] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
2717| [134719] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
2718| [134718] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
2719| [134717] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
2720| [134716] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
2721| [134715] Microsoft Windows up to Server 2019 Win32k memory corruption
2722| [134714] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
2723| [134713] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
2724| [134712] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
2725| [134710] Microsoft Windows up to Server 2019 GDI information disclosure
2726| [134709] Microsoft Windows up to Server 2019 Kernel privilege escalation
2727| [134706] Microsoft Windows up to Server 2019 Error Reporting privilege escalation
2728| [134704] Microsoft SQL Server 2017 Analysis Services information disclosure
2729| [134701] Microsoft Windows up to Server 2019 Windows Defender Application Control privilege escalation
2730| [134700] Microsoft Windows up to Server 2019 Diagnostic Hub privilege escalation
2731| [134699] Microsoft Windows up to Server 2019 NDIS ndis.sys memory corruption
2732| [134698] Microsoft Windows up to Server 2019 OLE memory corruption
2733| [134697] Microsoft Office/Word 2016/2019/365 ProPlus memory corruption
2734| [134684] Microsoft Windows up to Server 2019 DHCP Server memory corruption
2735| [134678] Microsoft Windows up to Server 2019 GDI+ memory corruption
2736| [133236] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
2737| [133235] Microsoft Azure DevOps Server 2019 privilege escalation
2738| [133234] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
2739| [133232] Microsoft Azure DevOps Server 2019 cross site scripting
2740| [133229] Microsoft Azure DevOps Server 2019 cross site scripting
2741| [133224] Microsoft Exchange Server 2013 CU22/2016 CU11/2016 CU12/2019/2019 CU1 Outlook Web Access privilege escalation
2742| [133223] Microsoft Azure DevOps Server 2019 Content Security Policy privilege escalation
2743| [133222] Microsoft Windows up to Server 2019 Remote Registry Service memory corruption
2744| [133221] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
2745| [133220] Microsoft Windows up to Server 2019 GDI Memory information disclosure
2746| [133219] Microsoft Windows up to Server 2019 Win32k Memory information disclosure
2747| [133218] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
2748| [133217] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
2749| [133216] Microsoft Windows up to Server 2019 Kernel Memory information disclosure
2750| [133215] Microsoft Windows up to Server 2019 VBScript Engine memory corruption
2751| [133214] Microsoft Windows up to Server 2019 AppX Deployment Service privilege escalation
2752| [133213] Microsoft Windows up to Server 2019 Kernel Memory information disclosure
2753| [133212] Microsoft Windows up to Server 2019 Terminal Services Memory information disclosure
2754| [133211] Microsoft Windows up to Server 2019 Task Scheduler information disclosure
2755| [133209] Microsoft Windows up to Server 2019 LUAFV Driver luafv.sys privilege escalation
2756| [133206] Microsoft SharePoint Enterprise Server 2010 SP2/2013 SP1/2016/2019 cross site scripting
2757| [133205] Microsoft SharePoint Enterprise Server 2013 SP1/2016/2019 cross site scripting
2758| [133204] Microsoft Office/Excel up to 2019 memory corruption
2759| [133203] Microsoft Office up to 2019 Access Connectivity Engine memory corruption
2760| [133202] Microsoft Office up to 2019 Access Connectivity Engine memory corruption
2761| [133201] Microsoft Office up to 2019 Access Connectivity Engine memory corruption
2762| [133200] Microsoft Office up to 2019 Access Connectivity Engine memory corruption
2763| [133199] Microsoft Office 2010 SP2 Access Connectivity Engine memory corruption
2764| [133198] Microsoft Exchange Server up to 2019 CU1 Outlook Web Access cross site scripting
2765| [133197] Microsoft ASP.NET Core 2.2 Request denial of service
2766| [133196] Microsoft Windows up to Server 2019 Win32k information disclosure
2767| [133195] Microsoft Windows up to Server 2019 LUAFV Driver luafv.sys privilege escalation
2768| [133194] Microsoft Windows up to Server 2019 GDI Memory information disclosure
2769| [133193] Microsoft Windows up to Server 2019 LUAFV Driver luafv.sys privilege escalation
2770| [133192] Microsoft Windows up to Server 2019 OLE Automation privilege escalation
2771| [133189] Microsoft Windows up to Server 2019 CSRSS memory corruption
2772| [133188] Microsoft Windows up to Server 2019 LUAFV Driver luafv.sys privilege escalation
2773| [133187] Microsoft Windows up to Server 2019 LUAFV Driver luafv.sys privilege escalation
2774| [133186] Microsoft Windows up to Server 2019 TCP/IP Stack Fragmented IP Packet information disclosure
2775| [133185] Microsoft Windows up to Server 2019 Win32k memory corruption
2776| [133184] Microsoft Office 2016 for Mac/2019/365 ProPlus Graphics Component memory corruption
2777| [133183] Microsoft Windows up to Server 2019 Win32k memory corruption
2778| [133182] Microsoft Windows up to Server 2019 Win32k memory corruption
2779| [133181] Microsoft Office/Excel/PowerPoint up to 2019 URL Document Code Execution
2780| [133180] Microsoft Windows up to Server 2019 MS XML Code Execution
2781| [133179] Microsoft Windows up to Server 2019 MS XML Code Execution
2782| [133177] Microsoft Windows up to Server 2019 Device Guard luafv.sys privilege escalation
2783| [133174] Microsoft Windows up to Server 2019 GDI+ privilege escalation
2784| [133173] Microsoft Windows up to Server 2019 IOleCvt Interface privilege escalation
2785| [133166] Microsoft Windows up to Server 2019 MS XML Code Execution
2786| [133165] Microsoft Windows up to Server 2019 MS XML Code Execution
2787| [133164] Microsoft Windows up to Server 2019 MS XML Code Execution
2788| [133163] Microsoft Windows up to Server 2019 MS XML Code Execution
2789| [133162] Microsoft Windows up to Server 2019 MS XML Code Execution
2790| [131687] Microsoft Team Foundation Server 2017 Update 3.1/2018 Update 3.2/2018 Updated 1.2 cross site scripting
2791| [131685] Microsoft Windows up to Server 2019 SMB information disclosure
2792| [131684] Microsoft Visual Studio 2017 Version 15.9 C++ Redistributable Installer privilege escalation
2793| [131681] Microsoft Windows up to Server 2019 Win32k memory corruption
2794| [131679] Microsoft Windows up to Server 2019 Kernel information disclosure
2795| [131675] Microsoft SharePoint 2013 SP1/2016 cross site scripting
2796| [131674] Microsoft Windows up to Server 2019 Win32k information disclosure
2797| [131673] Microsoft Windows up to Server 2019 Kernel information disclosure
2798| [131672] Microsoft Windows up to Server 2019 GDI information disclosure
2799| [131671] Microsoft Windows up to Server 2019 VBScript Engine memory corruption
2800| [131668] Microsoft Windows up to Server 2019 AppX Deployment Server privilege escalation
2801| [131667] Microsoft Windows up to Server 2019 Comctl32.dll memory corruption
2802| [131663] Microsoft Windows up to Server 2019 Print Spooler information disclosure
2803| [131658] Microsoft Windows up to Server 2019 information disclosure
2804| [131657] Microsoft Windows up to Server 2019 denial of service
2805| [131656] Microsoft Office 2010 SP2 Connectivity Engine memory corruption
2806| [131653] Microsoft Windows up to Server 2019 SMB information disclosure
2807| [131652] Microsoft Windows up to Server 2019 SMB information disclosure
2808| [131651] Microsoft Windows up to Server 2019 Kernel information disclosure
2809| [131650] Microsoft Windows 10 1803/10 1809/Server 2019/Server 1803 Hyper-V denial of service
2810| [131649] Microsoft Windows up to Server 2019 Kernel memory corruption
2811| [131648] Microsoft Windows up to Server 2019 Hyper-V denial of service
2812| [131644] Microsoft Windows up to Server 2019 Hyper-V denial of service
2813| [131638] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
2814| [131632] Microsoft Windows 10 1803/10 1809/Server 2019/Server 1803 DHCP Client memory corruption
2815| [131631] Microsoft Windows 10 1803/10 1809/Server 2019/Server 1803 DHCP Client memory corruption
2816| [131630] Microsoft Windows 10 1803/10 1809/Server 2019/Server 1803 DHCP Client memory corruption
2817| [131629] Microsoft Windows up to Server 2019 Deployment Services TFTP Server memory corruption
2818| [131628] Microsoft Windows up to Server 2019 ActiveX memory corruption
2819| [131619] Microsoft Windows up to Server 2019 MS XML privilege escalation
2820| [131334] Microsoft Team Foundation Server 2018 Update 3.2 cross site scripting
2821| [131333] Microsoft Team Foundation Server 2018 Update 3.2 cross site scripting
2822| [131330] Microsoft Exchange Server 2010 SP3 UR26/2013 CU22/2016 CU12/2019 CU1 privilege escalation
2823| [131329] Microsoft Excel 2010 SP2/2013 SP1/2013 RT SP1/2016 information disclosure
2824| [131328] Microsoft Windows up to Server 2016 Kernel information disclosure
2825| [130832] Microsoft 2013 SP1 spoofing
2826| [130828] Microsoft Exchange Server 2010 SP3/2013 CU22/2016 CU12/2019 CU1 EWS privilege escalation
2827| [130826] Microsoft Office 2010 SP2 Connectivity Engine memory corruption
2828| [130825] Microsoft Office up to 2019 Connectivity Engine memory corruption
2829| [130824] Microsoft Office up to 2019 Connectivity Engine memory corruption
2830| [130823] Microsoft Office up to 2019 Connectivity Engine privilege escalation
2831| [130822] Microsoft Office up to 2019 Connectivity Engine privilege escalation
2832| [130821] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
2833| [130820] Microsoft Windows up to Server 2012 R2 GDI information disclosure
2834| [130818] Microsoft Windows up to Server 2019 GDI information disclosure
2835| [130817] Microsoft Windows up to Server 2019 Storage Service privilege escalation
2836| [130814] Microsoft Windows up to Server 2019 privilege escalation
2837| [130809] Microsoft Windows up to Server 2019 Defender Firewall Security privilege escalation
2838| [130808] Microsoft Windows up to Server 2019 information disclosure
2839| [130807] Microsoft Windows up to Server 2019 Hyper-V information disclosure
2840| [130806] Microsoft Windows up to Server 2019 SMB privilege escalation
2841| [130805] Microsoft Windows up to Server 2019 Device Guard privilege escalation
2842| [130804] Microsoft Windows up to Server 2019 Device Guard privilege escalation
2843| [130803] Microsoft Windows up to Server 2019 SMB privilege escalation
2844| [130802] Microsoft Windows up to Server 2019 Win32k information disclosure
2845| [130801] Microsoft Windows up to Server 2019 Device Guard privilege escalation
2846| [130800] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
2847| [130799] Microsoft Windows up to Server 2016 Win32k memory corruption
2848| [130798] Microsoft Windows up to Server 2019 GDI information disclosure
2849| [130797] Microsoft Windows up to Server 2019 GDI information disclosure
2850| [130796] Microsoft Windows up to Server 2019 GDI information disclosure
2851| [130793] Microsoft Windows up to Server 2019 GDI information disclosure
2852| [130792] Microsoft Windows up to Server 2019 HID information disclosure
2853| [130791] Microsoft Windows up to Server 2019 HID information disclosure
2854| [130790] Microsoft Windows up to Server 2016 JET Database Engine memory corruption
2855| [130789] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
2856| [130788] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
2857| [130787] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
2858| [130786] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
2859| [130785] Microsoft Office 2010 SP2/2013 SP1/2016/2019/365 ProPlus Security Feature Phishing spoofing
2860| [130784] Microsoft Windows up to Server 2019 GDI+ memory corruption
2861| [130782] Microsoft Windows up to Server 2019 DHCP Server memory corruption
2862| [130781] Microsoft Windows up to Server 2019 GDI+ memory corruption
2863| [129847] Microsoft Team Foundation Server 2017 Update 3.1/2018 Update 1.2/2018 Update 3.2 information disclosure
2864| [129846] Microsoft Team Foundation Server 2018 Update 3.2 cross site scripting
2865| [129845] Microsoft Skype for Business 2015 CU 8 Request cross site scripting
2866| [128765] Microsoft Visual Studio 2017 Version 15.9 C++ Construct privilege escalation
2867| [128764] Microsoft Exchange Server 2010 SP3/2013 CU21/2016 CU10/2016 CU11/2019 PowerShell API information disclosure
2868| [128762] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016/365 ProPlus Word memory corruption
2869| [128761] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
2870| [128760] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
2871| [128759] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
2872| [128758] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
2873| [128757] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
2874| [128756] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
2875| [128755] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
2876| [128754] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
2877| [128753] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
2878| [128752] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
2879| [128751] Microsoft Windows up to Server 2019 Data Sharing Service privilege escalation
2880| [128750] Microsoft Windows up to Server 2019 Runtime privilege escalation
2881| [128749] Microsoft Windows up to Server 2019 Kernel information disclosure
2882| [128747] Microsoft ASP.NET Core 2.1 Web Request denial of service
2883| [128746] Microsoft SharePoint Enterprise Server 2013 SP1/2016/2019 cross site scripting
2884| [128745] Microsoft Office up to 2019 Word Macro information disclosure
2885| [128744] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016/365 ProPlus information disclosure
2886| [128743] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016/365 ProPlus information disclosure
2887| [128742] Microsoft SharePoint Enterprise Server 2013 SP1/2016/2019 cross site scripting
2888| [128741] Microsoft SharePoint Enterprise Server 2016 cross site scripting
2889| [128740] Microsoft SharePoint Enterprise Server 2013 SP1 cross site scripting
2890| [128739] Microsoft Windows up to Server 2019 Kernel information disclosure
2891| [128738] Microsoft Windows up to Server 2019 Subsystem for Linux information disclosure
2892| [128737] Microsoft Windows up to Server 2019 COM Desktop Broker privilege escalation
2893| [128736] Microsoft Windows up to Server 2019 Kernel information disclosure
2894| [128735] Microsoft ASP.NET Core 2.1/2.2 Web Request denial of service
2895| [128733] Microsoft Windows up to Server 2019 Authentication Request privilege escalation
2896| [128732] Microsoft Office 2010 SP2/2013 SP1/2016/2019/365 ProPlus MSHTML Engine privilege escalation
2897| [128729] Microsoft Visual Studio 2010 SP1/2012 Update 5 vscontent File information disclosure
2898| [128728] Microsoft Windows up to Server 2019 Kernel information disclosure
2899| [128727] Microsoft Windows up to Server 2019 Data Sharing Service privilege escalation
2900| [128726] Microsoft Windows up to Server 2019 Data Sharing Service privilege escalation
2901| [128725] Microsoft Windows up to Server 2019 Data Sharing Service privilege escalation
2902| [128718] Microsoft Windows up to Server 2019 Hyper-V memory corruption
2903| [128717] Microsoft Windows 10 1803/10 1809/Server 2019/Server 1803 Hyper-V memory corruption
2904| [127925] Microsoft SharePoint Enterprise Server 2016 Web Request cross site scripting
2905| [127882] Microsoft Dynamics NAV 2016/2017 Web Request cross site scripting
2906| [127881] Microsoft Windows 10 1809/Server 2019 Object denial of service
2907| [127880] Microsoft Windows up to Server 2019 Win32k Object memory corruption
2908| [127828] Microsoft Windows up to Server 2019 Win32k memory corruption
2909| [127827] Microsoft Windows 10 1809/Server 2019 DirectX information disclosure
2910| [127826] Microsoft Windows 10 1803/10 1809/Server 2019/Server 1803 Win32k ASLR privilege escalation
2911| [127825] Microsoft SharePoint Enterprise Server 2010 SP2/2013 SP1/2016 privilege escalation
2912| [127824] Microsoft Excel up to 2019 Out-of-Bounds memory corruption
2913| [127823] Microsoft Windows up to Server 2012 R2 Kernel information disclosure
2914| [127821] Microsoft Windows up to Server 2019 Connected User Experiences and Telemetry Service denial of service
2915| [127820] Microsoft Windows up to Server 2019 Kernel memory corruption
2916| [127819] Microsoft Exchange Server 2016 CU10/2016 CU11 Profile Data privilege escalation
2917| [127817] Microsoft Excel up to 2019 information disclosure
2918| [127816] Microsoft Windows up to Server 2019 GDI information disclosure
2919| [127815] Microsoft Windows up to Server 2019 GDI information disclosure
2920| [127814] Microsoft SharePoint Enterprise Server 2010 SP2/2013 SP1/2016 Search cross site request forgery
2921| [127812] Microsoft Windows up to Server 2019 Remote Procedure Call information disclosure
2922| [127809] Microsoft PowerPoint 2010 SP2/2013 RT SP1/2013 SP1/2016/365 ProPlus memory corruption
2923| [127806] Microsoft Outlook up to 2019 memory corruption
2924| [127805] Microsoft Excel up to 2019 memory corruption
2925| [127804] Microsoft Excel up to 2019 memory corruption
2926| [127803] Microsoft Windows up to Server 2019 Text-To-Speech memory corruption
2927| [127801] Microsoft Windows up to Server 2019 DNS Server privilege escalation
2928| [126938] Microsoft Team Foundation Server 2018 Update 1.1/2018 Update 3 Code Execution
2929| [126755] Microsoft .NET Core 2.1 privilege escalation
2930| [126754] Microsoft Skype for Business/Lync Server 2013 SP1/2016 Emoji denial of service
2931| [126750] Microsoft Windows up to Server 2019 ALPC privilege escalation
2932| [126749] Microsoft Exchange Server 2010/2013/2016/2019 privilege escalation
2933| [126748] Microsoft Office 2019/365 ProPlus Outlook Message information disclosure
2934| [126747] Microsoft SharePoint Enterprise Server 2013 SP1 Folder information disclosure
2935| [126746] Microsoft Outlook 2010 SP2/2013 SP1/2013 RT SP1/2016 memory corruption
2936| [126745] Microsoft Project 2010 SP2/2013 SP1/2016 memory corruption
2937| [126744] Microsoft Office up to 2019 Word memory corruption
2938| [126743] Microsoft SharePoint Enterprise Server 2013 SP1/2016/2019 cross site scripting
2939| [126742] Microsoft SharePoint Enterprise Server 2013 SP1/2016/2019 cross site scripting
2940| [126739] Microsoft Windows up to Server 2012 R2 Win32k information disclosure
2941| [126737] Microsoft Windows up to Server 2012 R2 DirectX information disclosure
2942| [126736] Microsoft Windows up to Server 2019 Win32k memory corruption
2943| [126735] Microsoft Windows up to Server 2019 DirectX privilege escalation
2944| [126734] Microsoft Office 2019/365 ProPlus information disclosure
2945| [126733] Microsoft Windows 10 1803/10 1809/Server 2019/Server 1803 DirectX memory corruption
2946| [126730] Microsoft Windows up to Server 2019 Active Directory Federation Services cross site scripting
2947| [126728] Microsoft Office/SharePoint 2010 SP2 Word memory corruption
2948| [126727] Microsoft Outlook 2010 SP2/2013 SP1/2013 RT SP1/2016 memory corruption
2949| [126726] Microsoft Outlook 2010 SP2/2013 SP1/2013 RT SP1/2016 memory corruption
2950| [126725] Microsoft Windows up to Server 2019 DirectX memory corruption
2951| [126722] Microsoft Windows up to Server 2019 PowerShell privilege escalation
2952| [126718] Microsoft Windows up to Server 2016 Search memory corruption
2953| [126717] Microsoft Outlook 2010 SP2/2013 SP1/2013 RT SP1/2016/2019 memory corruption
2954| [126716] Microsoft Office up to 2019 Excel memory corruption
2955| [126715] Microsoft Office 2016/2019/365 ProPlus Excel memory corruption
2956| [126714] Microsoft Windows up to Server 2019 PowerShell unknown vulnerability
2957| [126713] Microsoft Windows up to Server 2019 VBScript Engine memory corruption
2958| [126712] Microsoft Windows up to Server 2016 Graphics Component memory corruption
2959| [126711] Microsoft Windows up to Server 2019 Deployment Services TFTP Server memory corruption
2960| [125123] Microsoft Windows up to Server 2019 Codecs Library information disclosure
2961| [125122] Microsoft Windows up to Server 2016 TCP/IP information disclosure
2962| [125121] Microsoft Windows up to Server 2019 DirectX memory corruption
2963| [125120] Microsoft Windows up to Server 2019 Windows Media Player information disclosure
2964| [125119] Microsoft Windows up to Server 2019 Windows Media Player information disclosure
2965| [125116] Microsoft Exchange Server 2013 CU21/2016 CU10 privilege escalation
2966| [125115] Microsoft Windows up to Server 2019 Theme API privilege escalation
2967| [125114] Microsoft Windows up to Server 2019 Windows Shell privilege escalation
2968| [125113] Microsoft Windows up to Server 2019 Kernel memory corruption
2969| [125111] Microsoft Windows up to Server 2019 Device Guard Code Integrity Policy privilege escalation
2970| [125110] Microsoft Windows up to Server 2019 DNS Global Blocklist privilege escalation
2971| [125109] Microsoft Windows up to Server 2019 NTFS privilege escalation
2972| [125108] Microsoft Windows up to Server 2019 Filter Manager memory corruption
2973| [125107] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
2974| [125106] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
2975| [125105] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
2976| [125104] Microsoft SharePoint Enterprise Server 2016 cross site scripting
2977| [125102] Microsoft Office/Word 2010 SP2/2013 RT SP1/2013 SP1/2016/2019 Protected View memory corruption
2978| [125100] Microsoft Office/Powerpoint 2010 SP2/2013 RT SP1/2013 SP1/2016/2019 Protected View memory corruption
2979| [125099] Microsoft Office/Excel up to 2019 Protected View memory corruption
2980| [125098] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
2981| [125097] Microsoft Windows up to Server 2019 DirectX Graphics memory corruption
2982| [125096] Microsoft Windows up to Server 2019 Win32k memory corruption
2983| [125095] Microsoft Exchange Server 2013 CU21/2016 CU10 Outlook Web Access cross site scripting
2984| [125093] Microsoft Windows up to Server 2019 Hyper-V memory corruption
2985| [125092] Microsoft Windows up to Server 2019 Hyper-V memory corruption
2986| [125091] Microsoft Windows up to Server 2019 MS XML privilege escalation
2987| [124371] Microsoft Exchange Server up to 2010 SP3 Outlook Web Access /owa/auth/logon.aspx Parameter Server-Side Request Forgery
2988| [124217] Microsoft Windows Server 2012/Server 2016 Active Directory Federation Services /adfs/ls Server-Side Request Forgery
2989| [123995] Microsoft Lync 2011 on Mac Security Feature Messages Download privilege escalation
2990| [123881] Microsoft Windows up to Server 2016 Sandbox privilege escalation
2991| [123874] Microsoft Windows up to Server 2016 Kernel information disclosure
2992| [123872] Microsoft Windows 8.1/RT 8.1/10/Server 2012/Server 2012 R2 SMB information disclosure
2993| [123868] Microsoft Windows up to Server 2016 Hyper-V denial of service
2994| [123864] Microsoft Windows up to Server 2016 Hyper-V information disclosure
2995| [123862] Microsoft SharePoint Enterprise Server 2010 SP2/2013 SP1/2013 RT SP1/2016 cross site scripting
2996| [123861] Microsoft Excel 2010 SP2/2013 SP1/2013 RT SP1/2016/2016 C2R information disclosure
2997| [123860] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
2998| [123859] Microsoft SharePoint Enterprise Server 2010 SP2/2013 SP1/2016 cross site scripting
2999| [123851] Microsoft Windows up to Server 2016 ALPC privilege escalation
3000| [123849] Microsoft Windows up to Server 2016 SMB denial of service
3001| [123846] Microsoft Office 2016 on Win/Mac memory corruption
3002| [123844] Microsoft Word 2013 SP1/2013 RT SP1/2016 PDF File memory corruption
3003| [123843] Microsoft Windows up to Server 2016 JET Database Engine memory corruption
3004| [123842] Microsoft Windows up to Server 2016 JET Database Engine memory corruption
3005| [123830] Microsoft Windows up to Server 2016 Hyper-V memory corruption
3006| [123828] Microsoft Windows up to Server 2016 Win32k Graphics privilege escalation
3007| [123827] Microsoft Windows up to Server 2016 Image memory corruption
3008| [123825] Microsoft Windows up to Server 2016 MSXML Parser privilege escalation
3009| [123823] Microsoft Windows up to Server 2016 Hyper-V privilege escalation
3010| [122887] Microsoft Office 2016 on Mac AutoUpdate memory corruption
3011| [122886] Microsoft Windows up to Server 2016 DirectX Graphics memory corruption
3012| [122885] Microsoft Windows up to Server 2016 DirectX Graphics memory corruption
3013| [122884] Microsoft Windows up to Server 2016 Win32k memory corruption
3014| [122883] Microsoft Windows up to Server 2016 DirectX Graphics memory corruption
3015| [122875] Microsoft Excel 2010 SP2/2013 SP1/2013 RT SP1/2016/2016 C2R information disclosure
3016| [122874] Microsoft Excel 2010 SP2/2013 SP1/2013 RT SP1/2016/2016 C2R memory corruption
3017| [122873] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R information disclosure
3018| [122872] Microsoft SharePoint Enterprise Server 2013 SP1/2016 information disclosure
3019| [122871] Microsoft PowerPoint 2010 SP2 memory corruption
3020| [122870] Microsoft Excel 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R memory corruption
3021| [122861] Microsoft Windows up to Server 2016 Microsoft COM for Windows privilege escalation
3022| [122850] Microsoft Visual Studio 2015 Update 3/2017/2017 Version 15.8 Diagnostic Hub privilege escalation
3023| [122849] Microsoft Windows up to Server 2016 Diagnostic Hub privilege escalation
3024| [122848] Microsoft Windows Security Feature 2FA weak authentication
3025| [122834] Microsoft Windows up to Server 2016 LNK memory corruption
3026| [122825] Microsoft Windows up to Server 2016 Graphics memory corruption
3027| [122823] Microsoft SQL Server 2016 SP1/2016 SP2/2017 memory corruption
3028| [121208] Microsoft Outlook 2010 SP2/2013 SP1/2013 RT SP1/2016/2016 C2R Attachment privilege escalation
3029| [121118] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
3030| [121116] Microsoft Windows up to Server 2016 Sandbox privilege escalation
3031| [121114] Microsoft Access 2013 SP1/2016/2016 C2R memory corruption
3032| [121111] Microsoft Windows up to Server 2016 Kernel memory corruption
3033| [121110] Microsoft Windows up to Server 2016 Wordpad privilege escalation
3034| [121107] Microsoft Windows up to Server 2016 DNSAPI DNSAPI.dll denial of service
3035| [121106] Microsoft SharePoint Enterprise Server 2013 SP1/2016 privilege escalation
3036| [121105] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
3037| [121098] Microsoft Office 2016/2016 C2R memory corruption
3038| [121092] Microsoft Windows up to Server 2016 FTP Server denial of service
3039| [121090] Microsoft Visual Studio up to 2017 Version 15.8 Preview privilege escalation
3040| [119479] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
3041| [119477] Microsoft Excel 2010 SP2/2013 RT SP1/2013 SP1/2016 information disclosure
3042| [119476] Microsoft Publisher 2010 SP2 OLE Object PUB File privilege escalation
3043| [119475] Microsoft Outlook 2010 SP2/2013 RT SP1/2013 SP1/2016 Attachment privilege escalation
3044| [119474] Microsoft Windows up to Server 2016 GDI information disclosure
3045| [119470] Microsoft Windows up to Server 2016 HTTP HTTP.sys denial of service
3046| [119468] Microsoft Windows up to Server 2016 Device Guard Code Integrity Policy privilege escalation
3047| [119467] Microsoft Windows up to Server 2016 Hypervisor privilege escalation
3048| [119465] Microsoft Windows up to Server 2016 Device Guard Code Integrity Policy privilege escalation
3049| [119464] Microsoft Windows up to Server 2016 Device Guard Code Integrity Policy privilege escalation
3050| [119463] Microsoft Windows up to Server 2016 Device Guard Code Integrity Policy privilege escalation
3051| [119461] Microsoft Windows up to Server 2016 Device Guard Code Integrity Policy privilege escalation
3052| [119460] Microsoft Windows up to Server 2016 Device Guard Code Integrity Policy privilege escalation
3053| [119459] Microsoft Windows up to Server 2016 memory corruption
3054| [119457] Microsoft Windows up to Server 2016 Desktop Bridge privilege escalation
3055| [119456] Microsoft Windows up to Server 2016 Kernel information disclosure
3056| [119455] Microsoft Windows up to Server 2016 denial of service
3057| [119454] Microsoft Windows up to Server 2016 Device Guard Code Integrity Policy privilege escalation
3058| [119452] Microsoft Windows up to Server 2016 HIDParser memory corruption
3059| [119448] Microsoft Windows up to Server 2016 Code Integrity Module denial of service
3060| [119447] Microsoft Windows up to Server 2016 NTFS privilege escalation
3061| [119441] Microsoft Windows up to Server 2016 Media Foundation memory corruption
3062| [119437] Microsoft Windows up to Server 2016 HTTP Protocol Stack Http.sys memory corruption
3063| [119436] Microsoft Windows up to Server 2016 memory corruption
3064| [119431] Microsoft Windows up to Server 2016 DNSAPI DNSAPI.dll DNS Response privilege escalation
3065| [118120] Microsoft Office 2016 on Mac XML Data Code Execution
3066| [117561] Microsoft SharePoint Enterprise Server 2010 SP2/2013 SP1 Web Request cross site scripting
3067| [117560] Microsoft Exchange Server up to 2016 CU9 Code Execution memory corruption
3068| [117559] Microsoft Exchange Server 2016 CU8/2016 CU9 Outlook Web Access Web Request cross site scripting
3069| [117558] Microsoft Windows up to Server 2016 Code Execution memory corruption
3070| [117507] Microsoft Infopath 2013 SP1 memory corruption
3071| [117505] Microsoft Excel 2010 SP2/2013 SP1/2013 RT SP1/2016/2016 C2R information disclosure
3072| [117504] Microsoft Office 2010 SP2 information disclosure
3073| [117503] Microsoft Exchange Server 2013 CU19/2013 CU20/2016 CU8/2016 CU9 Outlook Web Access cross site scripting
3074| [117502] Microsoft SharePoint Enterprise Server 2010 SP2/2013 SP1/2016 cross site scripting
3075| [117501] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
3076| [117500] Microsoft Exchange Server 2016 CU8/2016 CU9 Outlook Web Access cross site scripting
3077| [117499] Microsoft Exchange Server up to 2016 CU9 information disclosure
3078| [117498] Microsoft Office 2016 C2R Security Feature privilege escalation
3079| [117497] Microsoft SharePoint Enterprise Server 2010/2013 SP1/2016 cross site scripting
3080| [117480] Microsoft Windows up to Server 2016 COM Serialized privilege escalation
3081| [117473] Microsoft Excel 2010 SP2/2013 SP1/2013 RT SP1/2016/2016 C2R memory corruption
3082| [117472] Microsoft Office 2010 SP2/2013 SP1/2013 RT SP1/2016/2016 C2R memory corruption
3083| [117471] Microsoft Office 2010 SP2/2013 SP1/2013 RT SP1/2016/2016 C2R memory corruption
3084| [117470] Microsoft Office 2010 SP2/2013 SP1/2013 RT SP1/2016/2016 C2R memory corruption
3085| [117469] Microsoft Excel 2010 SP2/2013 SP1/2013 RT SP1/2016/2016 C2R memory corruption
3086| [117468] Microsoft Excel 2010 SP2/2013 SP1/2013 RT SP1/2016/2016 C2R memory corruption
3087| [117444] Microsoft Windows up to Server 2016 Hyper-V vSMB memory corruption
3088| [117443] Microsoft Windows up to Server 2016 Hyper-V memory corruption
3089| [117442] Microsoft Windows up to Server 2016 VBScript Engine memory corruption
3090| [116132] Microsoft Office 2016 Memory information disclosure
3091| [116051] Microsoft SharePoint Enterprise Server 2016 cross site scripting
3092| [116050] Microsoft SharePoint Enterprise Server 2010 SP2/2013/2016 cross site scripting
3093| [116049] Microsoft SharePoint Enterprise Server 2013/2016 privilege escalation
3094| [116048] Microsoft Windows up to Server 2016 DirectX Graphics Kernel Subsystem memory corruption
3095| [116047] Microsoft Windows up to Server 2016 OpenType Font Driver atmfd.dll memory corruption
3096| [116046] Microsoft SharePoint Enterprise Server 2013/2016 Share cross site scripting
3097| [116045] Microsoft Windows up to Server 2016 JET Database Engine memory corruption
3098| [116039] Microsoft Windows up to Server 2016 Remote Desktop Protocol denial of service
3099| [116031] Microsoft Windows up to Server 2016 Kernel ASLR information disclosure
3100| [116030] Microsoft Windows up to Server 2016 SNMP Service denial of service
3101| [116026] Microsoft Windows up to Server 2016 Kernel information disclosure
3102| [116024] Microsoft Windows up to Server 2016 HTTP.sys denial of service
3103| [116023] Microsoft Office up to 2016 C2R information disclosure
3104| [116022] Microsoft Excel 2010 SP2 memory corruption
3105| [116020] Microsoft Windows 10 1607/10 1703/10 1709/Server 2016/Server 1709 Active Directory privilege escalation
3106| [116019] Microsoft Windows up to Server 2016 Kernel information disclosure
3107| [116018] Microsoft Office 2013 SP1/2013 RT SP1/2016/2016 C2R memory corruption
3108| [116017] Microsoft Excel up to 2016 C2R memory corruption
3109| [116016] Microsoft Office 2010 SP2/2013 SP1/2013 RT SP1/2016 Graphics memory corruption
3110| [116014] Microsoft Office 2013 SP1/2013 RT SP1/2016/2016 C2R memory corruption
3111| [116013] Microsoft Excel 2010 SP2/2013 RT SP1/2013 SP1 memory corruption
3112| [116008] Microsoft Windows up to Server 2016 Graphics memory corruption
3113| [116007] Microsoft Windows up to Server 2016 Graphics memory corruption
3114| [116006] Microsoft Windows up to Server 2016 Graphics memory corruption
3115| [116005] Microsoft Windows up to Server 2016 Graphics memory corruption
3116| [116004] Microsoft Windows up to Server 2016 Graphics memory corruption
3117| [116003] Microsoft Windows up to Server 2016 VBScript Engine memory corruption
3118| [115994] Microsoft Windows up to Server 2016 Malware Protection Engine memory corruption
3119| [115804] Microsoft Windows up to Server 2016 Malware Protection Engine privilege escalation
3120| [114579] Microsoft Exchange Server up to 2017 CU8 Outlook Web Access information disclosure
3121| [114574] Microsoft SharePoint Enterprise Server 2016 privilege escalation
3122| [114573] Microsoft SharePoint Enterprise Server 2016 cross site scripting
3123| [114571] Microsoft Exchange Server 2016 CU7/2016 CU8 Outlook Web Access information disclosure
3124| [114570] Microsoft Exchange Server 2010 SP3/2013 CU18/2013 CU19/2016 CU7/2016 CU8 Outlook Web Access Fake privilege escalation
3125| [114565] Microsoft Windows 10 1607/10 1703/10 1709/Server 2016/Server 1709 Kernel information disclosure
3126| [114564] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
3127| [114562] Microsoft SharePoint Enterprise Server 2016 cross site scripting
3128| [114560] Microsoft SharePoint Enterprise Server 2016 cross site scripting
3129| [114559] Microsoft SharePoint Enterprise Server 2016 cross site scripting
3130| [114558] Microsoft SharePoint Enterprise Server 2016 cross site scripting
3131| [114557] Microsoft SharePoint Enterprise Server 2016 cross site scripting
3132| [114556] Microsoft SharePoint Enterprise Server 2016 cross site scripting
3133| [114555] Microsoft SharePoint Enterprise Server 2016 cross site scripting
3134| [114554] Microsoft SharePoint Enterprise Server 2016 cross site scripting
3135| [114553] Microsoft SharePoint Enterprise Server 2016 cross site scripting
3136| [114552] Microsoft SharePoint Enterprise Server 2016 cross site scripting
3137| [114551] Microsoft Excel up to 2016 C2R Security Feature privilege escalation
3138| [114549] Microsoft Access 2010 SP2/2013 SP1/2016 memory corruption
3139| [114548] Microsoft Windows up to Server 2016 CNG Security Feature cng.sys privilege escalation
3140| [114547] Microsoft Windows up to Server 2016 Kernel information disclosure
3141| [114546] Microsoft Windows up to Server 2016 Kernel information disclosure
3142| [114545] Microsoft Windows up to Server 2016 Kernel information disclosure
3143| [114544] Microsoft Windows up to Server 2016 Kernel information disclosure
3144| [114543] Microsoft Windows up to Server 2016 Kernel information disclosure
3145| [114542] Microsoft Windows up to Server 2016 Kernel information disclosure
3146| [114541] Microsoft Windows up to Server 2016 Kernel information disclosure
3147| [114540] Microsoft Windows up to Server 2016 Kernel information disclosure
3148| [114536] Microsoft Windows up to Server 2016 CredSSP privilege escalation
3149| [114535] Microsoft Windows up to Server 2016 Hyper-V denial of service
3150| [114531] Microsoft Windows up to Server 2016 Windows Installer privilege escalation
3151| [114530] Microsoft Windows up to Server 2016 GDI privilege escalation
3152| [114529] Microsoft Windows up to Server 2016 GDI privilege escalation
3153| [114527] Microsoft Windows up to Server 2016 Kernel information disclosure
3154| [114526] Microsoft Windows up to Server 2016 Kernel information disclosure
3155| [114525] Microsoft Windows up to Server 2016 Kernel information disclosure
3156| [114522] Microsoft Windows 10 1607/10 1703/Server 2016 Desktop Bridge privilege escalation
3157| [114521] Microsoft Windows up to Server 2016 Video Control privilege escalation
3158| [114520] Microsoft Windows 10/Server 2016/Server 1709 Desktop Bridge privilege escalation
3159| [114518] Microsoft Windows up to Server 2016 Remote Assistance information disclosure
3160| [114517] Microsoft Windows 10/Server 2016/Server 1709 Desktop Bridge VFS privilege escalation
3161| [114516] Microsoft Windows up to Server 2016 Windows Shell privilege escalation
3162| [113835] Microsoft Identity Manager 2016 SP1 cross site scripting
3163| [113264] Microsoft Windows 8.1/RT 8.1/Server 2012 R2 SMBv2/SMBv3 denial of service
3164| [113260] Microsoft Windows up to Server 2016 Kernel memory corruption
3165| [113259] Microsoft Windows 10/Server 2016/Server 1709 NTFS privilege escalation
3166| [113254] Microsoft Windows up to Server 2016 Kernel information disclosure
3167| [113253] Microsoft Windows 10/Server 2016/Server 1709 Kernel memory corruption
3168| [113252] Microsoft Windows up to Server 2016 Kernel memory corruption
3169| [113250] Microsoft Windows 10/Server 2016/Server 1709 Kernel memory corruption
3170| [113249] Microsoft Windows up to Server 2016 Kernel memory corruption
3171| [113248] Microsoft Windows up to Server 2016 Kernel information disclosure
3172| [113243] Microsoft Windows 10/Server 2016 MultiPoint Management privilege escalation
3173| [113242] Microsoft Windows up to Server 2016 Common Log File System Driver memory corruption
3174| [113241] Microsoft Windows up to Server 2016 Common Log File System Driver memory corruption
3175| [113240] Microsoft Windows 10/Server 2016/Server 1709 AppContainer privilege escalation
3176| [113237] Microsoft SharePoint Enterprise Server 2016 cross site scripting
3177| [113236] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
3178| [113233] Microsoft Office 2010 SP2/2013 SP1/2013 RT SP1/2016 Uninitialized Memory information disclosure
3179| [113232] Microsoft Excel 2016 memory corruption
3180| [113230] Microsoft Windows up to Server 2016 Scripting Engine information disclosure
3181| [113229] Microsoft Windows up to Server 2016 StructuredQuery memory corruption
3182| [111580] Microsoft Office 2016 on Mac Email Attachment spoofing
3183| [111571] Microsoft SharePoint Enterprise Server 2013/2016 Access cross site scripting
3184| [111567] Microsoft Office 2010/2013/2016 memory corruption
3185| [111564] Microsoft Word 2016 memory corruption
3186| [111562] Microsoft SharePoint Server 2010/2013/2016 Web Request cross site scripting
3187| [111561] Microsoft SharePoint Server 2010/2013/2016 Web Request cross site scripting
3188| [128730] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
3189| [111358] Microsoft Windows up to Server 2016 IPsec denial of service
3190| [110553] Microsoft Office 2016 C2R information disclosure
3191| [110552] Microsoft SharePoint Enterprise Server 2016 Web Request privilege escalation
3192| [110551] Microsoft Excel 2016 C2R memory corruption
3193| [110550] Microsoft PowerPoint 2013 SP1/2013 RT SP1/2016 information disclosure
3194| [110549] Microsoft Exchange Server 2016 CU6/2016 CU7 Outlook Web Access privilege escalation
3195| [110547] Microsoft Windows up to Server 2016 its:// Protocol information disclosure
3196| [110531] Microsoft Windows 10/Server 2016 Device Guard privilege escalation
3197| [110522] Microsoft Windows up to Server 2016 RRAS privilege escalation
3198| [110350] Microsoft Windows up to Server 2016 Malware Protection Engine memory corruption
3199| [110318] Microsoft Windows up to Server 2016 Malware Protection Engine memory corruption
3200| [109391] Microsoft SharePoint Enterprise Server 2016 Project Server cross site request forgery
3201| [109389] Microsoft Excel 2016 Click-to-Run memory corruption
3202| [109360] Microsoft Windows up to Server 2016 Windows Search denial of service
3203| [107759] Microsoft Windows up to Server 2016 SMB denial of service
3204| [107757] Microsoft Windows up to Server 2016 JET Database Engine memory corruption
3205| [107756] Microsoft Windows up to Server 2016 JET Database Engine memory corruption
3206| [107753] Microsoft Windows 10/Server 2016 SMB privilege escalation
3207| [107744] Microsoft Windows up to Server 2016 DNSAPI DNSAPI.dll DNS Response privilege escalation
3208| [107741] Microsoft Outlook 2016 Secure Connection Mail information disclosure
3209| [107740] Microsoft Windows up to Server 2016 Graphics memory corruption
3210| [107739] Microsoft Windows up to Server 2016 Graphics memory corruption
3211| [107738] Microsoft Windows up to Server 2016 Search information disclosure
3212| [107734] Microsoft Windows 10/Server 2016 SMB privilege escalation
3213| [107732] Microsoft Outlook 2010 SP2/2013 SP1/2013 RT SP1/2016 Bypass privilege escalation
3214| [107730] Microsoft Windows up to Server 2016 Search Remote memory corruption
3215| [107729] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
3216| [107728] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
3217| [107727] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
3218| [107724] Microsoft Windows up to Server 2016 Text Services Framework memory corruption
3219| [107723] Microsoft Windows up to Server 2016 SMB information disclosure
3220| [107698] Microsoft Office 2016 memory corruption
3221| [107593] InFocus Mondopad 2.2.08 Excel Spreadsheet Microsoft Office Document Credentials information disclosure
3222| [106544] Microsoft Exchange Server 2016 Outlook Web Access cross site scripting
3223| [106531] Microsoft SharePoint Foundation 2013 SP1 cross site scripting
3224| [106529] Microsoft PowerPoint 2016 memory corruption
3225| [106523] Microsoft Windows up to Server 2016 PDF Library memory corruption
3226| [106518] Microsoft Edge on Win10/Server 2016 memory corruption
3227| [106516] Microsoft Windows up to Server 2016 PDF Library memory corruption
3228| [106498] Microsoft Windows up to Server 2016 Shell privilege escalation
3229| [106496] Microsoft Windows up to Server 2016 Uniscribe information disclosure
3230| [106495] Microsoft Windows up to Server 2012 R2 Uniscribe memory corruption
3231| [106492] Microsoft Windows Server 2012/Server 2012 R2/Server 2016 DHCP Service memory corruption
3232| [106489] Microsoft Windows up to Server 2016 Graphics Win32k win32k!fsc_CalcGrayRow memory corruption
3233| [106474] Microsoft Office 2016 memory corruption
3234| [106473] Microsoft SharePoint Server 2013 SP1 cross site scripting
3235| [106472] Microsoft Windows up to Server 2016 Bluetooth Driver Object BlueBorne spoofing
3236| [106470] Microsoft Excel 2011 on Mac memory corruption
3237| [106455] Microsoft Exchange Server 2013/2016 information disclosure
3238| [106454] Microsoft Windows up to Server 2016 Windows NetBT Session Services race condition memory corruption
3239| [105048] Microsoft Edge on Win10/Server 2016 Scripting Engine memory corruption
3240| [105047] Microsoft Edge on Win10/Server 2016 Scripting Engine EntryCall memory corruption
3241| [105046] Microsoft Edge on Win10/Server 2016 Javascript Engine memory corruption
3242| [105040] Microsoft Edge on Win10/Server 2016 Scripting Engine memory corruption
3243| [105038] Microsoft Edge on Win10/Server 2016 Javascript Engine Out-of-Bounds memory corruption
3244| [105037] Microsoft Edge on Win10/Server 2016 Javascript Engine PreVisitCatch memory corruption
3245| [105035] Microsoft SharePoint Server 2010 SP2 cross site scripting
3246| [105033] Microsoft Edge 38.14393.1066.0 on Win10/Server 2016 Use-After-Free information disclosure
3247| [105029] Microsoft Edge on Win10/Server 2016 Javascript Engine ProcessLinkFailedAsmJsModule memory corruption
3248| [105027] Microsoft Edge on Win10/Server 2016 _SelectValueInternal information disclosure
3249| [105024] Microsoft Edge on Win10/Server 2016 Javascript Engine memory corruption
3250| [105023] Microsoft Edge on Win10/Server 2016 Javascript Engine memory corruption
3251| [105017] Microsoft Windows up to Server 2016 Error Reporting information disclosure
3252| [105013] Microsoft Windows 10 1607/10 1703/Server 2016 Hyper-V denial of service
3253| [105011] Microsoft Windows up to Server 2016 Windows Search memory corruption
3254| [105010] Microsoft Windows up to Server 2016 Win32k memory corruption
3255| [105009] Microsoft Windows up to Server 2016 Input Method Editor memory corruption
3256| [105008] Microsoft SQL Server 2012/2014/2016 Analysis Services information disclosure
3257| [104990] Microsoft Windows up to Server 2016 JET Database Engine memory corruption
3258| [104989] Microsoft Windows up to Server 2016 NetBIOS denial of service
3259| [104584] Microsoft Outlook up to 2016 C2R Document File privilege escalation
3260| [104583] Microsoft Outlook up to 2016 C2R Email memory corruption
3261| [104582] Microsoft Outlook up to 2016 C2R Object memory corruption
3262| [103468] Microsoft Exchange Server 2010 SP3/2013 SP3/2013 CU16/2016 CU5 Open Redirect
3263| [103446] Microsoft Windows up to Server 2016 Search Object privilege escalation
3264| [103445] Microsoft Windows up to Server 2016 Wordpad privilege escalation
3265| [103444] Microsoft Windows up to Server 2016 Explorer denial of service
3266| [103442] Microsoft Windows 10/Server 2016 HoloLens WiFi Packet privilege escalation
3267| [103441] Microsoft Windows up to Server 2016 Object HTTP.sys information disclosure
3268| [103431] Microsoft Windows up to Server 2016 PowerShell PSObject Object privilege escalation
3269| [103429] Microsoft Windows up to Server 2016 Kerberos weak authentication
3270| [103426] Microsoft Exchange Server 2010 SP3/2013 SP3/2013 CU16/2016 CU5 OWA Request cross site scripting
3271| [103425] Microsoft Exchange Server 2010 SP3/2013 SP3/2013 CU16/2016 CU5 OWA Request cross site scripting
3272| [103420] Microsoft Windows up to Server 2016 Kerberos Bypass privilege escalation
3273| [103417] Microsoft Windows up to Server 2016 Windows Shell privilege escalation
3274| [102544] Microsoft Edge on Win10/Server 2016 Fetch API information disclosure
3275| [102543] Microsoft Edge on Win10/Server 2016 Javascript XML DOM Object information disclosure
3276| [102463] Microsoft Project Server 2013 SP1 cross site scripting
3277| [102460] Microsoft Outlook 2016 on Mac HTML spoofing
3278| [102448] Microsoft SharePoint Enterprise Server 2016 Reflected cross site scripting
3279| [102446] Microsoft Office up to 2016 privilege escalation
3280| [102445] Microsoft Office 2010 SP2/2011/2013 SP1/2013 RT SP1/2016 privilege escalation
3281| [102443] Microsoft Office up to 2016 privilege escalation
3282| [102412] Microsoft Windows up to Server 2016 PDF information disclosure
3283| [102397] Microsoft Outlook 2010 SP1/2013 SP1/2016 DLL Loader privilege escalation
3284| [102396] Microsoft Office 2013 SP1/2016 DLL Loader privilege escalation
3285| [102386] Microsoft Windows up to Server 2012 R2 Uniscribe privilege escalation
3286| [102385] Microsoft Windows up to Server 2016 Font Library privilege escalation
3287| [102376] Microsoft Windows up to Server 2016 CAB File privilege escalation
3288| [102375] Microsoft Windows up to Server 2016 PDF Parser privilege escalation
3289| [102374] Microsoft Windows up to Server 2016 PDF Parser privilege escalation
3290| [102373] Microsoft Windows up to Server 2016 Uniscribe Font USP10!MergeLigRecords memory corruption
3291| [101817] Microsoft Windows up to Server 2016 Malware Protection Engine denial of service
3292| [101816] Microsoft Windows up to Server 2016 Malware Protection Engine setCaller memory corruption
3293| [101815] Microsoft Windows up to Server 2016 Malware Protection Engine Use-After-Free memory corruption
3294| [101814] Microsoft Windows up to Server 2016 Malware Protection Engine denial of service
3295| [101813] Microsoft Windows up to Server 2016 Malware Protection Engine memory corruption
3296| [101812] Microsoft Windows up to Server 2016 Malware Protection Engine denial of service
3297| [101811] Microsoft Windows up to Server 2016 Malware Protection Engine denial of service
3298| [101810] Microsoft Windows up to Server 2016 Malware Protection Engine denial of service
3299| [101028] Microsoft Windows 10/Server 2016 Hyper-V vSMB privilege escalation
3300| [101020] Microsoft SharePoint Foundation 2013 SP1 cross site scripting
3301| [101019] Microsoft Skype for Business 2016 memory corruption
3302| [101018] Microsoft SharePoint 2010 SP2/2013 SP1/2016 memory corruption
3303| [101016] Microsoft PowerPoint 2011 on Mac memory corruption
3304| [101015] Microsoft PowerPoint 2011 on Mac memory corruption
3305| [101014] Microsoft Office 2010 SP2/2016 memory corruption
3306| [101013] Microsoft Office 2010 SP2/2016 memory corruption
3307| [101002] Microsoft Windows up to Server 2016 SMBv1 Server memory corruption
3308| [101001] Microsoft Windows up to Server 2016 SMBv1 Server memory corruption
3309| [101000] Microsoft Windows up to Server 2016 SMBv1 Server memory corruption
3310| [100999] Microsoft Windows up to Server 2016 SMBv1 Server memory corruption
3311| [100918] Microsoft Windows 8/8.1/10/Server 2012/Server 2016 Malware Protection Service Type Confusion privilege escalation
3312| [99697] Microsoft SharePoint Server 2010 SP1/2010 SP2 Excel Services cross site scripting
3313| [99683] Microsoft Windows 10 1607/10 1703/Server 2012 R2/Server 2016 Active Directory Lockout privilege escalation
3314| [99682] Microsoft Outlook 2011 on Mac HTML Tag Validator spoofing
3315| [99681] Microsoft Windows up to Server 2016 OLE Integrity-Level Check privilege escalation
3316| [99667] Microsoft Windows 10/Server 2016 Active Directory Service Unresponsive denial of service
3317| [98272] Microsoft Windows up to 10/Server 2016 Local Session privilege escalation
3318| [98096] Microsoft Exchange 2013 SP1 privilege escalation
3319| [98095] Microsoft Lync for Mac 2011 Certificate Validation weak authentication
3320| [98094] Microsoft SharePoint Server 2013 SP1 cross site scripting
3321| [98093] Microsoft SharePoint Server/Office Web Apps 2010 SP2 memory corruption
3322| [98091] Microsoft SharePoint Server/Office Web Apps 2010 SP2 memory corruption
3323| [98090] Microsoft SharePoint Server 2010 SP2/2013 SP1 information disclosure
3324| [98089] Microsoft Office Web Apps 2013 SP1 memory corruption
3325| [98082] Microsoft Office 2010 SP2/2013 SP1/2013 RT SP1/2016 denial of service
3326| [98081] Microsoft Excel up to 2016 information disclosure
3327| [98080] Microsoft Excel 2010 SP2/2013 SP1/2013 RT SP1/2016 memory corruption
3328| [98079] Microsoft Word 2016 memory corruption
3329| [98076] Microsoft Lync/Skype for Business 2010/2013/2016 Graphics Component privilege escalation
3330| [98075] Microsoft Lync/Skype for Business 2010/2013/2016 GDI+ information disclosure
3331| [98074] Microsoft Lync/Skype for Business 2010/2013/2016 GDI+ information disclosure
3332| [98073] Microsoft Office 2010 SP2/Word Viewer Graphics Component information disclosure
3333| [98069] Microsoft Windows up to Server 2012 R2 Color Management memory corruption
3334| [98056] Microsoft Windows up to Server 2016 DNS Query information disclosure
3335| [98054] Microsoft Windows up to Server 2016 SMBv2/SMBv3 NULL Pointer Dereference memory corruption
3336| [98017] Microsoft Windows up to Server 2016 PDF memory corruption
3337| [98015] Microsoft Windows 10/Server 2016 Hyper-V denial of service
3338| [98013] Microsoft Windows 10/Server 2016 Hyper-V vSMB memory corruption
3339| [98007] Microsoft Windows 10/Server 2016 Hyper-V Network Switch denial of service
3340| [98006] Microsoft Windows 10/Server 2016 Hyper-V vSMB memory corruption
3341| [96521] Microsoft Windows 8.1/10/Server 2012/Server 2016 SMB Response mrxsmb20.sys denial of service
3342| [95781] Microsoft PowerPoint 2016 Java Embedded Object privilege escalation
3343| [95125] Microsoft Word/SharePoint Enterprise Server 2016 Document privilege escalation
3344| [94451] Microsoft Office 2011 memory corruption
3345| [94447] Microsoft Office 2010 SP2 memory corruption
3346| [94446] Microsoft Office 2016 memory corruption
3347| [94444] Microsoft Office 2010 SP2/2013 SP1/2013 RT SP1/2016 OLE DLL Loader memory corruption
3348| [94443] Microsoft Office up to 2016 information disclosure
3349| [94442] Microsoft Office 2010 SP2/2013 SP1/2013 RT SP1/2016 privilege escalation
3350| [93964] Microsoft Windows 7 Excel Starter 2010 XXE information disclosure
3351| [93543] Microsoft SQL Server 2016 FILESTREAM Path privilege escalation
3352| [93540] Microsoft Excel 2010 SP2/2011/2016 memory corruption
3353| [93416] Microsoft SQL Server up to 2012 SP3/2014 SP2/2016 Server Agent atxcore.dll privilege escalation
3354| [93415] Microsoft SQL Server 2016 MDS API cross site scripting
3355| [93414] Microsoft SQL Server up to 2012 SP3 RDBMS Engine privilege escalation
3356| [93413] Microsoft SQL Server up to 2014 SP2/2016 RDBMS Engine privilege escalation
3357| [93412] Microsoft SQL Server 2016 RDBMS Engine privilege escalation
3358| [93393] Microsoft Office up to 2016 memory corruption
3359| [93392] Microsoft Office up to 2016 memory corruption
3360| [93391] Microsoft Office up to 2016 memory corruption
3361| [93389] Microsoft Windows up to Server 2016 Media Foundation memory corruption
3362| [93388] Microsoft Windows up to Server 2016 Animation Manager Stylesheets memory corruption
3363| [92587] Microsoft Windows 8.1/RT 8.1/10/Server 2012/Server 2012 R2 Transaction Manager privilege escalation
3364| [92584] Microsoft Office up to 2016 memory corruption
3365| [91571] Microsoft Windows 8.1/RT 8.1/10/Server 2012/Server 2012 R2 PDF Library information disclosure
3366| [91570] Microsoft Windows 8.1/RT 8.1/10/Server 2012/Server 2012 R2 PDF Library information disclosure
3367| [91556] Microsoft Exchange 2016 Meeting Invation cross site scripting
3368| [91555] Microsoft Exchange 2013/2016 Link spoofing
3369| [91550] Microsoft Office 2016 memory corruption
3370| [91547] Microsoft Office 2010 memory corruption
3371| [91543] Microsoft Office up to 2016 memory corruption
3372| [91541] Microsoft Office 2013/2016 APP-V ASLR privilege escalation
3373| [90711] Microsoft Windows 8.1/RT 8.1/10/Server 2012/Server 2012 R2 PDF privilege escalation
3374| [90710] Microsoft Windows 8.1/RT 8.1/Server 2012/Server 2012 R2 Netlogon privilege escalation
3375| [90704] Microsoft Office 2013/2013 RT/2016 memory corruption
3376| [89043] Microsoft Office up to 2016 memory corruption
3377| [89041] Microsoft Office up to 2016 memory corruption
3378| [89040] Microsoft Office 2010 SP2/2011/2013 SP1/2013 RT SP1/2016 memory corruption
3379| [89038] Microsoft Office 2010 SP2/2013 SP1/2013 RT SP1/2016 Security Feature privilege escalation
3380| [89037] Microsoft Office 2010 SP2/2013 SP1/2013 RT SP1/2016 memory corruption
3381| [87961] Microsoft Windows up to Server 2012 R2 Search denial of service
3382| [87959] Microsoft Windows 8.1/10/Server 2012/Server 2012 R2 PDF information disclosure
3383| [87958] Microsoft Windows 8.1/10/Server 2012/Server 2012 R2 PDF memory corruption
3384| [87957] Microsoft Windows 8.1/10/Server 2012/Server 2012 R2 PDF information disclosure
3385| [87956] Microsoft Exchange 2013/2016 Oracle Outside In Libraries information disclosure
3386| [87944] Microsoft Windows Server 2012/Server 2012 R2 Virtual PCI Memory information disclosure
3387| [87940] Microsoft Windows Server 2012/Server 2012 R2 DNS Server Use-After-Free memory corruption
3388| [87936] Microsoft Office up to 2016 memory corruption
3389| [87166] Microsoft Windows up to Server 2012 R2 DirectX Graphics Kernel Subsystem privilege escalation
3390| [87156] Microsoft Windows 8.1/RT 8.1/10/Server 2012 R2 Shell memory corruption
3391| [87149] Microsoft Office up to 2016 memory corruption
3392| [87148] Microsoft Office 2010 Graphics memory corruption
3393| [87146] Microsoft Office 2011/2013/2013 RT/2016 memory corruption
3394| [82229] Microsoft Excel 2010 SP2 Office Document memory corruption
3395| [82223] Microsoft Windows 8.1/10/Server 2012 R2 Hyper-V Memory information disclosure
3396| [82222] Microsoft Windows 8.1/10/Server 2012/Server 2012 R2 Memory information disclosure
3397| [82221] Microsoft Windows 8.1/10/Server 2012/Server 2012 R2 Hyper-V privilege escalation
3398| [81274] Microsoft Office up to 2016 memory corruption
3399| [81270] Microsoft Windows 8.1/RT 8.1/10/Server 2012/Server 2012 R2 PDF Library memory corruption
3400| [81269] Microsoft Windows up to Server 2012 R2 Media Parser memory corruption
3401| [81268] Microsoft Windows up to Server 2012 R2 Media Parser memory corruption
3402| [80886] Microsoft SharePoint Foundation 2013 SP1 cross site scripting
3403| [80885] Microsoft Windows 7 SP1/8.1/10/Server 2012/Server 2012 R2 RDP memory corruption
3404| [80878] Microsoft Windows Server 2012 R2 Active Directory Federation Service denial of service
3405| [80874] Microsoft Windows 7 SP1/8.1/10/Server 2012/Server 2012 R2 RDP privilege escalation
3406| [80870] Microsoft Office up to 2016 memory corruption
3407| [80868] Microsoft Office up to 2016 memory corruption
3408| [80867] Microsoft Office up to 2016 memory corruption
3409| [80865] Microsoft Windows 8.1/RT 8.1/Server 2012/Server 2012 R2 DLL Loader memory corruption
3410| [80860] Microsoft Windows 8.1/10/Server 2012/Server 2012 R2 Reader memory corruption
3411| [80859] Microsoft Windows 8.1/10/Server 2012/Server 2012 R2 PDF Library memory corruption
3412| [80231] Microsoft Excel up to 2016 Office Document memory corruption
3413| [80229] Microsoft Exchange Server 2013 SP1/2013 CU 10/2013 CU 11/2016 Outlook Web Access cross site scripting
3414| [80228] Microsoft Exchange Server 2016 Outlook Web Access cross site scripting
3415| [80227] Microsoft Exchange Server 2013 SP1/2013 CU 10/2016 Outlook Web Access cross site scripting
3416| [80226] Microsoft Exchange Server 2016 Outlook Web Access cross site scripting
3417| [80218] Microsoft Office up to 2016 ASLR privilege escalation
3418| [80217] Microsoft SharePoint Foundation 2013 SP1 Access Control Policy cross site scripting
3419| [80216] Microsoft Office up to 2016 Office Document memory corruption
3420| [80206] Microsoft SharePoint Foundation 2013 SP1 Access Control Policy cross site scripting
3421| [128763] Microsoft Exchange Server 2016 CU10/2016 CU11/2019 memory corruption
3422| [79508] Microsoft Windows up to Server 2012 R2 Library Loader memory corruption
3423| [79500] Microsoft Office 2010/2011/2016 memory corruption
3424| [79183] Microsoft Windows up to Server 2012 R2 IPsec denial of service
3425| [79173] Microsoft Windows up to Server 2012 R2 Graphics information disclosure
3426| [79117] Microsoft Outlook 2011/2016 on Mac HTML spoofing
3427| [78375] Microsoft SharePoint Server/SharePoint Foundation 2013 SP1 cross site scripting
3428| [77645] Microsoft Exchange Server 2013 CU8/2013 CU9 Outlook Web Access cross site scripting
3429| [77644] Microsoft Exchange Server 2013 CU8/2013 CU9 Outlook Web Access cross site scripting
3430| [77638] Microsoft Lync Server 2013 cross site scripting
3431| [77628] Microsoft SharePoint Foundation 2013 SP1 cross site scripting
3432| [77612] Microsoft Exchange Server 2013 CU8/2013 CU9 Outlook Web Access Stack-Based information disclosure
3433| [77050] Microsoft Office up to 2016 memory corruption
3434| [77037] Microsoft Windows Server 2012/Server 2012 R2 System Center Operations Manager cross site scripting
3435| [76461] Microsoft Windows up to Server 2012 R2 Domain-Controller Communication Credentials information disclosure
3436| [76460] Microsoft Windows 7 SP1/8/Server 2012 RDP Server Service memory corruption
3437| [76448] Microsoft Windows 8.1/Server 2012 R2 Hyper-V memory corruption
3438| [75793] Microsoft Exchange Server 2013 CU8 cross site scripting
3439| [75792] Microsoft Exchange Server 2013 SP1 CU8 cross site request forgery
3440| [75791] Microsoft Office 2013 SP1 Office Document Uninitialized Memory memory corruption
3441| [75787] Microsoft Exchange Server 2013 SP1 CU8 Same Origin Policy privilege escalation
3442| [75786] Microsoft Office 2010 SP2/2013 SP1/2013 RT SP1 Office Document memory corruption
3443| [66976] Microsoft Access 2010 VBA Datatype denial of service
3444| [74848] Microsoft SharePoint Foundation/SharePoint Server 2013 SP1 cross site scripting
3445| [74842] Microsoft Windows 8.1/Server 2012 R2 Hyper-V denial of service
3446| [74836] Microsoft Project Server 2010 SP2/2013 SP1 cross site scripting
3447| [74835] Microsoft Office 2011 on Mac Use-After-Free cross site scripting
3448| [74834] Microsoft Windows Server 2012 R2 Active Directory Federation Services 3.0 privilege escalation
3449| [74833] Microsoft Windows 7 SP1/8/8.1/Server 2012/Server 2012 R2 HTTP Request HTTP.sys privilege escalation
3450| [74393] Microsoft SharePoint Server 2013 Foundation cross site scripting
3451| [73967] Microsoft Office up to 2013 SP1 Office File memory corruption
3452| [73966] Microsoft Office up to 2013 SP1 RTF File memory corruption
3453| [73965] Microsoft Office up to 2013 SP1 Use-After-Free memory corruption
3454| [73961] Microsoft Windows 7 SP1/8/8.1/Server 2012/Server 2012 R2 Remote Desktop Protocol Object Management denial of service
3455| [69162] Microsoft System Center Virtual Machine Manager 2012 privilege escalation
3456| [69160] Microsoft Windows up to Server 2012 Process privilege escalation
3457| [69156] Microsoft Office 2010 Object memory corruption
3458| [68593] Microsoft Windows up to Server 2012 Network Location Awareness Service privilege escalation
3459| [68417] Microsoft Exchange 2013 Outlook Web Access Token spoofing
3460| [68191] Microsoft SharePoint 2010 cross site scripting
3461| [67828] Microsoft ASP.NET MVC 2/3/4/5/5.1 System.Web.Mvc.dll cross site scripting
3462| [67518] Microsoft Lync 2013 denial of service
3463| [67517] Microsoft Lync 2013 Script Reflected cross site scripting
3464| [67516] Microsoft Lync 2010/2013 denial of service
3465| [67362] Microsoft Windows up to Server 2012 R2 Remote Procedure Call privilege escalation
3466| [67360] Microsoft SharePoint 2013 App Permission Management cross site scripting
3467| [13549] Microsoft Windows 7/8/8.1/Server 2012 Remote Desktop Protocol weak encryption
3468| [13547] Microsoft Lync 2010/2013 Meeting cross site scripting
3469| [13228] Microsoft Office 2013 Document privilege escalation
3470| [68577] Microsoft ASP.NET 2014.3.1209 Telerik UI RadAsyncUpload directory traversal
3471| [12267] Microsoft Forefront Security for Exchange Server 2010 Mail memory corruption
3472| [12263] Microsoft Windows up to Server 2012 Direct2D 2D Geometric Figure memory corruption
3473| [12238] Microsoft Windows 8/Server 2012/RT IPv6 denial of service
3474| [12185] Microsoft .NET Framework 2/4 HMAC weak authentication
3475| [12183] Microsoft .NET Framework 2/4 DTD denial of service
3476| [11673] Microsoft Windows Live Movie Maker 2011 WAV File denial of service
3477| [11468] Microsoft Exchange 2010/2013 cross site scripting
3478| [11466] Microsoft Office 2013 File Response information disclosure
3479| [11457] Microsoft SharePoint Server/Office Web Apps 2010 SP1/2010 SP2/2013 W3WP Service Account privilege escalation
3480| [11150] Microsoft Windows 8/Server 2012 Hyper-V Data Structure Value Crash privilege escalation
3481| [11004] Microsoft Windows Server 2012 R2 RDP Restricted Admin Mode weak authentication
3482| [10250] Microsoft SharePoint Server up to 2013 W3WP Process denial of service
3483| [10249] Microsoft SharePoint 2010/2003/2007/2.0/3.0 Workflow memory corruption
3484| [10248] Microsoft SharePoint Server up to 2013 cross site scripting
3485| [9943] Microsoft Windows Server 2012 NAT Driver ICMP Packet denial of service
3486| [8739] Microsoft Windows Essentials up to 2012 Windows Writer Eingabe information disclosure
3487| [8725] Microsoft Lync 2010/2013 Use-After-Free memory corruption
3488| [8722] Microsoft Windows 8/Server 2012/RT HTTP.sys denial of service
3489| [8206] Microsoft SharePoint Server 2010 SP1 HTML Sanitization Component cross site scripting
3490| [8203] Microsoft Windows up to 2012 AD LDAP Query denial of service
3491| [8200] Microsoft SharePoint Server 2013 ACL information disclosure
3492| [7971] Microsoft Office for Mac 2011 up to 14.3.1 on Mac HTML5 Mail Message Parser File information disclosure
3493| [7969] Microsoft OneNote 2010 SP1 ONE File information disclosure
3494| [7968] Microsoft SharePoint Server 2010 SP1 Input Validator Eingabe Crash denial of service
3495| [7967] Microsoft SharePoint Server 2010 SP1 User Account Eingabe Crash information disclosure
3496| [7966] Microsoft SharePoint Server 2010 SP1 Eingabe Crash cross site scripting
3497| [7965] Microsoft SharePoint Server 2010 SP1 User Account Callback URL privilege escalation
3498| [7964] Microsoft Visio 2010 Tree Object Type File memory corruption
3499| [7343] Microsoft Lync 2012 HTTP Format String
3500| [7258] Microsoft Windows up to 8/Server 2012 SSL/TLS race condition
3501| [7230] Microsoft Excel 2010 SP1 on 32-bit XLS File Formatting Information Crash denial of service
3502| [6831] Microsoft Office Picture Manager 2010 File memory corruption
3503| [62720] EMC NetWorker Module for Microsoft Applications up to 2.2.0 memory corruption
3504| [6624] Microsoft SQL Server up to 2012 Report Manager cross site scripting
3505| [62238] Microsoft Visual Studio Team Foundation Server 2010 cross site scripting
3506| [5946] Microsoft Visio/Visio Viewer up to 2010 SP1 File memory corruption
3507| [5644] Microsoft SharePoint 2010 scriptesx.ashx cross site scripting
3508| [5641] Microsoft SharePoint 2010 cross site scripting
3509| [60943] Microsoft Dynamics AX 2012 Enterprise Portal cross site scripting
3510| [12311] Microsoft Lync 2010 Search race condition
3511| [60570] Microsoft Forefront Unified Access Gateway 2010 information disclosure
3512| [60569] Microsoft Forefront Unified Access Gateway 2010 spoofing
3513| [60208] Microsoft Visio Viewer 2010 memory corruption
3514| [60207] Microsoft Visio Viewer 2010 memory corruption
3515| [60206] Microsoft Visio Viewer 2010 memory corruption
3516| [4640] Microsoft SharePoint 2010 inplview.aspx cross site scripting
3517| [4636] Microsoft SharePoint 2010 wizardlist.aspx cross site scripting
3518| [4635] Microsoft SharePoint 2010 themeweb.aspx cross site scripting
3519| [59008] Microsoft Forefront Unified Access Gateway 2010 Crash denial of service
3520| [58995] Microsoft Forefront Unified Access Gateway 2010 memory corruption
3521| [58994] Microsoft Forefront Unified Access Gateway 2010 Reflected cross site scripting
3522| [58993] Microsoft Forefront Unified Access Gateway 2010 Reflected cross site scripting
3523| [4424] Microsoft Host Integration Server up to 2010 denial of service
3524| [4420] Microsoft Forefront Unified Access Gateway 2010 memory corruption
3525| [58487] Microsoft SharePoint Foundation 2010 cross site scripting
3526| [58486] Microsoft SharePoint Foundation 2010 Reflected cross site scripting
3527| [58485] Microsoft SharePoint Foundation 2010 EditForm.aspx cross site scripting
3528| [4414] Microsoft SharePoint 2010 cross site scripting
3529| [4413] Microsoft SharePoint 2010/2007/3.0 XML/XLS Designfehler
3530| [91971] Microsoft Skype 2.2.x/5.2.x/5.3.x denial of service
3531| [57693] Microsoft Forefront Threat Management Gateway 2010 NSPLookupServiceNext memory corruption
3532| [4332] Microsoft PowerPoint 2010/2007 memory corruption
3533| [56028] Microsoft Data Access Components 2.8 memory corruption
3534| [55777] Microsoft Windows Movie Maker 2.6 memory corruption
3535| [55424] Microsoft Forefront Unified Access Gateway 2010 Signurl.asp cross site scripting
3536| [55415] Microsoft Forefront Unified Access Gateway 2010 cross site scripting
3537| [55414] Microsoft Forefront Unified Access Gateway 2010 cross site scripting
3538| [55413] Microsoft Forefront Unified Access Gateway 2010 spoofing
3539| [54341] Microsoft Windows Movie Maker 2.1 memory corruption
3540| [54549] Microsoft PowerPoint 2010 pptimpconv.dll memory corruption
3541| [4009] Microsoft NET Framework 2.x/3.x denial of service
3542| [45681] Microsoft Internet Explorer 8 Beta 2 privilege escalation
3543| [45449] Microsoft Internet Explorer 8 Beta 2 XSS Filter cross site scripting
3544| [45448] Microsoft Internet Explorer 8 Beta 2 XSS Filter cross site scripting
3545| [45446] Microsoft Internet Explorer 8 Beta 2 XSS Filter cross site scripting
3546| [2927] Microsoft Data Access Components 2.x ADODB.Connection ActiveX Control memory corruption
3547| [32692] Microsoft XML Core Services up to 2.6 memory corruption
3548| [32691] Microsoft XML Core Services up to 2.6 memory corruption
3549| [29608] Microsoft Data Access Components 2.7 memory corruption
3550|
3551| MITRE CVE - https://cve.mitre.org:
3552| [CVE-2013-3661] The EPATHOBJ::bFlatten function in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not check whether linked-list traversal is continually accessing the same list member, which allows local users to cause a denial of service (infinite traversal) via vectors that trigger a crafted PATHRECORD chain.
3553| [CVE-2013-3660] The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, and Windows Server 2012 does not properly initialize a pointer for the next object in a certain list, which allows local users to obtain write access to the PATHRECORD chain, and consequently gain privileges, by triggering excessive consumption of paged memory and then making many FlattenPath function calls, aka "Win32k Read AV Vulnerability."
3554| [CVE-2013-3174] DirectShow in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, and Windows Server 2012 allows remote attackers to execute arbitrary code via a crafted GIF file, aka "DirectShow Arbitrary Memory Overwrite Vulnerability."
3555| [CVE-2013-3173] Buffer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages improper handling of objects in memory, aka "Win32k Buffer Overwrite Vulnerability."
3556| [CVE-2013-3172] Buffer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to cause a denial of service (system hang) via a crafted application that leverages improper handling of objects in memory, aka "Win32k Buffer Overflow Vulnerability."
3557| [CVE-2013-3171] The serialization functionality in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5 does not properly check the permissions of delegate objects, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application that leverages a partial-trust relationship, aka "Delegate Serialization Vulnerability."
3558| [CVE-2013-3167] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Win32k Information Disclosure Vulnerability."
3559| [CVE-2013-3154] The signature-update functionality in Windows Defender on Microsoft Windows 7 and Windows Server 2008 R2 relies on an incorrect pathname, which allows local users to gain privileges via a Trojan horse application in the %SYSTEMDRIVE% top-level directory, aka "Microsoft Windows 7 Defender Improper Pathname Vulnerability."
3560| [CVE-2013-3138] Integer overflow in the TCP/IP kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allows remote attackers to cause a denial of service (system hang) via crafted TCP packets, aka "TCP/IP Integer Overflow Vulnerability."
3561| [CVE-2013-3136] The kernel in Microsoft Windows XP SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, and Windows 8 on 32-bit platforms does not properly handle unspecified page-fault system calls, which allows local users to obtain sensitive information from kernel memory via a crafted application, aka "Kernel Information Disclosure Vulnerability."
3562| [CVE-2013-3134] The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 on 64-bit platforms does not properly allocate arrays of structures, which allows remote attackers to execute arbitrary code via a crafted .NET Framework application that changes array data, aka "Array Allocation Vulnerability."
3563| [CVE-2013-3133] Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check the permissions of objects that use reflection, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application, aka "Anonymous Method Injection Vulnerability."
3564| [CVE-2013-3132] Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check the permissions of objects that use reflection, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application, aka "Delegate Reflection Bypass Vulnerability."
3565| [CVE-2013-3131] Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5, and Silverlight 5 before 5.1.20513.0, does not properly prevent changes to data in multidimensional arrays of structures, which allows remote attackers to execute arbitrary code via (1) a crafted .NET Framework application or (2) a crafted Silverlight application, aka "Array Access Violation Vulnerability."
3566| [CVE-2013-1345] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Win32k Vulnerability."
3567| [CVE-2013-1340] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Win32k Dereference Vulnerability."
3568| [CVE-2013-1339] The Print Spooler in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly manage memory during deletion of printer connections, which allows remote authenticated users to execute arbitrary code via a crafted request, aka "Print Spooler Vulnerability."
3569| [CVE-2013-1336] The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check signatures, which allows remote attackers to make undetected changes to signed XML documents via unspecified vectors that preserve signature validity, aka "XML Digital Signature Spoofing Vulnerability."
3570| [CVE-2013-1335] Microsoft Word 2003 SP3 and Word Viewer allow remote attackers to execute arbitrary code via crafted shape data in a Word document, aka "Word Shape Corruption Vulnerability."
3571| [CVE-2013-1334] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Win32k Window Handle Vulnerability."
3572| [CVE-2013-1332] dxgkrnl.sys (aka the DirectX graphics kernel subsystem) in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "DirectX Graphics Kernel Subsystem Double Fetch Vulnerability."
3573| [CVE-2013-1331] Buffer overflow in Microsoft Office 2003 SP3 and Office 2011 for Mac allows remote attackers to execute arbitrary code via crafted PNG data in an Office document, leading to improper memory allocation, aka "Office Buffer Overflow Vulnerability."
3574| [CVE-2013-1329] Integer signedness error in Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers a buffer underflow, aka "Publisher Buffer Underflow Vulnerability."
3575| [CVE-2013-1328] Microsoft Publisher 2003 SP3, 2007 SP3, and 2010 SP1 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers incorrect pointer handling, aka "Publisher Pointer Handling Vulnerability."
3576| [CVE-2013-1327] Integer signedness error in Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers an improper memory allocation, aka "Publisher Signed Integer Vulnerability."
3577| [CVE-2013-1323] Microsoft Publisher 2003 SP3 does not properly handle NULL values for unspecified data items, which allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Incorrect NULL Value Handling Vulnerability."
3578| [CVE-2013-1322] Microsoft Publisher 2003 SP3 does not properly check table range data, which allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Invalid Range Check Vulnerability."
3579| [CVE-2013-1321] Microsoft Publisher 2003 SP3 does not properly check the data type of an unspecified return value, which allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Return Value Validation Vulnerability."
3580| [CVE-2013-1320] Buffer overflow in Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Buffer Overflow Vulnerability."
3581| [CVE-2013-1319] Microsoft Publisher 2003 SP3 does not properly check the return value of an unspecified method, which allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Return Value Handling Vulnerability."
3582| [CVE-2013-1318] Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers access to an invalid pointer, aka "Publisher Corrupt Interface Pointer Vulnerability."
3583| [CVE-2013-1317] Integer overflow in Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers an improper allocation-size calculation, aka "Publisher Integer Overflow Vulnerability."
3584| [CVE-2013-1316] Microsoft Publisher 2003 SP3 does not properly validate the size of an unspecified array, which allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Negative Value Allocation Vulnerability."
3585| [CVE-2013-1302] Microsoft Communicator 2007 R2, Lync 2010, Lync 2010 Attendee, and Lync Server 2013 do not properly handle objects in memory, which allows remote attackers to execute arbitrary code via an invitation that triggers access to a deleted object, aka "Lync RCE Vulnerability."
3586| [CVE-2013-1301] Microsoft Visio 2003 SP3 2007 SP3, and 2010 SP1 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, aka "XML External Entities Resolution Vulnerability."
3587| [CVE-2013-1300] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Win32k Memory Allocation Vulnerability."
3588| [CVE-2013-1295] The Client/Server Run-time Subsystem (CSRSS) in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP2, and Server 2008 SP2 does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "CSRSS Memory Corruption Vulnerability."
3589| [CVE-2013-1294] Race condition in the kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages improper handling of objects in memory, aka "Kernel Race Condition Vulnerability."
3590| [CVE-2013-1293] The NTFS kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via a crafted application that leverages improper handling of objects in memory, aka "NTFS NULL Pointer Dereference Vulnerability."
3591| [CVE-2013-1292] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages improper handling of objects in memory, aka "Win32k Race Condition Vulnerability."
3592| [CVE-2013-1291] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, Windows 7 Gold and SP1, and Windows 8 allows local users to cause a denial of service (reboot) via a crafted OpenType font, aka "OpenType Font Parsing Vulnerability" or "Win32k Font Parsing Vulnerability."
3593| [CVE-2013-1287] The USB kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 do not properly handle objects in memory, which allows physically proximate attackers to execute arbitrary code by connecting a crafted USB device, aka "Windows USB Descriptor Vulnerability," a different vulnerability than CVE-2013-1285 and CVE-2013-1286.
3594| [CVE-2013-1286] The USB kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 do not properly handle objects in memory, which allows physically proximate attackers to execute arbitrary code by connecting a crafted USB device, aka "Windows USB Descriptor Vulnerability," a different vulnerability than CVE-2013-1285 and CVE-2013-1287.
3595| [CVE-2013-1285] The USB kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 do not properly handle objects in memory, which allows physically proximate attackers to execute arbitrary code by connecting a crafted USB device, aka "Windows USB Descriptor Vulnerability," a different vulnerability than CVE-2013-1286 and CVE-2013-1287.
3596| [CVE-2013-1283] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages improper handling of objects in memory, aka "Win32k Race Condition Vulnerability."
3597| [CVE-2013-1281] The NFS server in Microsoft Windows Server 2008 R2 and R2 SP1 and Server 2012 allows remote attackers to cause a denial of service (NULL pointer dereference and reboot) via an attempted renaming of a file or folder located on a read-only share, aka "NULL Dereference Vulnerability."
3598| [CVE-2013-1280] The kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Reference Count Vulnerability."
3599| [CVE-2013-1279] Race condition in the kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages incorrect handling of objects in memory, aka "Kernel Race Condition Vulnerability," a different vulnerability than CVE-2013-1278.
3600| [CVE-2013-1278] Race condition in the kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages incorrect handling of objects in memory, aka "Kernel Race Condition Vulnerability," a different vulnerability than CVE-2013-1279.
3601| [CVE-2013-1277] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
3602| [CVE-2013-1276] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
3603| [CVE-2013-1275] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
3604| [CVE-2013-1274] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
3605| [CVE-2013-1273] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
3606| [CVE-2013-1272] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
3607| [CVE-2013-1271] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
3608| [CVE-2013-1270] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
3609| [CVE-2013-1269] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
3610| [CVE-2013-1268] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
3611| [CVE-2013-1267] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
3612| [CVE-2013-1266] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
3613| [CVE-2013-1265] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
3614| [CVE-2013-1264] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
3615| [CVE-2013-1263] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
3616| [CVE-2013-1262] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
3617| [CVE-2013-1261] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
3618| [CVE-2013-1260] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
3619| [CVE-2013-1259] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
3620| [CVE-2013-1258] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
3621| [CVE-2013-1257] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
3622| [CVE-2013-1256] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
3623| [CVE-2013-1255] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
3624| [CVE-2013-1254] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
3625| [CVE-2013-1253] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
3626| [CVE-2013-1252] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
3627| [CVE-2013-1251] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
3628| [CVE-2013-1250] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
3629| [CVE-2013-1249] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
3630| [CVE-2013-1248] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
3631| [CVE-2013-0095] Outlook in Microsoft Office for Mac 2008 before 12.3.6 and Office for Mac 2011 before 14.3.2 allows remote attackers to trigger access to a remote URL and consequently confirm the rendering of an HTML e-mail message by including unspecified HTML5 elements and leveraging the installation of a WebKit browser on the victim's machine, aka "Unintended Content Loading Vulnerability."
3632| [CVE-2013-0077] Quartz.dll in DirectShow in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows remote attackers to execute arbitrary code via crafted media content in (1) a media file, (2) a media stream, or (3) a Microsoft Office document, aka "Media Decompression Vulnerability."
3633| [CVE-2013-0076] The Client/Server Run-time Subsystem (CSRSS) in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Reference Count Vulnerability."
3634| [CVE-2013-0075] The TCP/IP implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows remote attackers to cause a denial of service (reboot) via a crafted packet that terminates a TCP connection, aka "TCP FIN WAIT Vulnerability."
3635| [CVE-2013-0073] The Windows Forms (aka WinForms) component in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly restrict the privileges of a callback function during object creation, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application, aka "WinForms Callback Elevation Vulnerability."
3636| [CVE-2013-0013] The SSL provider component in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle encrypted packets, which allows man-in-the-middle attackers to conduct SSLv2 downgrade attacks against (1) SSLv3 sessions or (2) TLS sessions by intercepting handshakes and injecting content, aka "Microsoft SSL Version 3 and TLS Protocol Security Feature Bypass Vulnerability."
3637| [CVE-2013-0011] The Print Spooler in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted print job, aka "Windows Print Spooler Components Vulnerability."
3638| [CVE-2013-0010] Cross-site scripting (XSS) vulnerability in Microsoft System Center Operations Manager 2007 SP1 and R2 allows remote attackers to inject arbitrary web script or HTML via crafted input, aka "System Center Operations Manager Web Console XSS Vulnerability," a different vulnerability than CVE-2013-0009.
3639| [CVE-2013-0009] Cross-site scripting (XSS) vulnerability in Microsoft System Center Operations Manager 2007 SP1 and R2 allows remote attackers to inject arbitrary web script or HTML via crafted input, aka "System Center Operations Manager Web Console XSS Vulnerability," a different vulnerability than CVE-2013-0010.
3640| [CVE-2013-0008] win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle window broadcast messages, which allows local users to gain privileges via a crafted application, aka "Win32k Improper Message Handling Vulnerability."
3641| [CVE-2013-0004] Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly validate the permissions of objects in memory, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application, aka "Double Construction Vulnerability."
3642| [CVE-2013-0003] Buffer overflow in a System.DirectoryServices.Protocols (S.DS.P) namespace method in Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, and 4.5 allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application that leverages a missing array-size check during a memory copy operation, aka "S.DS.P Buffer Overflow Vulnerability."
3643| [CVE-2013-0002] Buffer overflow in the Windows Forms (aka WinForms) component in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, and 4.5 allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application that leverages improper counting of objects during a memory copy operation, aka "WinForms Buffer Overflow Vulnerability."
3644| [CVE-2013-0001] The Windows Forms (aka WinForms) component in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 4, and 4.5 does not properly initialize memory arrays, which allows remote attackers to obtain sensitive information via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application that leverages a pointer to an unmanaged memory location, aka "System Drawing Information Disclosure Vulnerability."
3645| [CVE-2012-5672] Microsoft Excel Viewer (aka Xlview.exe) and Excel in Microsoft Office 2007 (aka Office 12) allow remote attackers to cause a denial of service (read access violation and application crash) via a crafted spreadsheet file, as demonstrated by a .xls file with battery voltage data.
3646| [CVE-2012-4791] Microsoft Exchange Server 2007 SP3 and 2010 SP1 and SP2 allows remote authenticated users to cause a denial of service (Information Store service hang) by subscribing to a crafted RSS feed, aka "RSS Feed May Cause Exchange DoS Vulnerability."
3647| [CVE-2012-4786] The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allow remote attackers to execute arbitrary code via a crafted TrueType Font (TTF) file, aka "TrueType Font Parsing Vulnerability."
3648| [CVE-2012-4776] The Web Proxy Auto-Discovery (WPAD) functionality in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not validate configuration data that is returned during acquisition of proxy settings, which allows remote attackers to execute arbitrary JavaScript code by providing crafted data during execution of (1) an XAML browser application (aka XBAP) or (2) a .NET Framework application, aka "Web Proxy Auto-Discovery Vulnerability."
3649| [CVE-2012-4774] Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allow remote attackers to execute arbitrary code via a crafted (1) file name or (2) subfolder name that triggers use of unallocated memory as the destination of a copy operation, aka "Windows Filename Parsing Vulnerability."
3650| [CVE-2012-2897] The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT, as used by Google Chrome before 22.0.1229.79 and other programs, do not properly handle objects in memory, which allows remote attackers to execute arbitrary code via a crafted TrueType font file, aka "Windows Font Parsing Vulnerability" or "TrueType Font Parsing Vulnerability."
3651| [CVE-2012-2556] The OpenType Font (OTF) driver in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows remote attackers to execute arbitrary code via a crafted OpenType font file, aka "OpenType Font Parsing Vulnerability."
3652| [CVE-2012-2553] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application, aka "Win32k Use After Free Vulnerability."
3653| [CVE-2012-2552] Cross-site scripting (XSS) vulnerability in the SQL Server Report Manager in Microsoft SQL Server 2000 Reporting Services SP2 and SQL Server 2005 SP4, 2008 SP2 and SP3, 2008 R2 SP1, and 2012 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka "Reflected XSS Vulnerability."
3654| [CVE-2012-2551] The server in Kerberos in Microsoft Windows Server 2008 R2 and R2 SP1, and Windows 7 Gold and SP1, allows remote attackers to cause a denial of service (NULL pointer dereference and reboot) via a crafted session request, aka "Kerberos NULL Dereference Vulnerability."
3655| [CVE-2012-2543] Stack-based buffer overflow in Microsoft Excel 2007 SP2 and SP3 and 2010 SP1
3656| [CVE-2012-2539] Microsoft Word 2003 SP3, 2007 SP2 and SP3, and 2010 SP1
3657| [CVE-2012-2536] Cross-site scripting (XSS) vulnerability in Microsoft Systems Management Server 2003 SP3 and System Center Configuration Manager 2007 SP2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Reflected XSS Vulnerability."
3658| [CVE-2012-2530] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application, aka "Win32k Use After Free Vulnerability."
3659| [CVE-2012-2529] Integer overflow in the kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages improper handling of objects in memory, aka "Windows Kernel Integer Overflow Vulnerability."
3660| [CVE-2012-2528] Use-after-free vulnerability in Microsoft Word 2003 SP3, 2007 SP2 and SP3, and 2010 SP1
3661| [CVE-2012-2527] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application, aka "Win32k Use After Free Vulnerability."
3662| [CVE-2012-2524] Microsoft Office 2007 SP2 and SP3 and 2010 SP1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Computer Graphics Metafile (CGM) file, aka "CGM File Format Memory Corruption Vulnerability."
3663| [CVE-2012-2520] Cross-site scripting (XSS) vulnerability in Microsoft InfoPath 2007 SP2 and SP3 and 2010 SP1, Communicator 2007 R2, Lync 2010 and 2010 Attendee, SharePoint Server 2007 SP2 and SP3 and 2010 SP1, Groove Server 2010 SP1, Windows SharePoint Services 3.0 SP2, SharePoint Foundation 2010 SP1, and Office Web Apps 2010 SP1 allows remote attackers to inject arbitrary web script or HTML via a crafted string, aka "HTML Sanitization Vulnerability."
3664| [CVE-2012-2519] Untrusted search path vulnerability in Entity Framework in ADO.NET in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, and 4 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .NET application, aka ".NET Framework Insecure Library Loading Vulnerability."
3665| [CVE-2012-1896] Microsoft .NET Framework 2.0 SP2 and 3.5.1 does not properly consider trust levels during construction of output data, which allows remote attackers to obtain sensitive information via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework application, aka "Code Access Security Info Disclosure Vulnerability."
3666| [CVE-2012-1895] The reflection implementation in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5.1, and 4 does not properly enforce object permissions, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework application, aka "Reflection Bypass Vulnerability."
3667| [CVE-2012-1893] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly validate callback parameters during creation of a hook procedure, which allows local users to gain privileges via a crafted application, aka "Win32k Incorrect Type Handling Vulnerability."
3668| [CVE-2012-1890] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle keyboard-layout files, which allows local users to gain privileges via a crafted application, aka "Keyboard Layout Vulnerability."
3669| [CVE-2012-1887] Use-after-free vulnerability in Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 SP1, and Office 2008 and 2011 for Mac, allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel SST Invalid Length Use After Free Vulnerability."
3670| [CVE-2012-1886] Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 SP1
3671| [CVE-2012-1885] Heap-based buffer overflow in Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 SP1
3672| [CVE-2012-1870] The CBC mode in the TLS protocol, as used in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and other products, allows remote web servers to obtain plaintext data by triggering multiple requests to a third-party HTTPS server and sniffing the network during the resulting HTTPS session, aka "TLS Protocol Vulnerability."
3673| [CVE-2012-1867] Integer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted TrueType font file that triggers incorrect memory allocation, aka "Font Resource Refcount Integer Overflow Vulnerability."
3674| [CVE-2012-1866] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle user-mode input passed to kernel mode for driver objects, which allows local users to gain privileges via a crafted application, aka "Clipboard Format Atom Name Handling Vulnerability."
3675| [CVE-2012-1865] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle user-mode input passed to kernel mode for driver objects, which allows local users to gain privileges via a crafted application, aka "String Atom Class Name Handling Vulnerability," a different vulnerability than CVE-2012-1864.
3676| [CVE-2012-1864] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle user-mode input passed to kernel mode for driver objects, which allows local users to gain privileges via a crafted application, aka "String Atom Class Name Handling Vulnerability," a different vulnerability than CVE-2012-1865.
3677| [CVE-2012-1863] Cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint Server 2007 SP2 and SP3 Windows SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via crafted JavaScript elements in a URL, aka "SharePoint Reflected List Parameter Vulnerability."
3678| [CVE-2012-1862] Open redirect vulnerability in Microsoft Office SharePoint Server 2007 SP2 and SP3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL, aka "SharePoint URL Redirection Vulnerability."
3679| [CVE-2012-1860] Microsoft Office SharePoint Server 2007 SP2 and SP3, SharePoint Server 2010 Gold and SP1, and Office Web Apps 2010 Gold and SP1 do not properly check permissions for search scopes, which allows remote authenticated users to obtain sensitive information or cause a denial of service (data modification) by changing a parameter in a search-scope URL, aka "SharePoint Search Scope Vulnerability."
3680| [CVE-2012-1858] The toStaticHTML API (aka the SafeHTML component) in Microsoft Internet Explorer 8 and 9, Communicator 2007 R2, and Lync 2010 and 2010 Attendee does not properly handle event attributes and script, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted HTML document, aka "HTML Sanitization Vulnerability."
3681| [CVE-2012-1856] The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office 2003 SP3, Office 2003 Web Components SP3, Office 2007 SP2 and SP3, Office 2010 SP1, SQL Server 2000 SP4, SQL Server 2005 SP4, SQL Server 2008 SP2, SP3, R2, R2 SP1, and R2 SP2, Commerce Server 2002 SP4, Commerce Server 2007 SP2, Commerce Server 2009 Gold and R2, Host Integration Server 2004 SP1, Visual FoxPro 8.0 SP1, Visual FoxPro 9.0 SP2, and Visual Basic 6.0 Runtime allows remote attackers to execute arbitrary code via a crafted (1) document or (2) web page that triggers system-state corruption, aka "MSCOMCTL.OCX RCE Vulnerability."
3682| [CVE-2012-1855] Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly handle function pointers, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework application, aka ".NET Framework Memory Access Vulnerability."
3683| [CVE-2012-1854] Untrusted search path vulnerability in VBE6.dll in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1
3684| [CVE-2012-1851] Format string vulnerability in the Print Spooler service in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted response, aka "Print Spooler Service Format String Vulnerability."
3685| [CVE-2012-1850] The Remote Administration Protocol (RAP) implementation in the LanmanWorkstation service in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle RAP responses, which allows remote attackers to cause a denial of service (service hang) via crafted RAP packets, aka "Remote Administration Protocol Denial of Service Vulnerability."
3686| [CVE-2012-1848] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview does not properly handle user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application, aka "Scrollbar Calculation Vulnerability."
3687| [CVE-2012-1847] Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1
3688| [CVE-2012-1537] Heap-based buffer overflow in DirectPlay in DirectX 9.0 through 11.1 in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 allows remote attackers to execute arbitrary code via a crafted Office document, aka "DirectPlay Heap Overflow Vulnerability."
3689| [CVE-2012-1528] Integer overflow in Windows Shell in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 allows local users to gain privileges via a crafted briefcase, aka "Windows Briefcase Integer Overflow Vulnerability."
3690| [CVE-2012-1527] Integer underflow in Windows Shell in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 allows local users to gain privileges via a crafted briefcase, aka "Windows Briefcase Integer Underflow Vulnerability."
3691| [CVE-2012-1459] The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, ClamAV 0.96.4, Command Antivirus 5.2.11.5, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, F-Prot Antivirus 4.6.2.117, F-Secure Anti-Virus 9.0.16160.0, Fortinet Antivirus 4.2.254.0, G Data AntiVirus 21, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, nProtect Anti-Virus 2011-01-17.01, Panda Antivirus 10.0.2.7, PC Tools AntiVirus 7.0.3.5, Rising Antivirus 22.83.00.03, Sophos Anti-Virus 4.61.0, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, Trend Micro HouseCall 9.120.0.1004, VBA32 3.12.14.2, and VirusBuster 13.6.151.0 allows remote attackers to bypass malware detection via a TAR archive entry with a length field corresponding to that entire entry, plus part of the header of the next entry. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.
3692| [CVE-2012-1457] The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, ClamAV 0.96.4, Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, G Data AntiVirus 21, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, PC Tools AntiVirus 7.0.3.5, Rising Antivirus 22.83.00.03, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, Trend Micro HouseCall 9.120.0.1004, VBA32 3.12.14.2, and VirusBuster 13.6.151.0 allows remote attackers to bypass malware detection via a TAR archive entry with a length field that exceeds the total TAR file size. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.
3693| [CVE-2012-1453] The CAB file parser in Dr.Web 5.0.2.03300, Trend Micro HouseCall 9.120.0.1004, Kaspersky Anti-Virus 7.0.0.125, Sophos Anti-Virus 4.61.0, Trend Micro AntiVirus 9.120.0.1004, McAfee Gateway (formerly Webwasher) 2010.1C, Emsisoft Anti-Malware 5.1.0.1, CA eTrust Vet Antivirus 36.1.8511, Antiy Labs AVL SDK 2.0.3.7, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, Rising Antivirus 22.83.00.03, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via a CAB file with a modified coffFiles field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different CAB parser implementations.
3694| [CVE-2012-1443] The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Command Antivirus 5.2.11.5, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Emsisoft Anti-Malware 5.1.0.1, PC Tools AntiVirus 7.0.3.5, F-Prot Antivirus 4.6.2.117, VirusBuster 13.6.151.0, Fortinet Antivirus 4.2.254.0, Antiy Labs AVL SDK 2.0.3.7, K7 AntiVirus 9.77.3565, Trend Micro HouseCall 9.120.0.1004, Kaspersky Anti-Virus 7.0.0.125, Jiangmin Antivirus 13.0.900, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, Sophos Anti-Virus 4.61.0, NOD32 Antivirus 5795, Avira AntiVir 7.11.1.163, Norman Antivirus 6.06.12, McAfee Anti-Virus Scanning Engine 5.400.0.1158, Panda Antivirus 10.0.2.7, McAfee Gateway (formerly Webwasher) 2010.1C, Trend Micro AntiVirus 9.120.0.1004, Comodo Antivirus 7424, Bitdefender 7.2, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.0, nProtect Anti-Virus 2011-01-17.01, AhnLab V3 Internet Security 2011.01.18.00, AVG Anti-Virus 10.0.0.1190, avast! Antivirus 4.8.1351.0 and 5.0.677.0, and VBA32 3.12.14.2 allows user-assisted remote attackers to bypass malware detection via a RAR file with an initial MZ character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different RAR parser implementations.
3695| [CVE-2012-1420] The TAR file parser in Quick Heal (aka Cat QuickHeal) 11.00, Command Antivirus 5.2.11.5, F-Prot Antivirus 4.6.2.117, Fortinet Antivirus 4.2.254.0, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, Panda Antivirus 10.0.2.7, and Rising Antivirus 22.83.00.03 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial \7fELF character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.
3696| [CVE-2012-1194] The resolver in the DNS Server service in Microsoft Windows Server 2008 before R2 overwrites cached server names and TTL values in NS records during the processing of a response to an A record query, which allows remote attackers to trigger continued resolvability of revoked domain names via a "ghost domain names" attack.
3697| [CVE-2012-0185] Heap-based buffer overflow in Microsoft Excel 2007 SP2 and SP3 and 2010 Gold and SP1, Excel Viewer, and Office Compatibility Pack SP2 and SP3 allows remote attackers to execute arbitrary code via a crafted spreadsheet that triggers incorrect handling of memory during opening, aka "Excel MergeCells Record Heap Overflow Vulnerability."
3698| [CVE-2012-0184] Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1
3699| [CVE-2012-0183] Microsoft Word 2003 SP3 and 2007 SP2 and SP3, Office 2008 and 2011 for Mac, and Office Compatibility Pack SP2 and SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted RTF data, aka "RTF Mismatch Vulnerability."
3700| [CVE-2012-0182] Microsoft Word 2007 SP2 and SP3 does not properly handle memory during the parsing of Word documents, which allows remote attackers to execute arbitrary code via a crafted document, aka "Word PAPX Section Corruption Vulnerability."
3701| [CVE-2012-0181] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview does not properly manage Keyboard Layout files, which allows local users to gain privileges via a crafted application, aka "Keyboard Layout File Vulnerability."
3702| [CVE-2012-0180] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview does not properly handle user-mode input passed to kernel mode for (1) windows and (2) messages, which allows local users to gain privileges via a crafted application, aka "Windows and Messages Vulnerability."
3703| [CVE-2012-0179] Double free vulnerability in tcpip.sys in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that binds an IPv6 address to a local interface, aka "TCP/IP Double Free Vulnerability."
3704| [CVE-2012-0178] Race condition in partmgr.sys in Windows Partition Manager in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that makes multiple simultaneous Plug and Play (PnP) Configuration Manager function calls, aka "Plug and Play (PnP) Configuration Manager Vulnerability."
3705| [CVE-2012-0177] Heap-based buffer overflow in the Office Works File Converter in Microsoft Office 2007 SP2, Works 9, and Works 6-9 File Converter allows remote attackers to execute arbitrary code via a crafted Works (aka .wps) file, aka "Office WPS Converter Heap Overflow Vulnerability."
3706| [CVE-2012-0175] The Shell in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted name for a (1) file or (2) directory, aka "Command Injection Vulnerability."
3707| [CVE-2012-0174] Windows Firewall in tcpip.sys in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly enforce firewall rules for outbound broadcast packets, which allows remote attackers to obtain potentially sensitive information by observing broadcast traffic on a local network, aka "Windows Firewall Bypass Vulnerability."
3708| [CVE-2012-0173] The Remote Desktop Protocol (RDP) implementation in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly process packets in memory, which allows remote attackers to execute arbitrary code by sending crafted RDP packets triggering access to an object that (1) was not properly initialized or (2) is deleted, aka "Remote Desktop Protocol Vulnerability," a different vulnerability than CVE-2012-0002.
3709| [CVE-2012-0167] Heap-based buffer overflow in the Office GDI+ library in Microsoft Office 2003 SP3 and 2007 SP2 and SP3 allows remote attackers to execute arbitrary code via a crafted EMF image in an Office document, aka "GDI+ Heap Overflow Vulnerability."
3710| [CVE-2012-0165] GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2 and Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1 does not properly validate record types in EMF images, which allows remote attackers to execute arbitrary code via a crafted image, aka "GDI+ Record Type Vulnerability."
3711| [CVE-2012-0163] Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly validate function parameters, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka ".NET Framework Parameter Validation Vulnerability."
3712| [CVE-2012-0161] Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5 SP1, 3.5.1, and 4 does not properly handle an unspecified exception during use of partially trusted assemblies to serialize input data, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework application, aka ".NET Framework Serialization Vulnerability."
3713| [CVE-2012-0160] Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5 SP1, 3.5.1, and 4 does not properly serialize input data, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework application, aka ".NET Framework Serialization Vulnerability."
3714| [CVE-2012-0159] Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview
3715| [CVE-2012-0158] The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1
3716| [CVE-2012-0157] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle window messaging, which allows local users to gain privileges via a crafted application that calls the PostMessage function, aka "PostMessage Function Vulnerability."
3717| [CVE-2012-0156] DirectWrite in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly render Unicode characters, which allows remote attackers to cause a denial of service (application hang) via a (1) instant message or (2) web site, aka "DirectWrite Application Denial of Service Vulnerability."
3718| [CVE-2012-0154] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers keyboard layout errors, aka "Keyboard Layout Use After Free Vulnerability."
3719| [CVE-2012-0152] The Remote Desktop Protocol (RDP) service in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows remote attackers to cause a denial of service (application hang) via a series of crafted packets, aka "Terminal Server Denial of Service Vulnerability."
3720| [CVE-2012-0151] The Authenticode Signature Verification function in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview does not properly validate the digest of a signed portable executable (PE) file, which allows user-assisted remote attackers to execute arbitrary code via a modified file with additional content, aka "WinVerifyTrust Signature Validation Vulnerability."
3721| [CVE-2012-0150] Buffer overflow in msvcrt.dll in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted media file, aka "Msvcrt.dll Buffer Overflow Vulnerability."
3722| [CVE-2012-0149] afd.sys in the Ancillary Function Driver in Microsoft Windows Server 2003 SP2 does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application, aka "Ancillary Function Driver Elevation of Privilege Vulnerability."
3723| [CVE-2012-0148] afd.sys in the Ancillary Function Driver in Microsoft Windows XP SP2, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 on 64-bit platforms does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application, aka "AfdPoll Elevation of Privilege Vulnerability."
3724| [CVE-2012-0143] Microsoft Excel 2003 SP3 and Office 2008 for Mac do not properly handle memory during the opening of files, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel Memory Corruption Using Various Modified Bytes Vulnerability."
3725| [CVE-2012-0142] Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1
3726| [CVE-2012-0141] Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1
3727| [CVE-2012-0015] Microsoft .NET Framework 2.0 SP2 and 3.5.1 does not properly calculate the length of an unspecified buffer, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka ".NET Framework Heap Corruption Vulnerability."
3728| [CVE-2012-0014] Microsoft .NET Framework 2.0 SP2, 3.5.1, and 4, and Silverlight 4 before 4.1.10111, does not properly restrict access to memory associated with unmanaged objects, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, (3) a crafted .NET Framework application, or (4) a crafted Silverlight application, aka ".NET Framework Unmanaged Objects Vulnerability."
3729| [CVE-2012-0013] Incomplete blacklist vulnerability in the Windows Packager configuration in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted ClickOnce application in a Microsoft Office document, related to .application files, aka "Assembly Execution Vulnerability."
3730| [CVE-2012-0009] Untrusted search path vulnerability in the Windows Object Packager configuration in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a Trojan horse executable file in the current working directory, as demonstrated by a directory that contains a file with an embedded packaged object, aka "Object Packager Insecure Executable Launching Vulnerability."
3731| [CVE-2012-0008] Untrusted search path vulnerability in Microsoft Visual Studio 2008 SP1, 2010, and 2010 SP1 allows local users to gain privileges via a Trojan horse add-in in an unspecified directory, aka "Visual Studio Add-In Vulnerability."
3732| [CVE-2012-0006] The DNS server in Microsoft Windows Server 2003 SP2 and Server 2008 SP2, R2, and R2 SP1 does not properly handle objects in memory during record lookup, which allows remote attackers to cause a denial of service (daemon restart) via a crafted query, aka "DNS Denial of Service Vulnerability."
3733| [CVE-2012-0005] The Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP2, and Server 2008 SP2, when a Chinese, Japanese, or Korean system locale is used, can access uninitialized memory during the processing of Unicode characters, which allows local users to gain privileges via a crafted application, aka "CSRSS Elevation of Privilege Vulnerability."
3734| [CVE-2012-0004] Unspecified vulnerability in DirectShow in DirectX in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted media file, related to Quartz.dll, Qdvd.dll, closed captioning, and the Line21 DirectShow filter, aka "DirectShow Remote Code Execution Vulnerability."
3735| [CVE-2012-0003] Unspecified vulnerability in winmm.dll in Windows Multimedia Library in Windows Media Player (WMP) in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows remote attackers to execute arbitrary code via a crafted MIDI file, aka "MIDI Remote Code Execution Vulnerability."
3736| [CVE-2012-0002] The Remote Desktop Protocol (RDP) implementation in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly process packets in memory, which allows remote attackers to execute arbitrary code by sending crafted RDP packets triggering access to an object that (1) was not properly initialized or (2) is deleted, aka "Remote Desktop Protocol Vulnerability."
3737| [CVE-2012-0001] The kernel in Microsoft Windows XP SP2, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly load structured exception handling tables, which allows context-dependent attackers to bypass the SafeSEH security feature by leveraging a Visual C++ .NET 2003 application, aka "Windows Kernel SafeSEH Bypass Vulnerability."
3738| [CVE-2011-5046] The Graphics Device Interface (GDI) in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly validate user-mode input, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted data, as demonstrated by a large height attribute of an IFRAME element rendered by Safari, aka "GDI Access Violation Vulnerability."
3739| [CVE-2011-4434] Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 do not properly enforce AppLocker rules, which allows local users to bypass intended access restrictions via a (1) macro or (2) scripting feature in an application, as demonstrated by Microsoft Office applications and the SANDBOX_INERT and LOAD_IGNORE_CODE_AUTHZ_LEVEL flags.
3740| [CVE-2011-3417] The Forms Authentication feature in the ASP.NET subsystem in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0, when sliding expiry is enabled, does not properly handle cached content, which allows remote attackers to obtain access to arbitrary user accounts via a crafted URL, aka "ASP.NET Forms Authentication Ticket Caching Vulnerability."
3741| [CVE-2011-3416] The Forms Authentication feature in the ASP.NET subsystem in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0 allows remote authenticated users to obtain access to arbitrary user accounts via a crafted username, aka "ASP.Net Forms Authentication Bypass Vulnerability."
3742| [CVE-2011-3415] Open redirect vulnerability in the Forms Authentication feature in the ASP.NET subsystem in Microsoft .NET Framework 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted return URL, aka "Insecure Redirect in .NET Form Authentication Vulnerability."
3743| [CVE-2011-3414] The CaseInsensitiveHashProvider.getHashCode function in the HashTable implementation in the ASP.NET subsystem in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters, aka "Collisions in HashTable May Cause DoS Vulnerability."
3744| [CVE-2011-3413] Microsoft PowerPoint 2007 SP2
3745| [CVE-2011-3412] Microsoft Publisher 2003 SP3, and 2007 SP2 and SP3, allows remote attackers to execute arbitrary code via a crafted Publisher file that leverages incorrect memory handling, aka "Publisher Memory Corruption Vulnerability."
3746| [CVE-2011-3411] Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that leverages incorrect handling of values in memory, aka "Publisher Invalid Pointer Vulnerability."
3747| [CVE-2011-3410] Array index error in Microsoft Publisher 2003 SP3, and 2007 SP2 and SP3, allows remote attackers to execute arbitrary code via a crafted Publisher file that leverages incorrect handling of values in memory, aka "Publisher Out-of-bounds Array Index Vulnerability."
3748| [CVE-2011-3408] Csrsrv.dll in the Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly check permissions for sending inter-process device-event messages from low-integrity processes to high-integrity processes, which allows local users to gain privileges via a crafted application, aka "CSRSS Local Privilege Elevation Vulnerability."
3749| [CVE-2011-3406] Buffer overflow in Active Directory, Active Directory Application Mode (ADAM), and Active Directory Lightweight Directory Service (AD LDS) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote authenticated users to execute arbitrary code via a crafted query that leverages incorrect memory initialization, aka "Active Directory Buffer Overflow Vulnerability."
3750| [CVE-2011-3403] Microsoft Excel 2003 SP3 and Office 2004 for Mac do not properly handle objects in memory, which allows remote attackers to execute arbitrary code via a crafted Excel spreadsheet, aka "Record Memory Corruption Vulnerability."
3751| [CVE-2011-3402] Unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via crafted font data in a Word document or web page, as exploited in the wild in November 2011 by Duqu, aka "TrueType Font Parsing Vulnerability."
3752| [CVE-2011-3400] Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 do not properly handle OLE objects in memory, which allows remote attackers to execute arbitrary code via a crafted object in a file, aka "OLE Property Vulnerability."
3753| [CVE-2011-3397] The Microsoft Time component in DATIME.DLL in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted web site that leverages an unspecified "binary behavior" in Internet Explorer, aka "Microsoft Time Remote Code Execution Vulnerability."
3754| [CVE-2011-3396] Untrusted search path vulnerability in Microsoft PowerPoint 2007 SP2 and 2010 allows local users to gain privileges via a Trojan horse DLL in the current working directory, aka "PowerPoint Insecure Library Loading Vulnerability."
3755| [CVE-2011-2019] Untrusted search path vulnerability in Microsoft Internet Explorer 9 on Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains an HTML file, aka "Internet Explorer Insecure Library Loading Vulnerability."
3756| [CVE-2011-2018] The kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, and Windows 7 Gold and SP1 does not properly initialize objects, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Exception Handler Vulnerability."
3757| [CVE-2011-2016] Untrusted search path vulnerability in Windows Mail and Windows Meeting Space in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .eml or .wcinv file, aka "Windows Mail Insecure Library Loading Vulnerability."
3758| [CVE-2011-2014] The LDAP over SSL (aka LDAPS) implementation in Active Directory, Active Directory Application Mode (ADAM), and Active Directory Lightweight Directory Service (AD LDS) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not examine Certificate Revocation Lists (CRLs), which allows remote authenticated users to bypass intended certificate restrictions and access Active Directory resources by leveraging a revoked X.509 certificate for a domain account, aka "LDAPS Authentication Bypass Vulnerability."
3759| [CVE-2011-2013] Integer overflow in the TCP/IP implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code by sending a sequence of crafted UDP packets to a closed port, aka "Reference Counter Overflow Vulnerability."
3760| [CVE-2011-2011] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, aka "Win32k Use After Free Vulnerability."
3761| [CVE-2011-2008] Microsoft Host Integration Server (HIS) 2004 SP1, 2006 SP1, 2009, and 2010 allows remote attackers to cause a denial of service (SNA Server service outage) via crafted TCP or UDP traffic, aka "Access of Unallocated Memory DoS Vulnerability."
3762| [CVE-2011-2007] Microsoft Host Integration Server (HIS) 2004 SP1, 2006 SP1, 2009, and 2010 allows remote attackers to cause a denial of service (SNA Server service outage) via crafted TCP or UDP traffic, aka "Endless Loop DoS in snabase.exe Vulnerability."
3763| [CVE-2011-2005] afd.sys in the Ancillary Function Driver in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application, aka "Ancillary Function Driver Elevation of Privilege Vulnerability."
3764| [CVE-2011-2004] Array index error in win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows remote attackers to cause a denial of service (reboot) via a crafted TrueType font file, aka "TrueType Font Parsing Vulnerability," a different vulnerability than CVE-2011-3402.
3765| [CVE-2011-2003] Buffer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted .fon file, aka "Font Library File Buffer Overrun Vulnerability."
3766| [CVE-2011-2002] win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle TrueType fonts, which allows local users to cause a denial of service (system hang) via a crafted font file, aka "Win32k TrueType Font Type Translation Vulnerability."
3767| [CVE-2011-1991] Multiple untrusted search path vulnerabilities in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allow local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .doc, .rtf, or .txt file, related to (1) deskpan.dll in the Display Panning CPL Extension, (2) EAPHost Authenticator Service, (3) Folder Redirection, (4) HyperTerminal, (5) the Japanese Input Method Editor (IME), and (6) Microsoft Management Console (MMC), aka "Windows Components Insecure Library Loading Vulnerability."
3768| [CVE-2011-1990] Microsoft Excel 2007 SP2
3769| [CVE-2011-1989] Microsoft Excel 2003 SP3 and 2007 SP2
3770| [CVE-2011-1988] Microsoft Excel 2003 SP3 and 2007 SP2
3771| [CVE-2011-1987] Array index error in Microsoft Excel 2003 SP3 and 2007 SP2
3772| [CVE-2011-1986] Use-after-free vulnerability in Microsoft Excel 2003 SP3 allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel Use after Free WriteAV Vulnerability."
3773| [CVE-2011-1985] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly validate user-mode input, which allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via a crafted application, aka "Win32k Null Pointer De-reference Vulnerability."
3774| [CVE-2011-1984] WINS in Microsoft Windows Server 2003 SP2 and Server 2008 SP2, R2, and R2 SP1 allows local users to gain privileges by sending crafted packets over the loopback interface, aka "WINS Local Elevation of Privilege Vulnerability."
3775| [CVE-2011-1983] Use-after-free vulnerability in Microsoft Office 2007 SP2 and SP3, Office 2010 Gold and SP1, and Office for Mac 2011 allows remote attackers to execute arbitrary code via a crafted Word document, aka "Word Use After Free Vulnerability."
3776| [CVE-2011-1982] Microsoft Office 2007 SP2, and 2010 Gold and SP1, does not initialize an unspecified object pointer during the opening of Word documents, which allows remote attackers to execute arbitrary code via a crafted document, aka "Office Uninitialized Object Pointer Vulnerability."
3777| [CVE-2011-1980] Untrusted search path vulnerability in Microsoft Office 2003 SP3 and 2007 SP2 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .doc, .ppt, or .xls file, aka "Office Component Insecure Library Loading Vulnerability."
3778| [CVE-2011-1979] Microsoft Visio 2003 SP3 and 2007 SP2 does not properly validate objects in memory during Visio file parsing, which allows remote attackers to execute arbitrary code via a crafted file, aka "Move Around the Block RCE Vulnerability."
3779| [CVE-2011-1978] Microsoft .NET Framework 2.0 SP2, 3.5.1, and 4 does not properly validate the System.Net.Sockets trust level, which allows remote attackers to obtain sensitive information or trigger arbitrary outbound network traffic via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "Socket Restriction Bypass Vulnerability."
3780| [CVE-2011-1976] Cross-site scripting (XSS) vulnerability in the Report Viewer Control in Microsoft Visual Studio 2005 SP1 and Report Viewer 2005 SP1 allows remote attackers to inject arbitrary web script or HTML via a parameter in a data source, aka "Report Viewer Controls XSS Vulnerability."
3781| [CVE-2011-1975] Untrusted search path vulnerability in the Data Access Tracing component in Windows Data Access Components (Windows DAC) 6.0 in Microsoft Windows 7 Gold and SP1 and Windows Server 2008 R2 and R2 SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains an Excel .xlsx file, aka "Data Access Components Insecure Library Loading Vulnerability."
3782| [CVE-2011-1974] NDISTAPI.sys in the NDISTAPI driver in Remote Access Service (RAS) in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP2 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "NDISTAPI Elevation of Privilege Vulnerability."
3783| [CVE-2011-1972] Microsoft Visio 2003 SP3, 2007 SP2, and 2010 Gold and SP1 does not properly validate objects in memory during Visio file parsing, which allows remote attackers to execute arbitrary code via a crafted file, aka "pStream Release RCE Vulnerability."
3784| [CVE-2011-1971] The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly parse file metadata, which allows local users to cause a denial of service (reboot) via a crafted file, aka "Windows Kernel Metadata Parsing DOS Vulnerability."
3785| [CVE-2011-1970] The DNS server in Microsoft Windows Server 2003 SP2 and Windows Server 2008 SP2, R2, and R2 SP1 does not properly initialize memory, which allows remote attackers to cause a denial of service (service outage) via a query for a nonexistent domain, aka "DNS Uninitialized Memory Corruption Vulnerability."
3786| [CVE-2011-1968] The Remote Desktop Protocol (RDP) implementation in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP2 does not properly process packets in memory, which allows remote attackers to cause a denial of service (reboot) by sending crafted RDP packets triggering access to an object that (1) was not properly initialized or (2) is deleted, as exploited in the wild in 2011, aka "Remote Desktop Protocol Vulnerability."
3787| [CVE-2011-1967] Winsrv.dll in the Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly check permissions for sending inter-process device-event messages from low-integrity processes to high-integrity processes, which allows local users to gain privileges via a crafted application, aka "CSRSS Vulnerability."
3788| [CVE-2011-1966] The DNS server in Microsoft Windows Server 2008 SP2, R2, and R2 SP1 does not properly handle NAPTR queries that trigger recursive processing, which allows remote attackers to execute arbitrary code via a crafted query, aka "DNS NAPTR Query Vulnerability."
3789| [CVE-2011-1965] Tcpip.sys in the TCP/IP stack in Microsoft Windows 7 Gold and SP1 and Windows Server 2008 R2 and R2 SP1 does not properly implement URL-based QoS, which allows remote attackers to cause a denial of service (reboot) via a crafted URL to a web server, aka "TCP/IP QOS Denial of Service Vulnerability."
3790| [CVE-2011-1894] The MHTML protocol handler in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle a MIME format in a request for embedded content in an HTML document, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted EMBED element in a web page that is visited in Internet Explorer, aka "MHTML Mime-Formatted Request Vulnerability."
3791| [CVE-2011-1893] Cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint Server 2010, Windows SharePoint Services 2.0 and 3.0 SP2, and SharePoint Foundation 2010 allows remote attackers to inject arbitrary web script or HTML via the URI, aka "SharePoint XSS Vulnerability."
3792| [CVE-2011-1892] Microsoft Office Groove 2007 SP2, SharePoint Workspace 2010 Gold and SP1, Office Forms Server 2007 SP2, Office SharePoint Server 2007 SP2, Office SharePoint Server 2010 Gold and SP1, Office Groove Data Bridge Server 2007 SP2, Office Groove Management Server 2007 SP2, Groove Server 2010 Gold and SP1, Windows SharePoint Services 3.0 SP2, SharePoint Foundation 2010, and Office Web Apps 2010 Gold and SP1 do not properly handle Web Parts containing XML classes referencing external entities, which allows remote authenticated users to read arbitrary files via a crafted XML and XSL file, aka "SharePoint Remote File Disclosure Vulnerability."
3793| [CVE-2011-1888] win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Null Pointer De-reference Vulnerability."
3794| [CVE-2011-1887] win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Null Pointer De-reference Vulnerability."
3795| [CVE-2011-1885] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Null Pointer De-reference Vulnerability."
3796| [CVE-2011-1884] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Use After Free Vulnerability."
3797| [CVE-2011-1883] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Use After Free Vulnerability."
3798| [CVE-2011-1882] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Use After Free Vulnerability."
3799| [CVE-2011-1881] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Null Pointer De-reference Vulnerability."
3800| [CVE-2011-1880] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Null Pointer De-reference Vulnerability."
3801| [CVE-2011-1879] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Use After Free Vulnerability."
3802| [CVE-2011-1878] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Use After Free Vulnerability."
3803| [CVE-2011-1877] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, aka "Win32k Use After Free Vulnerability."
3804| [CVE-2011-1876] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Use After Free Vulnerability."
3805| [CVE-2011-1875] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Use After Free Vulnerability."
3806| [CVE-2011-1874] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Use After Free Vulnerability."
3807| [CVE-2011-1873] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 on 64-bit platforms does not properly validate pointers during the parsing of OpenType (aka OTF) fonts, which allows remote attackers to execute arbitrary code via a crafted font file, aka "Win32k OTF Validation Vulnerability."
3808| [CVE-2011-1872] Hyper-V in Microsoft Windows Server 2008 Gold, SP2, R2, and R2 SP1 allows guest OS users to cause a denial of service (host OS infinite loop) via malformed machine instructions in a VMBus packet, aka "VMBus Persistent DoS Vulnerability."
3809| [CVE-2011-1871] Tcpip.sys in the TCP/IP stack in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to cause a denial of service (reboot) via a series of crafted ICMP messages, aka "ICMP Denial of Service Vulnerability."
3810| [CVE-2011-1870] Integer overflow in the Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, and Windows Server 2003 SP2, allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application that triggers an incorrect memory assignment for a user transaction, aka "CSRSS Local EOP SrvWriteConsoleOutputString Vulnerability."
3811| [CVE-2011-1869] The Distributed File System (DFS) implementation in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote DFS servers to cause a denial of service (system hang) via a crafted referral response, aka "DFS Referral Response Vulnerability."
3812| [CVE-2011-1868] The Distributed File System (DFS) implementation in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly validate fields in DFS responses, which allows remote DFS servers to execute arbitrary code via a crafted response, aka "DFS Memory Corruption Vulnerability."
3813| [CVE-2011-1508] Microsoft Publisher 2003 SP3, and 2007 SP2 and SP3, does not properly manage memory allocations for function pointers, which allows user-assisted remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Function Pointer Overwrite Vulnerability."
3814| [CVE-2011-1284] Integer overflow in the Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application that triggers an incorrect memory assignment for a user transaction, aka "CSRSS Local EOP SrvWriteConsoleOutput Vulnerability."
3815| [CVE-2011-1283] The Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, and Windows Server 2008 Gold and SP2 does not ensure that an unspecified array index has a non-negative value before performing read and write operations, which allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application that triggers an incorrect memory assignment for a user transaction, aka "CSRSS Local EOP SrvSetConsoleNumberOfCommand Vulnerability."
3816| [CVE-2011-1282] The Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly initialize memory and consequently uses a NULL pointer in an unspecified function call, which allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application that triggers an incorrect memory assignment for a user transaction, aka "CSRSS Local EOP SrvSetConsoleLocalEUDC Vulnerability."
3817| [CVE-2011-1281] The Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly restrict the number of console objects for a process, which allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application that triggers an incorrect memory assignment for a user transaction, aka "CSRSS Local EOP AllocConsole Vulnerability."
3818| [CVE-2011-1280] The XML Editor in Microsoft InfoPath 2007 SP2 and 2010
3819| [CVE-2011-1279] Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information during parsing of Excel spreadsheets, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted spreadsheet, aka "Excel Out of Bounds WriteAV Vulnerability."
3820| [CVE-2011-1278] Microsoft Excel 2002 SP3 and Office 2004 for Mac do not properly validate record information during parsing of Excel spreadsheets, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted spreadsheet, aka "Excel WriteAV Vulnerability."
3821| [CVE-2011-1277] Microsoft Excel 2002 SP3, Office 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information during parsing of Excel spreadsheets, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted spreadsheet, aka "Excel Memory Corruption Vulnerability."
3822| [CVE-2011-1276] Buffer overflow in Microsoft Excel 2002 SP3, 2003 SP3, and 2007 SP2
3823| [CVE-2011-1275] Microsoft Excel 2002 SP3
3824| [CVE-2011-1274] Microsoft Excel 2002 SP3, 2003 SP3, and 2007 SP2
3825| [CVE-2011-1273] Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP2, and 2010
3826| [CVE-2011-1272] Microsoft Excel 2002 SP3, 2003 SP3, and 2007 SP2
3827| [CVE-2011-1270] Buffer overflow in Microsoft PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "Presentation Buffer Overrun RCE Vulnerability."
3828| [CVE-2011-1269] Microsoft PowerPoint 2002 SP3, 2003 SP3, and 2007 SP2
3829| [CVE-2011-1268] The SMB client in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote SMB servers to execute arbitrary code via a crafted (1) SMBv1 or (2) SMBv2 response, aka "SMB Response Parsing Vulnerability."
3830| [CVE-2011-1267] The SMB server in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to cause a denial of service (system hang) via a crafted (1) SMBv1 or (2) SMBv2 request, aka "SMB Request Parsing Vulnerability."
3831| [CVE-2011-1264] Cross-site scripting (XSS) vulnerability in Active Directory Certificate Services Web Enrollment in Microsoft Windows Server 2003 SP2 and Server 2008 Gold, SP2, R2, and R2 SP1 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka "Active Directory Certificate Services Vulnerability."
3832| [CVE-2011-1263] Cross-site scripting (XSS) vulnerability in the logon page in Remote Desktop Web Access (RD Web Access) in Microsoft Windows Server 2008 R2 and R2 SP1 allows remote attackers to inject arbitrary web script or HTML via the URI, aka "Remote Desktop Web Access Vulnerability."
3833| [CVE-2011-1253] Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5.1, and 4, and Silverlight 4 before 4.0.60831, does not properly restrict inheritance, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, (3) a crafted .NET Framework application, or (4) a crafted Silverlight application, aka ".NET Framework Class Inheritance Vulnerability."
3834| [CVE-2011-1252] Cross-site scripting (XSS) vulnerability in the SafeHTML function in the toStaticHTML API in Microsoft Internet Explorer 7 and 8, Office SharePoint Server 2007 SP2, Office SharePoint Server 2010 Gold and SP1, Groove Server 2010 Gold and SP1, Windows SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via unspecified strings, aka "toStaticHTML Information Disclosure Vulnerability" or "HTML Sanitization Vulnerability."
3835| [CVE-2011-1249] The Ancillary Function Driver (AFD) in afd.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Ancillary Function Driver Elevation of Privilege Vulnerability."
3836| [CVE-2011-1248] WINS in Microsoft Windows Server 2003 SP2 and Server 2008 Gold, SP2, R2, and R2 SP1 does not properly handle socket send exceptions, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted packets, related to unintended stack-frame values and buffer passing, aka "WINS Service Failed Response Vulnerability."
3837| [CVE-2011-1247] Untrusted search path vulnerability in the Microsoft Active Accessibility component in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, aka "Active Accessibility Insecure Library Loading Vulnerability."
3838| [CVE-2011-1242] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
3839| [CVE-2011-1241] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
3840| [CVE-2011-1240] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
3841| [CVE-2011-1239] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
3842| [CVE-2011-1238] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
3843| [CVE-2011-1237] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
3844| [CVE-2011-1236] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
3845| [CVE-2011-1235] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
3846| [CVE-2011-1234] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
3847| [CVE-2011-1233] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
3848| [CVE-2011-1232] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
3849| [CVE-2011-1231] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
3850| [CVE-2011-1230] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
3851| [CVE-2011-1229] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
3852| [CVE-2011-1228] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
3853| [CVE-2011-1227] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
3854| [CVE-2011-1226] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
3855| [CVE-2011-1225] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
3856| [CVE-2011-0980] Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly parse Office Art objects, which allows remote attackers to execute arbitrary code via vectors related to a function pointer, aka "Excel Dangling Pointer Vulnerability."
3857| [CVE-2011-0979] Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP2, and 2010
3858| [CVE-2011-0978] Stack-based buffer overflow in Microsoft Excel 2002 SP3, 2003 SP3, and 2007 SP2
3859| [CVE-2011-0977] Use-after-free vulnerability in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via malformed shape data in the Office drawing file format, aka "Microsoft Office Graphic Object Dereferencing Vulnerability."
3860| [CVE-2011-0976] Microsoft PowerPoint 2002 SP3, 2003 SP3, and 2007 SP2
3861| [CVE-2011-0677] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
3862| [CVE-2011-0676] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
3863| [CVE-2011-0675] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
3864| [CVE-2011-0674] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
3865| [CVE-2011-0672] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
3866| [CVE-2011-0671] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
3867| [CVE-2011-0670] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
3868| [CVE-2011-0667] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
3869| [CVE-2011-0666] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
3870| [CVE-2011-0665] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
3871| [CVE-2011-0664] Microsoft .NET Framework 2.0 SP1 and SP2, 3.5 Gold and SP1, 3.5.1, and 4.0, and Silverlight 4 before 4.0.60531.0, does not properly validate arguments to unspecified networking API functions, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, (3) a crafted .NET Framework application, or (4) a crafted Silverlight application, aka ".NET Framework Array Offset Vulnerability."
3872| [CVE-2011-0662] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
3873| [CVE-2011-0661] The SMB Server service in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly validate fields in SMB requests, which allows remote attackers to execute arbitrary code via a malformed request in a (1) SMBv1 or (2) SMBv2 packet, aka "SMB Transaction Parsing Vulnerability."
3874| [CVE-2011-0660] The SMB client in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote SMB servers to execute arbitrary code via a crafted (1) SMBv1 or (2) SMBv2 response, aka "SMB Client Response Parsing Vulnerability."
3875| [CVE-2011-0658] Integer underflow in the OLE Automation protocol implementation in VBScript.dll in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted WMF file, aka "OLE Automation Underflow Vulnerability."
3876| [CVE-2011-0657] DNSAPI.dll in the DNS client in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly process DNS queries, which allows remote attackers to execute arbitrary code via (1) a crafted LLMNR broadcast query or (2) a crafted application, aka "DNS Query Vulnerability."
3877| [CVE-2011-0656] Microsoft PowerPoint 2002 SP3, 2003 SP3, 2007 SP2, and 2010
3878| [CVE-2011-0655] Microsoft PowerPoint 2007 SP2 and 2010
3879| [CVE-2011-0654] Integer underflow in the BowserWriteErrorLogEntry function in the Common Internet File System (CIFS) browser service in Mrxsmb.sys or bowser.sys in Active Directory in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code or cause a denial of service (system crash) via a malformed BROWSER ELECTION message, leading to a heap-based buffer overflow, aka "Browser Pool Corruption Vulnerability." NOTE: some of these details are obtained from third party information.
3880| [CVE-2011-0107] Untrusted search path vulnerability in Microsoft Office XP SP3, Office 2003 SP3, and Office 2007 SP2 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .docx file, aka "Office Component Insecure Library Loading Vulnerability."
3881| [CVE-2011-0105] Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac obtain a certain length value from an uninitialized memory location, which allows remote attackers to trigger a buffer overflow and execute arbitrary code via a crafted Excel file, aka "Excel Data Initialization Vulnerability."
3882| [CVE-2011-0104] Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted HLink record in an Excel file, aka "Excel Buffer Overwrite Vulnerability."
3883| [CVE-2011-0103] Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted record information in an Excel file, aka "Excel Memory Corruption Vulnerability."
3884| [CVE-2011-0101] Microsoft Excel 2002 SP3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted RealTimeData record, related to a stTopic field, doubly-byte characters, and an incorrect pointer calculation, aka "Excel Record Parsing WriteAV Vulnerability."
3885| [CVE-2011-0098] Integer signedness error in Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP2, and 2010
3886| [CVE-2011-0097] Integer underflow in Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP2, and 2010
3887| [CVE-2011-0096] The MHTML protocol handler in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle a MIME format in a request for content blocks in a document, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted web site that is visited in Internet Explorer, aka "MHTML Mime-Formatted Request Vulnerability."
3888| [CVE-2011-0093] ELEMENTS.DLL in Microsoft Visio 2002 SP2, 2003 SP3, and 2007 SP2 does not properly parse structures during the opening of a Visio file, which allows remote attackers to execute arbitrary code via a file containing a malformed structure, aka "Visio Data Type Memory Corruption Vulnerability."
3889| [CVE-2011-0092] The LZW stream decompression functionality in ORMELEMS.DLL in Microsoft Visio 2002 SP2, 2003 SP3, and 2007 SP2 allows remote attackers to execute arbitrary code via a Visio file with a malformed VisioDocument stream that triggers an exception handler that accesses an object that has not been fully initialized, which triggers memory corruption, aka "Visio Object Memory Corruption Vulnerability."
3890| [CVE-2011-0091] Kerberos in Microsoft Windows Server 2008 R2 and Windows 7 does not prevent a session from changing from strong encryption to DES encryption, which allows man-in-the-middle attackers to spoof network traffic and obtain sensitive information via a DES downgrade, aka "Kerberos Spoofing Vulnerability."
3891| [CVE-2011-0090] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Win32k Memory Corruption Vulnerability."
3892| [CVE-2011-0089] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Win32k Window Class Improper Pointer Validation Vulnerability."
3893| [CVE-2011-0088] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Win32k Window Class Pointer Confusion Vulnerability."
3894| [CVE-2011-0087] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Win32k Insufficient User Input Validation Vulnerability."
3895| [CVE-2011-0086] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Win32k Improper User Input Validation Vulnerability."
3896| [CVE-2011-0043] Kerberos in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 supports weak hashing algorithms, which allows local users to gain privileges by operating a service that sends crafted service tickets, as demonstrated by the CRC32 algorithm, aka "Kerberos Unkeyed Checksum Vulnerability."
3897| [CVE-2011-0042] SBE.dll in the Stream Buffer Engine in Windows Media Player and Windows Media Center in Microsoft Windows XP SP2 and SP3, Windows XP Media Center Edition 2005 SP3, Windows Vista SP1 and SP2, Windows 7 Gold and SP1, and Windows Media Center TV Pack for Windows Vista does not properly parse Digital Video Recording (.dvr-ms) files, which allows remote attackers to execute arbitrary code via a crafted file, aka "DVR-MS Vulnerability."
3898| [CVE-2011-0041] Integer overflow in gdiplus.dll in GDI+ in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold and SP2, and Office XP SP3 allows remote attackers to execute arbitrary code via a crafted EMF image, aka "GDI+ Integer Overflow Vulnerability."
3899| [CVE-2011-0040] The server in Microsoft Active Directory on Windows Server 2003 SP2 does not properly handle an update request for a service principal name (SPN), which allows remote attackers to cause a denial of service (authentication downgrade or outage) via a crafted request that triggers name collisions, aka "Active Directory SPN Validation Vulnerability."
3900| [CVE-2011-0039] The Local Security Authority Subsystem Service (LSASS) in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly process authentication requests, which allows local users to gain privileges via a request with a crafted length, aka "LSASS Length Validation Vulnerability."
3901| [CVE-2011-0034] Stack-based buffer overflow in the OpenType Compact Font Format (aka OTF or CFF) driver in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via crafted parameter values in an OpenType font, aka "OpenType Font Stack Overflow Vulnerability."
3902| [CVE-2011-0033] The OpenType Compact Font Format (CFF) driver in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate parameter values in OpenType fonts, which allows remote attackers to execute arbitrary code via a crafted font, aka "OpenType Font Encoded Character Vulnerability."
3903| [CVE-2011-0032] Untrusted search path vulnerability in DirectShow in Microsoft Windows Vista SP1 and SP2, Windows 7 Gold and SP1, Windows Server 2008 R2 and R2 SP1, and Windows Media Center TV Pack for Windows Vista allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a Digital Video Recording (.dvr-ms), Windows Recorded TV Show (.wtv), or .mpg file, aka "DirectShow Insecure Library Loading Vulnerability."
3904| [CVE-2011-0031] The (1) JScript 5.8 and (2) VBScript 5.8 scripting engines in Microsoft Windows Server 2008 R2 and Windows 7 do not properly load decoded scripts obtained from web pages, which allows remote attackers to trigger memory corruption and consequently obtain sensitive information via a crafted web site, aka "Scripting Engines Information Disclosure Vulnerability."
3905| [CVE-2011-0030] The Client/Server Run-time Subsystem (CSRSS) in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly kill processes after a logout, which allows local users to obtain sensitive information or gain privileges via a crafted application that continues to execute throughout the logout of one user and the login session of the next user, aka "CSRSS Elevation of Privilege Vulnerability," a different vulnerability than CVE-2010-0023.
3906| [CVE-2011-0028] WordPad in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly parse fields in Word documents, which allows remote attackers to execute arbitrary code via a crafted .doc file, aka "WordPad Converter Parsing Vulnerability."
3907| [CVE-2010-5082] Untrusted search path vulnerability in colorcpl.exe 6.0.6000.16386 in the Color Control Panel in Microsoft Windows Server 2008 SP2, R2, and R2 SP1 allows local users to gain privileges via a Trojan horse sti.dll file in the current working directory, as demonstrated by a directory that contains a .camp, .cdmp, .gmmp, .icc, or .icm file, aka "Color Control Panel Insecure Library Loading Vulnerability."
3908| [CVE-2010-4701] Heap-based buffer overflow in the CDrawPoly::Serialize function in fxscover.exe in Microsoft Windows Fax Services Cover Page Editor 5.2 r2 in Windows XP Professional SP3, Server 2003 R2 Enterprise Edition SP2, and Windows 7 Professional allows remote attackers to execute arbitrary code via a long record in a Fax Cover Page (.cov) file. NOTE: some of these details are obtained from third party information.
3909| [CVE-2010-4669] The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Microsoft Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, and Windows 7 allows remote attackers to cause a denial of service (CPU consumption and system hang) by sending many Router Advertisement (RA) messages with different source addresses, as demonstrated by the flood_router6 program in the thc-ipv6 package.
3910| [CVE-2010-4562] Microsoft Windows 2008, 7, Vista, 2003, 2000, and XP, when using IPv6, allows remote attackers to determine whether a host is sniffing the network by sending an ICMPv6 Echo Request to a multicast address and determining whether an Echo Reply is sent, as demonstrated by thcping. NOTE: due to a typo, some sources map CVE-2010-4562 to a ProFTPd mod_sql vulnerability, but that issue is covered by CVE-2010-4652.
3911| [CVE-2010-4398] Stack-based buffer overflow in the RtlQueryRegistryValues function in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges, and bypass the User Account Control (UAC) feature, via a crafted REG_BINARY value for a SystemDefaultEUDCFont registry key, aka "Driver Improper Interaction with Windows Kernel Vulnerability."
3912| [CVE-2010-4182] Untrusted search path vulnerability in the Data Access Objects (DAO) library (dao360.dll) in Microsoft Windows XP Professional SP3, Windows Server 2003 R2 Enterprise Edition SP3, Windows Vista Business SP1, and Windows 7 Professional allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse msjet49.dll that is located in the same folder as a file that is processed by dao360.dll. NOTE: the provenance of this information is unknown
3913| [CVE-2010-3974] fxscover.exe in the Fax Cover Page Editor in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly parse FAX cover pages, which allows remote attackers to execute arbitrary code via a crafted .cov file, aka "Fax Cover Page Editor Memory Corruption Vulnerability."
3914| [CVE-2010-3970] Stack-based buffer overflow in the CreateSizedDIBSECTION function in shimgvw.dll in the Windows Shell graphics processor (aka graphics rendering engine) in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a crafted .MIC or unspecified Office document containing a thumbnail bitmap with a negative biClrUsed value, as reported by Moti and Xu Hao, aka "Windows Shell Graphics Processing Overrun Vulnerability."
3915| [CVE-2010-3966] Untrusted search path vulnerability in Microsoft Windows Server 2008 R2 and Windows 7, when BranchCache is supported, allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains an EML file, an RSS file, or a WPOST file, aka "BranchCache Insecure Library Loading Vulnerability."
3916| [CVE-2010-3965] Untrusted search path vulnerability in Windows Media Encoder 9 on Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, and Windows Server 2008 Gold and SP2 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a Windows Media Profile (PRX) file, aka "Insecure Library Loading Vulnerability."
3917| [CVE-2010-3964] Unrestricted file upload vulnerability in the Document Conversions Launcher Service in Microsoft Office SharePoint Server 2007 SP2, when the Document Conversions Load Balancer Service is enabled, allows remote attackers to execute arbitrary code via a crafted SOAP request to TCP port 8082, aka "Malformed Request Code Execution Vulnerability."
3918| [CVE-2010-3963] Buffer overflow in the Routing and Remote Access NDProxy component in the kernel in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a crafted application, related to the Routing and Remote Access service (RRAS) and improper copying from user mode to the kernel, aka "Kernel NDProxy Buffer Overflow Vulnerability."
3919| [CVE-2010-3961] The Consent User Interface (UI) in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly handle an unspecified registry-key value, which allows local users with SeImpersonatePrivilege rights to gain privileges via a crafted application, aka "Consent UI Impersonation Vulnerability."
3920| [CVE-2010-3960] Hyper-V in Microsoft Windows Server 2008 Gold, SP2, and R2 allows guest OS users to cause a denial of service (host OS hang) by sending a crafted encapsulated packet over the VMBus, aka "Hyper-V VMBus Vulnerability."
3921| [CVE-2010-3959] The OpenType Font (OTF) driver in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges via a crafted CMAP table in an OpenType font, aka "OpenType CMAP Table Vulnerability."
3922| [CVE-2010-3958] The x86 JIT compiler in Microsoft .NET Framework 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0 does not properly compile function calls, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka ".NET Framework Stack Corruption Vulnerability."
3923| [CVE-2010-3957] Double free vulnerability in the OpenType Font (OTF) driver in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges via a crafted OpenType font, aka "OpenType Font Double Free Vulnerability."
3924| [CVE-2010-3956] The OpenType Font (OTF) driver in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly perform array indexing, which allows local users to gain privileges via a crafted OpenType font, aka "OpenType Font Index Vulnerability."
3925| [CVE-2010-3955] pubconv.dll (aka the Publisher Converter DLL) in Microsoft Publisher 2002 SP3 does not properly perform array indexing, which allows remote attackers to execute arbitrary code via a crafted Publisher file that uses an old file format, aka "Array Indexing Memory Corruption Vulnerability."
3926| [CVE-2010-3954] Microsoft Publisher 2002 SP3, 2003 SP3, and 2010 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Publisher file, aka "Microsoft Publisher Memory Corruption Vulnerability."
3927| [CVE-2010-3946] Integer overflow in the PICT image converter in the graphics filters in Microsoft Office XP SP3, Office 2003 SP3, and Office Converter Pack allows remote attackers to execute arbitrary code via a crafted PICT image in an Office document, aka "PICT Image Converter Integer Overflow Vulnerability."
3928| [CVE-2010-3945] Buffer overflow in the CGM image converter in the graphics filters in Microsoft Office XP SP3, Office 2003 SP3, and Office Converter Pack allows remote attackers to execute arbitrary code via a crafted CGM image in an Office document, aka "CGM Image Converter Buffer Overrun Vulnerability."
3929| [CVE-2010-3944] win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2008 R2 and Windows 7 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Win32k Memory Corruption Vulnerability."
3930| [CVE-2010-3943] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly link driver objects, which allows local users to gain privileges via a crafted application that triggers linked-list corruption, aka "Win32k Cursor Linking Vulnerability."
3931| [CVE-2010-3942] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly allocate memory for copies from user mode, which allows local users to gain privileges via a crafted application, aka "Win32k WriteAV Vulnerability."
3932| [CVE-2010-3941] Double free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold and SP2, and Windows 7 allows local users to gain privileges via a crafted application, aka "Win32k Double Free Vulnerability."
3933| [CVE-2010-3940] Double free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges via a crafted application, aka "Win32k PFE Pointer Double Free Vulnerability."
3934| [CVE-2010-3939] Buffer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges via vectors related to improper memory allocation for copies from user mode, aka "Win32k Buffer Overflow Vulnerability."
3935| [CVE-2010-3937] Microsoft Exchange Server 2007 SP2 on the x64 platform allows remote authenticated users to cause a denial of service (infinite loop and MSExchangeIS outage) via a crafted RPC request, aka "Exchange Server Infinite Loop Vulnerability."
3936| [CVE-2010-3338] The Windows Task Scheduler in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly determine the security context of scheduled tasks, which allows local users to gain privileges via a crafted application, aka "Task Scheduler Vulnerability." NOTE: this might overlap CVE-2010-3888.
3937| [CVE-2010-3337] Untrusted search path vulnerability in Microsoft Office 2007 SP2 and 2010 allows local users to gain privileges via a Trojan horse DLL in the current working directory, aka "Insecure Library Loading Vulnerability." NOTE: this might overlap CVE-2010-3141 and CVE-2010-3142.
3938| [CVE-2010-3336] Microsoft Office XP SP3, Office 2004 and 2008 for Mac, Office for Mac 2011, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code via a crafted Office document that triggers memory corruption, aka "MSO Large SPID Read AV Vulnerability."
3939| [CVE-2010-3335] Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2008 for Mac, Office for Mac 2011, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code via a crafted Office document that triggers memory corruption, aka "Drawing Exception Handling Vulnerability."
3940| [CVE-2010-3334] Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2008 for Mac, Office for Mac 2011, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code via an Office document containing an Office Art Drawing record with crafted msofbtSp records and unspecified flags, which triggers memory corruption, aka "Office Art Drawing Records Vulnerability."
3941| [CVE-2010-3333] Stack-based buffer overflow in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2008 for Mac, Office for Mac 2011, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via crafted RTF data, aka "RTF Stack Buffer Overflow Vulnerability."
3942| [CVE-2010-3332] Microsoft .NET Framework 1.1 SP1, 2.0 SP1 and SP2, 3.5, 3.5 SP1, 3.5.1, and 4.0, as used for ASP.NET in Microsoft Internet Information Services (IIS), provides detailed error codes during decryption attempts, which allows remote attackers to decrypt and modify encrypted View State (aka __VIEWSTATE) form data, and possibly forge cookies or read application files, via a padding oracle attack, aka "ASP.NET Padding Oracle Vulnerability."
3943| [CVE-2010-3324] The toStaticHTML function in Microsoft Internet Explorer 8, and the SafeHTML function in Microsoft Windows SharePoint Services 3.0 SP2, SharePoint Foundation 2010, Office SharePoint Server 2007 SP2, Groove Server 2010, and Office Web Apps, allows remote attackers to bypass the cross-site scripting (XSS) protection mechanism and conduct XSS attacks via a crafted use of the Cascading Style Sheets (CSS) @import rule, aka "HTML Sanitization Vulnerability," a different vulnerability than CVE-2010-1257.
3944| [CVE-2010-3243] Cross-site scripting (XSS) vulnerability in the toStaticHTML function in Microsoft Internet Explorer 8, and the SafeHTML function in Microsoft Windows SharePoint Services 3.0 SP2 and Office SharePoint Server 2007 SP2, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "HTML Sanitization Vulnerability."
3945| [CVE-2010-3242] Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Ghost Record Type Parsing Vulnerability."
3946| [CVE-2010-3241] Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate binary file-format information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Out-of-Bounds Memory Write in Parsing Vulnerability."
3947| [CVE-2010-3240] Microsoft Excel 2002 SP3 and 2007 SP2
3948| [CVE-2010-3239] Microsoft Excel 2002 SP3 does not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Extra Out of Boundary Record Parsing Vulnerability."
3949| [CVE-2010-3238] Microsoft Excel 2002 SP3 and 2003 SP3, and Office 2004 for Mac, does not properly validate binary file-format information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Negative Future Function Vulnerability."
3950| [CVE-2010-3237] Microsoft Excel 2002 SP3 and Office 2004 for Mac do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Merge Cell Record Pointer Vulnerability."
3951| [CVE-2010-3236] Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Out Of Bounds Array Vulnerability."
3952| [CVE-2010-3235] Microsoft Excel 2002 SP3 does not properly validate formula information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Formula Biff Record Vulnerability."
3953| [CVE-2010-3234] Microsoft Excel 2002 SP3 does not properly validate formula information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Formula Substream Memory Corruption Vulnerability."
3954| [CVE-2010-3233] Microsoft Excel 2002 SP3 and 2003 SP3 does not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted .wk3 (aka Lotus 1-2-3 workbook) file, aka "Lotus 1-2-3 Workbook Parsing Vulnerability."
3955| [CVE-2010-3232] Microsoft Excel 2003 SP3 and 2007 SP2
3956| [CVE-2010-3231] Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Excel Record Parsing Memory Corruption Vulnerability."
3957| [CVE-2010-3230] Integer overflow in Microsoft Excel 2002 SP3 allows remote attackers to execute arbitrary code via an Excel document with crafted record information, aka "Excel Record Parsing Integer Overflow Vulnerability."
3958| [CVE-2010-3229] The Secure Channel (aka SChannel) security package in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, when IIS 7.x is used, does not properly process client certificates during SSL and TLS handshakes, which allows remote attackers to cause a denial of service (LSASS outage and reboot) via a crafted packet, aka "TLSv1 Denial of Service Vulnerability."
3959| [CVE-2010-3227] Stack-based buffer overflow in the UpdateFrameTitleForDocument method in the CFrameWnd class in mfc42.dll in the Microsoft Foundation Class (MFC) Library in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows context-dependent attackers to execute arbitrary code via a long window title that this library attempts to create at the request of an application, as demonstrated by the Trident PowerZip 7.2 Build 4010 application, aka "Windows MFC Document Title Updating Buffer Overflow Vulnerability."
3960| [CVE-2010-3223] The user interface in Microsoft Cluster Service (MSCS) in Microsoft Windows Server 2008 R2 does not properly set administrative-share permissions for new cluster disks that are shared as part of a failover cluster, which allows remote attackers to read or modify data on these disks via requests to the associated share, aka "Permissions on New Cluster Disks Vulnerability."
3961| [CVE-2010-3222] Stack-based buffer overflow in the Remote Procedure Call Subsystem (RPCSS) in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a crafted LPC message that requests an LRPC connection from an LPC server to a client, aka "LPC Message Buffer Overrun Vulnerability."
3962| [CVE-2010-3221] Microsoft Word 2002 SP3 and 2003 SP3, Office 2004 for Mac, and Word Viewer do not properly handle a malformed record during parsing of a Word document, which allows remote attackers to execute arbitrary code via a crafted document that triggers memory corruption, aka "Word Parsing Vulnerability."
3963| [CVE-2010-3220] Unspecified vulnerability in Microsoft Word 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Word document that triggers memory corruption, aka "Word Parsing Vulnerability."
3964| [CVE-2010-3219] Array index vulnerability in Microsoft Word 2002 SP3 allows remote attackers to execute arbitrary code via a crafted Word document that triggers memory corruption, aka "Word Index Parsing Vulnerability."
3965| [CVE-2010-3218] Heap-based buffer overflow in Microsoft Word 2002 SP3 allows remote attackers to execute arbitrary code via malformed records in a Word document, aka "Word Heap Overflow Vulnerability."
3966| [CVE-2010-3217] Double free vulnerability in Microsoft Word 2002 SP3 allows remote attackers to execute arbitrary code via a Word document with crafted List Format Override (LFO) records, aka "Word Pointer Vulnerability."
3967| [CVE-2010-3216] Microsoft Word 2002 SP3 and Office 2004 for Mac allow remote attackers to execute arbitrary code via a crafted Word document containing bookmarks that trigger use of an invalid pointer and memory corruption, aka "Word Bookmarks Vulnerability."
3968| [CVE-2010-3215] Microsoft Word 2002 SP3 and Office 2004 for Mac do not properly handle unspecified return values during parsing of a Word document, which allows remote attackers to execute arbitrary code via a crafted document that triggers memory corruption, aka "Word Return Value Vulnerability."
3969| [CVE-2010-3214] Stack-based buffer overflow in Microsoft Word 2002 SP3, 2003 SP3, 2007 SP2, and 2010
3970| [CVE-2010-3213] Cross-site request forgery (CSRF) vulnerability in Microsoft Outlook Web Access (owa/ev.owa) 2007 through SP2 allows remote attackers to hijack the authentication of e-mail users for requests that perform Outlook requests, as demonstrated by setting the auto-forward rule.
3971| [CVE-2010-3200] MSO.dll in Microsoft Word 2003 SP3 11.8326.11.8324 allows remote attackers to cause a denial of service (NULL pointer dereference and multiple-instance application crash) via a crafted buffer in a Word document, as demonstrated by word_crash_11.8326.8324_poc.doc.
3972| [CVE-2010-3190] Untrusted search path vulnerability in the Microsoft Foundation Class (MFC) Library in Microsoft Visual Studio .NET 2003 SP1
3973| [CVE-2010-3148] Untrusted search path vulnerability in Microsoft Visio 2003 SP3 allows local users to gain privileges via a Trojan horse mfc71enu.dll file in the current working directory, as demonstrated by a directory that contains a .vsd, .vdx, .vst, or .vtx file, aka "Microsoft Visio Insecure Library Loading Vulnerability."
3974| [CVE-2010-3147] Untrusted search path vulnerability in wab.exe 6.00.2900.5512 in Windows Address Book in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges via a Trojan horse wab32res.dll file in the current working directory, as demonstrated by a directory that contains a Windows Address Book (WAB), VCF (aka vCard), or P7C file, aka "Insecure Library Loading Vulnerability." NOTE: the codebase for this product may overlap the codebase for the product referenced in CVE-2010-3143.
3975| [CVE-2010-3146] Multiple untrusted search path vulnerabilities in Microsoft Groove 2007 SP2 allow local users to gain privileges via a Trojan horse (1) mso.dll or (2) GroovePerfmon.dll file in the current working directory, as demonstrated by a directory that contains a Groove vCard (.vcg) or Groove Tool Archive (.gta) file, aka "Microsoft Groove Insecure Library Loading Vulnerability."
3976| [CVE-2010-3144] Untrusted search path vulnerability in the Internet Connection Signup Wizard in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a Trojan horse smmscrpt.dll file in the current working directory, as demonstrated by a directory that contains an ISP or INS file, aka "Internet Connection Signup Wizard Insecure Library Loading Vulnerability."
3977| [CVE-2010-3142] Untrusted search path vulnerability in Microsoft Office PowerPoint 2007 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse rpawinet.dll that is located in the same folder as a .odp, .pothtml, .potm, .potx, .ppa, .ppam, .pps, .ppt, .ppthtml, .pptm, .pptxml, .pwz, .sldm, .sldx, and .thmx file.
3978| [CVE-2010-2750] Array index error in Microsoft Word 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Word document that triggers memory corruption, aka "Word Index Vulnerability."
3979| [CVE-2010-2748] Microsoft Word 2002 SP3 and Office 2004 for Mac do not properly check an unspecified boundary during parsing of a Word document, which allows remote attackers to execute arbitrary code via a crafted document that triggers memory corruption, aka "Word Boundary Check Vulnerability."
3980| [CVE-2010-2747] Microsoft Word 2002 SP3 and Office 2004 for Mac do not properly handle an uninitialized pointer during parsing of a Word document, which allows remote attackers to execute arbitrary code via a crafted document that triggers memory corruption, aka "Word Uninitialized Pointer Vulnerability."
3981| [CVE-2010-2746] Heap-based buffer overflow in Comctl32.dll (aka the common control library) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, when a third-party SVG viewer is used, allows remote attackers to execute arbitrary code via a crafted HTML document that triggers unspecified messages from this viewer, aka "Comctl32 Heap Overflow Vulnerability."
3982| [CVE-2010-2744] The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 do not properly manage a window class, which allows local users to gain privileges by creating a window, then using (1) the SetWindowLongPtr function to modify the popup menu structure, or (2) the SwitchWndProc function with a switch window information pointer, which is not re-initialized when a WM_NCCREATE message is processed, aka "Win32k Window Class Vulnerability."
3983| [CVE-2010-2742] The Netlogon RPC Service in Microsoft Windows Server 2003 SP2 and Server 2008 Gold, SP2, and R2, when the domain controller role is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and reboot) via a crafted RPC packet, aka "Netlogon RPC Null dereference DOS Vulnerability."
3984| [CVE-2010-2741] The OpenType Font (OTF) format driver in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 performs an incorrect integer calculation during font processing, which allows local users to gain privileges via a crafted application, aka "OpenType Font Validation Vulnerability."
3985| [CVE-2010-2740] The OpenType Font (OTF) format driver in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly perform memory allocation during font parsing, which allows local users to gain privileges via a crafted application, aka "OpenType Font Parsing Vulnerability."
3986| [CVE-2010-2739] Buffer overflow in the CreateDIBPalette function in win32k.sys in Microsoft Windows XP SP3, Server 2003 R2 Enterprise SP2, Vista Business SP1, Windows 7, and Server 2008 SP2 allows local users to cause a denial of service (crash) and possibly execute arbitrary code by performing a clipboard operation (GetClipboardData API function) with a crafted bitmap with a palette that contains a large number of colors.
3987| [CVE-2010-2738] The Uniscribe (aka new Unicode Script Processor) implementation in USP10.DLL in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2, and Microsoft Office XP SP3, 2003 SP3, and 2007 SP2, does not properly validate tables associated with malformed OpenType fonts, which allows remote attackers to execute arbitrary code via a crafted (1) web site or (2) Office document, aka "Uniscribe Font Parsing Engine Memory Corruption Vulnerability."
3988| [CVE-2010-2729] The Print Spooler service in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, when printer sharing is enabled, does not properly validate spooler access permissions, which allows remote attackers to create files in a system directory, and consequently execute arbitrary code, by sending a crafted print request over RPC, as exploited in the wild in September 2010, aka "Print Spooler Service Impersonation Vulnerability."
3989| [CVE-2010-2728] Heap-based buffer overflow in Microsoft Outlook 2002 SP3, 2003 SP3, and 2007 SP2, when Online Mode for an Exchange Server is enabled, allows remote attackers to execute arbitrary code via a crafted e-mail message, aka "Heap Based Buffer Overflow in Outlook Vulnerability."
3990| [CVE-2010-2573] Integer underflow in Microsoft PowerPoint 2002 SP3 and 2003 SP3, PowerPoint Viewer SP2, and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint Integer Underflow Causes Heap Corruption Vulnerability."
3991| [CVE-2010-2572] Buffer overflow in Microsoft PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint 95 document, aka "PowerPoint Parsing Buffer Overflow Vulnerability."
3992| [CVE-2010-2571] Array index error in pubconv.dll (aka the Publisher Converter DLL) in Microsoft Publisher 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher 97 file, aka "Memory Corruption Due To Invalid Index Into Array in Pubconv.dll Vulnerability."
3993| [CVE-2010-2570] Heap-based buffer overflow in pubconv.dll (aka the Publisher Converter DLL) in Microsoft Publisher 2002 SP3, 2003 SP3, 2007 SP2, and 2010 allows remote attackers to execute arbitrary code via a crafted Publisher file that uses an old file format, aka "Heap Overrun in pubconv.dll Vulnerability."
3994| [CVE-2010-2569] pubconv.dll (aka the Publisher Converter DLL) in Microsoft Publisher 2002 SP3, 2003 SP3, and 2007 SP2 does not properly handle an unspecified size field in certain older file formats, which allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted Publisher file, aka "Size Value Heap Corruption in pubconv.dll Vulnerability."
3995| [CVE-2010-2568] Windows Shell in Microsoft Windows XP SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 allows local users or remote attackers to execute arbitrary code via a crafted (1) .LNK or (2) .PIF shortcut file, which is not properly handled during icon display in Windows Explorer, as demonstrated in the wild in July 2010, and originally reported for malware that leverages CVE-2010-2772 in Siemens WinCC SCADA systems.
3996| [CVE-2010-2567] The RPC client implementation in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly allocate memory during the parsing of responses, which allows remote RPC servers and man-in-the-middle attackers to execute arbitrary code via a malformed response, aka "RPC Memory Corruption Vulnerability."
3997| [CVE-2010-2566] The Secure Channel (aka SChannel) security package in Microsoft Windows XP SP2 and SP3, and Windows Server 2003 SP2, does not properly validate certificate request messages from TLS and SSL servers, which allows remote servers to execute arbitrary code via a crafted SSL response, aka "SChannel Malformed Certificate Request Remote Code Execution Vulnerability."
3998| [CVE-2010-2563] The Word 97 text converter in the WordPad Text Converters in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly parse malformed structures in Word 97 documents, which allows remote attackers to execute arbitrary code via a crafted document containing an unspecified value that is used in a loop counter, aka "WordPad Word 97 Text Converter Memory Corruption Vulnerability."
3999| [CVE-2010-2562] Microsoft Office Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Excel file, aka "Excel Memory Corruption Vulnerability."
4000| [CVE-2010-2555] The Tracing Feature for Services in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly determine the length of strings in the registry, which allows local users to gain privileges or cause a denial of service (memory corruption) via vectors involving a long string, aka "Tracing Memory Corruption Vulnerability."
4001| [CVE-2010-2554] The Tracing Feature for Services in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 has incorrect ACLs on its registry keys, which allows local users to gain privileges via vectors involving a named pipe and impersonation, aka "Tracing Registry Key ACL Vulnerability."
4002| [CVE-2010-2552] Stack consumption vulnerability in the SMB Server in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows remote attackers to cause a denial of service (system hang) via a malformed SMBv2 compounded request, aka "SMB Stack Exhaustion Vulnerability."
4003| [CVE-2010-2551] The SMB Server in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate an internal variable in an SMB packet, which allows remote attackers to cause a denial of service (system hang) via a crafted (1) SMBv1 or (2) SMBv2 packet, aka "SMB Variable Validation Vulnerability."
4004| [CVE-2010-2550] The SMB Server in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate fields in an SMB request, which allows remote attackers to execute arbitrary code via a crafted SMB packet, aka "SMB Pool Overflow Vulnerability."
4005| [CVE-2010-2549] Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Vista SP1 and SP2 and Server 2008 Gold and SP2 allows local users to gain privileges or cause a denial of service (system crash) by using a large number of calls to the NtUserCheckAccessForIntegrityLevel function to trigger a failure in the LockProcessByClientId function, leading to deletion of an in-use process object, aka "Win32k Reference Count Vulnerability."
4006| [CVE-2010-2265] Cross-site scripting (XSS) vulnerability in the GetServerName function in sysinfo/commonFunc.js in Microsoft Windows Help and Support Center for Windows XP and Windows Server 2003 allows remote attackers to inject arbitrary web script or HTML via the svr parameter to sysinfo/sysinfomain.htm. NOTE: this can be leveraged with CVE-2010-1885 to execute arbitrary commands without user interaction.
4007| [CVE-2010-2091] Microsoft Outlook Web Access (OWA) 8.2.254.0, when Internet Explorer 7 on Windows Server 2003 is used, does not properly handle the id parameter in a Folder IPF.Note action to the default URI, which might allow remote attackers to obtain sensitive information or conduct cross-site scripting (XSS) attacks via an invalid value.
4008| [CVE-2010-2084] Microsoft ASP.NET 2.0 does not prevent setting the InnerHtml property on a control that inherits from HtmlContainerControl, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to an attribute.
4009| [CVE-2010-1903] Microsoft Office Word 2002 SP3 and 2003 SP3, and Office Word Viewer, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a malformed record in a Word file, aka "Word HTML Linked Objects Memory Corruption Vulnerability."
4010| [CVE-2010-1902] Buffer overflow in Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP2
4011| [CVE-2010-1901] Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP2
4012| [CVE-2010-1900] Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP2
4013| [CVE-2010-1898] The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP1, 2.0 SP2, 3.5, 3.5 SP1, and 3.5.1, and Microsoft Silverlight 2 and 3 before 3.0.50611.0 on Windows and before 3.0.41130.0 on Mac OS X, does not properly handle interfaces and delegations to virtual methods, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "Microsoft Silverlight and Microsoft .NET Framework CLR Virtual Method Delegate Vulnerability."
4014| [CVE-2010-1897] The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 do not properly validate pseudo-handle values in callback parameters during window creation, which allows local users to gain privileges via a crafted application, aka "Win32k Window Creation Vulnerability."
4015| [CVE-2010-1896] The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, and Windows Server 2008 Gold and SP2 do not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application, aka "Win32k User Input Validation Vulnerability."
4016| [CVE-2010-1895] The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, and Windows Server 2003 SP2, do not properly perform memory allocation before copying user-mode data to kernel mode, which allows local users to gain privileges via a crafted application, aka "Win32k Pool Overflow Vulnerability."
4017| [CVE-2010-1894] The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, and Windows Server 2003 SP2, do not properly handle unspecified exceptions, which allows local users to gain privileges via a crafted application, aka "Win32k Exception Handling Vulnerability."
4018| [CVE-2010-1893] Integer overflow in the TCP/IP stack in Microsoft Windows Vista SP1, Windows Server 2008 Gold and R2, and Windows 7 allows local users to gain privileges via a buffer of user-mode data that is copied to kernel mode, aka "Integer Overflow in Windows Networking Vulnerability."
4019| [CVE-2010-1892] The TCP/IP stack in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly handle malformed IPv6 packets, which allows remote attackers to cause a denial of service (system hang) via multiple crafted packets, aka "IPv6 Memory Corruption Vulnerability."
4020| [CVE-2010-1891] The Client/Server Runtime Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2, when a Chinese, Japanese, or Korean locale is enabled, does not properly allocate memory for transactions, which allows local users to gain privileges via a crafted application, aka "CSRSS Local Elevation of Privilege Vulnerability."
4021| [CVE-2010-1890] The kernel in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate ACLs on kernel objects, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Improper Validation Vulnerability."
4022| [CVE-2010-1889] Double free vulnerability in the kernel in Microsoft Windows Vista SP1 and SP2, and Windows Server 2008 Gold and SP2, allows local users to gain privileges via a crafted application, related to object initialization during error handling, aka "Windows Kernel Double Free Vulnerability."
4023| [CVE-2010-1887] The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 do not properly validate an unspecified system-call argument, which allows local users to cause a denial of service (system hang) via a crafted application, aka "Win32k Bounds Checking Vulnerability."
4024| [CVE-2010-1886] Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 SP2 and R2, and Windows 7 allow local users to gain privileges by leveraging access to a process with NetworkService credentials, as demonstrated by TAPI Server, SQL Server, and IIS processes, and related to the Windows Service Isolation feature. NOTE: the vendor states that privilege escalation from NetworkService to LocalSystem does not cross a "security boundary."
4025| [CVE-2010-1885] The MPC::HexToNum function in helpctr.exe in Microsoft Windows Help and Support Center in Windows XP and Windows Server 2003 does not properly handle malformed escape sequences, which allows remote attackers to bypass the trusted documents whitelist (fromHCP option) and execute arbitrary commands via a crafted hcp:// URL, aka "Help Center URL Validation Vulnerability."
4026| [CVE-2010-1883] Integer overflow in the Embedded OpenType (EOT) Font Engine in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows remote attackers to execute arbitrary code via a crafted table in an embedded font, aka "Embedded OpenType Font Integer Overflow Vulnerability."
4027| [CVE-2010-1882] Multiple buffer overflows in the MPEG Layer-3 Audio Codec for Microsoft DirectShow in l3codecx.ax in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allow remote attackers to execute arbitrary code via an MPEG Layer-3 audio stream in (1) a crafted media file or (2) crafted streaming content, aka "MPEG Layer-3 Audio Decoder Buffer Overflow Vulnerability."
4028| [CVE-2010-1881] The FieldList ActiveX control in the Microsoft Access Wizard Controls in ACCWIZ.dll in Microsoft Office Access 2003 SP3 does not properly interact with the memory-access approach used by Internet Explorer and Office during instantiation, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via an HTML document that references this control along with crafted persistent storage data, aka "ACCWIZ.dll Uninitialized Variable Vulnerability."
4029| [CVE-2010-1880] Unspecified vulnerability in Quartz.dll for DirectShow on Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1, and Server 2008 allows remote attackers to execute arbitrary code via a media file with crafted compression data, aka "MJPEG Media Decompression Vulnerability."
4030| [CVE-2010-1735] The SfnLOGONNOTIFY function in win32k.sys in the kernel in Microsoft Windows 2000, XP, and Server 2003 allows local users to cause a denial of service (system crash) via a 0x4c value in the second argument (aka the Msg argument) of a PostMessage function call for the DDEMLEvent window.
4031| [CVE-2010-1734] The SfnINSTRING function in win32k.sys in the kernel in Microsoft Windows 2000, XP, and Server 2003 allows local users to cause a denial of service (system crash) via a 0x18d value in the second argument (aka the Msg argument) of a PostMessage function call for the DDEMLEvent window.
4032| [CVE-2010-1690] The DNS implementation in smtpsvc.dll before 6.0.2600.5949 in Microsoft Windows 2000 SP4 and earlier, Windows XP SP3 and earlier, Windows Server 2003 SP2 and earlier, Windows Server 2008 SP2 and earlier, Windows Server 2008 R2, Exchange Server 2003 SP3 and earlier, Exchange Server 2007 SP2 and earlier, and Exchange Server 2010 does not verify that transaction IDs of responses match transaction IDs of queries, which makes it easier for man-in-the-middle attackers to spoof DNS responses, a different vulnerability than CVE-2010-0024 and CVE-2010-0025.
4033| [CVE-2010-1689] The DNS implementation in smtpsvc.dll before 6.0.2600.5949 in Microsoft Windows 2000 SP4 and earlier, Windows XP SP3 and earlier, Windows Server 2003 SP2 and earlier, Windows Server 2008 SP2 and earlier, Windows Server 2008 R2, Exchange Server 2003 SP3 and earlier, Exchange Server 2007 SP2 and earlier, and Exchange Server 2010 uses predictable transaction IDs that are formed by incrementing a previous ID by 1, which makes it easier for man-in-the-middle attackers to spoof DNS responses, a different vulnerability than CVE-2010-0024 and CVE-2010-0025.
4034| [CVE-2010-1263] Windows Shell and WordPad in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7
4035| [CVE-2010-1257] Cross-site scripting (XSS) vulnerability in the toStaticHTML API, as used in Microsoft Office InfoPath 2003 SP3, 2007 SP1, and 2007 SP2
4036| [CVE-2010-1255] The Windows kernel-mode drivers in win32k.sys in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 Gold and SP2, Windows 7, and Server 2008 R2 allows local users to execute arbitrary code via vectors related to "glyph outline information" and TrueType fonts, aka "Win32k TrueType Font Parsing Vulnerability."
4037| [CVE-2010-1253] Microsoft Office Excel 2002 SP3, 2007 SP1, and SP2
4038| [CVE-2010-1252] Unspecified vulnerability in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Excel file, aka "Excel String Variable Vulnerability."
4039| [CVE-2010-1251] Unspecified vulnerability in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Excel file, aka "Excel Record Stack Corruption Vulnerability."
4040| [CVE-2010-1250] Heap-based buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via an Excel file with malformed (1) EDG (0x88) and (2) Publisher (0x89) records, aka "Excel EDG Memory Corruption Vulnerability."
4041| [CVE-2010-1249] Buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via an Excel file with a malformed ExternName (0x23) record, aka "Excel Memory Corruption Vulnerability," a different vulnerability than CVE-2010-0823 and CVE-2010-1247.
4042| [CVE-2010-1248] Buffer overflow in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via an Excel file with a malformed HFPicture (0x866) record, aka "Excel HFPicture Memory Corruption Vulnerability."
4043| [CVE-2010-1247] Unspecified vulnerability in Microsoft Office Excel 2002 SP3 allows remote attackers to execute arbitrary code via an Excel file with a malformed RTD (0x813) record that triggers heap corruption, aka "Excel Memory Corruption Vulnerability," a different vulnerability than CVE-2010-0823 and CVE-2010-1249.
4044| [CVE-2010-1246] Stack-based buffer overflow in Microsoft Office Excel 2002 SP3 allows remote attackers to execute arbitrary code via an Excel file with a malformed RTD (0x813) record, aka "Excel RTD Memory Corruption Vulnerability."
4045| [CVE-2010-1245] Unspecified vulnerability in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via an Excel file with a malformed SxView (0xB0) record, aka "Excel Record Memory Corruption Vulnerability," a different vulnerability than CVE-2010-0824 and CVE-2010-0821.
4046| [CVE-2010-1225] The memory-management implementation in the Virtual Machine Monitor (aka VMM or hypervisor) in Microsoft Virtual PC 2007 Gold and SP1, Virtual Server 2005 Gold and R2 SP1, and Windows Virtual PC does not properly restrict access from the guest OS to memory locations in the VMM work area, which allows context-dependent attackers to bypass certain anti-exploitation protection mechanisms on the guest OS via crafted input to a vulnerable application. NOTE: the vendor reportedly found that only systems with an otherwise vulnerable application are affected, because "the memory areas accessible from the guest cannot be leveraged to achieve either remote code execution or elevation of privilege and ... no data from the host is exposed to the guest OS."
4047| [CVE-2010-1175] Microsoft Internet Explorer 7.0 on Windows XP and Windows Server 2003 allows remote attackers to have an unspecified impact via a certain XML document that references a crafted web site in the SRC attribute of an image element, related to a "0day Vulnerability."
4048| [CVE-2010-0917] Stack-based buffer overflow in VBScript in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, when Internet Explorer is used, might allow user-assisted remote attackers to execute arbitrary code via a long string in the fourth argument (aka helpfile argument) to the MsgBox function, leading to code execution when the F1 key is pressed, a different vulnerability than CVE-2010-0483.
4049| [CVE-2010-0824] Unspecified vulnerability in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via an Excel file with a malformed WOPT (0x80B) record, aka "Excel Record Memory Corruption Vulnerability," a different vulnerability than CVE-2010-0821 and CVE-2010-1245.
4050| [CVE-2010-0823] Unspecified vulnerability in Microsoft Office Excel 2002 SP3, 2003 SP3, 2007 SP1 and SP2
4051| [CVE-2010-0822] Stack-based buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via an Excel file with a crafted OBJ (0x5D) record, aka "Excel Object Stack Overflow Vulnerability."
4052| [CVE-2010-0821] Unspecified vulnerability in Microsoft Office Excel 2002 SP3, 2003 SP3, 2007 SP1 and SP2
4053| [CVE-2010-0820] Heap-based buffer overflow in the Local Security Authority Subsystem Service (LSASS), as used in Active Directory in Microsoft Windows Server 2003 SP2 and Windows Server 2008 Gold, SP2, and R2
4054| [CVE-2010-0819] Unspecified vulnerability in the Windows OpenType Compact Font Format (CFF) driver in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 allows local users to execute arbitrary code via unknown vectors related to improper validation when copying data from user mode to kernel mode, aka "OpenType CFF Font Driver Memory Corruption Vulnerability."
4055| [CVE-2010-0818] The MPEG-4 codec in the Windows Media codecs in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2 does not properly handle crafted media content with MPEG-4 video encoding, which allows remote attackers to execute arbitrary code via a file in an unspecified "supported format," aka "MPEG-4 Codec Vulnerability."
4056| [CVE-2010-0817] Cross-site scripting (XSS) vulnerability in _layouts/help.aspx in Microsoft SharePoint Server 2007 12.0.0.6421 and possibly earlier, and SharePoint Services 3.0 SP1 and SP2, versions, allows remote attackers to inject arbitrary web script or HTML via the cid0 parameter.
4057| [CVE-2010-0815] VBE6.DLL in Microsoft Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Visual Basic for Applications (VBA), and VBA SDK 6.3 through 6.5 does not properly search for ActiveX controls that are embedded in documents, which allows remote attackers to execute arbitrary code via a crafted document, aka "VBE6.DLL Stack Memory Corruption Vulnerability."
4058| [CVE-2010-0814] The Microsoft Access Wizard Controls in ACCWIZ.dll in Microsoft Office Access 2003 SP3 and 2007 SP1 and SP2 do not properly interact with the memory-allocation approach used by Internet Explorer during instantiation, which allows remote attackers to execute arbitrary code via a web site that references multiple ActiveX controls, as demonstrated by the ImexGrid and FieldList controls, aka "Access ActiveX Control Vulnerability."
4059| [CVE-2010-0812] Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allow remote attackers to bypass intended IPv4 source-address restrictions via a mismatched IPv6 source address in a tunneled ISATAP packet, aka "ISATAP IPv6 Source Address Spoofing Vulnerability."
4060| [CVE-2010-0811] Multiple unspecified vulnerabilities in the Microsoft Internet Explorer 8 Developer Tools ActiveX control in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allow remote attackers to execute arbitrary code via unknown vectors that "corrupt the system state," aka "Microsoft Internet Explorer 8 Developer Tools Vulnerability."
4061| [CVE-2010-0810] The kernel in Microsoft Windows Vista Gold, SP1, and SP2, and Windows Server 2008 Gold and SP2, does not properly handle unspecified exceptions, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Exception Handler Vulnerability."
4062| [CVE-2010-0719] An unspecified API in Microsoft Windows 2000, Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, and Windows 7 does not validate arguments, which allows local users to cause a denial of service (system crash) via a crafted application.
4063| [CVE-2010-0487] The Authenticode Signature verification functionality in cabview.dll in Cabinet File Viewer Shell Extension 5.1, 6.0, and 6.1 in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly use unspecified fields in a file digest, which allows remote attackers to execute arbitrary code via a modified cabinet (aka .CAB) file that incorrectly appears to have a valid signature, aka "Cabview Corruption Validation Vulnerability."
4064| [CVE-2010-0486] The WinVerifyTrust function in Authenticode Signature Verification 5.1, 6.0, and 6.1 in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly use unspecified fields in a file digest, which allows user-assisted remote attackers to execute arbitrary code via a modified (1) Portable Executable (PE) or (2) cabinet (aka .CAB) file that incorrectly appears to have a valid signature, aka "WinVerifyTrust Signature Validation Vulnerability."
4065| [CVE-2010-0485] The Windows kernel-mode drivers in win32k.sys in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 Gold and SP2, Windows 7, and Server 2008 R2 "do not properly validate all callback parameters when creating a new window," which allows local users to execute arbitrary code, aka "Win32k Window Creation Vulnerability."
4066| [CVE-2010-0484] The Windows kernel-mode drivers in win32k.sys in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2 "do not properly validate changes in certain kernel objects," which allows local users to execute arbitrary code via vectors related to Device Contexts (DC) and the GetDCEx function, aka "Win32k Improper Data Validation Vulnerability."
4067| [CVE-2010-0483] vbscript.dll in VBScript 5.1, 5.6, 5.7, and 5.8 in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, when Internet Explorer is used, allows user-assisted remote attackers to execute arbitrary code by referencing a (1) local pathname, (2) UNC share pathname, or (3) WebDAV server with a crafted .hlp file in the fourth argument (aka helpfile argument) to the MsgBox function, leading to code execution involving winhlp32.exe when the F1 key is pressed, aka "VBScript Help Keypress Vulnerability."
4068| [CVE-2010-0482] The kernel in Microsoft Windows Server 2008 R2 and Windows 7 does not properly validate relocation sections of image files, which allows local users to cause a denial of service (reboot) via a crafted file, aka "Windows Kernel Malformed Image Vulnerability."
4069| [CVE-2010-0481] The kernel in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly translate a registry key's virtual path to its real path, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Virtual Path Parsing Vulnerability."
4070| [CVE-2010-0480] Multiple stack-based buffer overflows in the MPEG Layer-3 audio codecs in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allow remote attackers to execute arbitrary code via a crafted AVI file, aka "MPEG Layer-3 Audio Decoder Stack Overflow Vulnerability."
4071| [CVE-2010-0479] Buffer overflow in Microsoft Office Publisher 2002 SP3, 2003 SP3, and 2007 SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Microsoft Office Publisher File Conversion TextBox Processing Buffer Overflow Vulnerability."
4072| [CVE-2010-0478] Stack-based buffer overflow in nsum.exe in the Windows Media Unicast Service in Media Services for Microsoft Windows 2000 Server SP4 allows remote attackers to execute arbitrary code via crafted packets associated with transport information, aka "Media Services Stack-based Buffer Overflow Vulnerability."
4073| [CVE-2010-0477] The SMB client in Microsoft Windows Server 2008 R2 and Windows 7 does not properly handle (1) SMBv1 and (2) SMBv2 response packets, which allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code via a crafted packet that causes the client to read the entirety of the response, and then improperly interact with the Winsock Kernel (WSK), aka "SMB Client Message Size Vulnerability."
4074| [CVE-2010-0476] The SMB client in Microsoft Windows Server 2003 SP2, Vista Gold, SP1, and SP2, and Windows Server 2008 Gold and SP2 allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and reboot) via a crafted SMB transaction response that uses (1) SMBv1 or (2) SMBv2, aka "SMB Client Response Parsing Vulnerability."
4075| [CVE-2010-0278] A certain ActiveX control in msgsc.14.0.8089.726.dll in Microsoft Windows Live Messenger 2009 build 14.0.8089.726 on Windows Vista and Windows 7 allows remote attackers to cause a denial of service (msnmsgr.exe crash) by calling the ViewProfile method with a crafted argument during an MSN Messenger session.
4076| [CVE-2010-0270] The SMB client in Microsoft Windows Server 2008 R2 and Windows 7 does not properly validate fields in SMB transaction responses, which allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and reboot) via a crafted (1) SMBv1 or (2) SMBv2 response, aka "SMB Client Transaction Vulnerability."
4077| [CVE-2010-0269] The SMB client in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly allocate memory for SMB responses, which allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code via a crafted (1) SMBv1 or (2) SMBv2 response, aka "SMB Client Memory Allocation Vulnerability."
4078| [CVE-2010-0268] Unspecified vulnerability in the Windows Media Player ActiveX control in Windows Media Player (WMP) 9 on Microsoft Windows 2000 SP4 and XP SP2 and SP3 allows remote attackers to execute arbitrary code via crafted media content, aka "Media Player Remote Code Execution Vulnerability."
4079| [CVE-2010-0266] Microsoft Office Outlook 2002 SP3, 2003 SP3, and 2007 SP1 and SP2 does not properly verify e-mail attachments with a PR_ATTACH_METHOD property value of ATTACH_BY_REFERENCE, which allows user-assisted remote attackers to execute arbitrary code via a crafted message, aka "Microsoft Outlook SMB Attachment Vulnerability."
4080| [CVE-2010-0265] Buffer overflow in Microsoft Windows Movie Maker 2.1, 2.6, and 6.0, and Microsoft Producer 2003, allows remote attackers to execute arbitrary code via a crafted project (.MSWMM) file, aka "Movie Maker and Producer Buffer Overflow Vulnerability."
4081| [CVE-2010-0264] Microsoft Office Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Microsoft Office Excel DbOrParamQry Record Parsing Vulnerability."
4082| [CVE-2010-0263] Microsoft Office Excel 2007 SP1 and SP2
4083| [CVE-2010-0262] Microsoft Office Excel 2007 SP1 and SP2 and Office 2004 for Mac do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet that triggers access of an uninitialized stack variable, aka "Microsoft Office Excel FNGROUPNAME Record Uninitialized Memory Vulnerability."
4084| [CVE-2010-0261] Heap-based buffer overflow in Microsoft Office Excel 2007 SP1 and SP2 and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted spreadsheet in which "a MDXSET record is broken up into several records," aka "Microsoft Office Excel MDXSET Record Heap Overflow Vulnerability."
4085| [CVE-2010-0260] Heap-based buffer overflow in Microsoft Office Excel 2007 SP1 and SP2
4086| [CVE-2010-0258] Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2
4087| [CVE-2010-0257] Microsoft Office Excel 2002 SP3 does not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Microsoft Office Excel Record Memory Corruption Vulnerability."
4088| [CVE-2010-0256] Microsoft Office Visio 2002 SP2, 2003 SP3, and 2007 SP1 and SP2 does not properly calculate unspecified indexes associated with Visio files, which allows remote attackers to execute arbitrary code via a crafted file, aka "Visio Index Calculation Memory Corruption Vulnerability."
4089| [CVE-2010-0254] Microsoft Office Visio 2002 SP2, 2003 SP3, and 2007 SP1 and SP2 does not properly validate attributes in Visio files, which allows remote attackers to execute arbitrary code via a crafted file, aka "Visio Attribute Validation Memory Corruption Vulnerability."
4090| [CVE-2010-0252] The Microsoft Data Analyzer ActiveX control (aka the Office Excel ActiveX control for Data Analysis) in max3activex.dll in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows remote attackers to execute arbitrary code via a crafted web page that corrupts the "system state," aka "Microsoft Data Analyzer ActiveX Control Vulnerability."
4091| [CVE-2010-0250] Heap-based buffer overflow in DirectShow in Microsoft DirectX, as used in the AVI Filter on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2, and in Quartz on Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, allows remote attackers to execute arbitrary code via an AVI file with a crafted length field in an unspecified video stream, which is not properly handled by the RLE video decompressor, aka "DirectShow Heap Overflow Vulnerability."
4092| [CVE-2010-0249] Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4
4093| [CVE-2010-0243] Buffer overflow in MSO.DLL in Microsoft Office XP SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Office document, aka "MSO.DLL Buffer Overflow."
4094| [CVE-2010-0242] The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 allows remote attackers to cause a denial of service (system hang) via crafted packets with malformed TCP selective acknowledgement (SACK) values, aka "TCP/IP Selective Acknowledgement Vulnerability."
4095| [CVE-2010-0241] The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2, when IPv6 is enabled, does not properly perform bounds checking on ICMPv6 Route Information packets, which allows remote attackers to execute arbitrary code via crafted packets, aka "ICMPv6 Route Information Vulnerability."
4096| [CVE-2010-0240] The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2, when a custom network driver is used, does not properly handle local fragmentation of Encapsulating Security Payload (ESP) over UDP packets, which allows remote attackers to execute arbitrary code via crafted packets, aka "Header MDL Fragmentation Vulnerability."
4097| [CVE-2010-0239] The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2, when IPv6 is enabled, does not properly perform bounds checking on ICMPv6 Router Advertisement packets, which allows remote attackers to execute arbitrary code via crafted packets, aka "ICMPv6 Router Advertisement Vulnerability."
4098| [CVE-2010-0238] Unspecified vulnerability in registry-key validation in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Vista Gold allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Registry Key Vulnerability."
4099| [CVE-2010-0237] The kernel in Microsoft Windows 2000 SP4 and XP SP2 and SP3 allows local users to gain privileges by creating a symbolic link from an untrusted registry hive to a trusted registry hive, aka "Windows Kernel Symbolic Link Creation Vulnerability."
4100| [CVE-2010-0236] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Vista Gold does not properly allocate memory for the destination key associated with a symbolic-link registry key, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Memory Allocation Vulnerability."
4101| [CVE-2010-0235] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Vista Gold does not perform the expected validation before creating a symbolic link, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Symbolic Link Value Vulnerability."
4102| [CVE-2010-0234] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 does not properly validate a registry-key argument to an unspecified system call, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Null Pointer Vulnerability."
4103| [CVE-2010-0233] Double free vulnerability in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows local users to gain privileges via a crafted application, aka "Windows Kernel Double Free Vulnerability."
4104| [CVE-2010-0232] The kernel in Microsoft Windows NT 3.1 through Windows 7, including Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, and Windows Server 2008 Gold and SP2, when access to 16-bit applications is enabled on a 32-bit x86 platform, does not properly validate certain BIOS calls, which allows local users to gain privileges by crafting a VDM_TIB data structure in the Thread Environment Block (TEB), and then calling the NtVdmControl function to start the Windows Virtual DOS Machine (aka NTVDM) subsystem, leading to improperly handled exceptions involving the #GP trap handler (nt!KiTrap0D), aka "Windows Kernel Exception Handler Vulnerability."
4105| [CVE-2010-0231] The SMB implementation in the Server service in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not use a sufficient source of entropy, which allows remote attackers to obtain access to files and other SMB resources via a large number of authentication requests, related to server-generated challenges, certain "duplicate values," and spoofing of an authentication token, aka "SMB NTLM Authentication Lack of Entropy Vulnerability."
4106| [CVE-2010-0035] The Key Distribution Center (KDC) in Kerberos in Microsoft Windows 2000 SP4, Server 2003 SP2, and Server 2008 Gold and SP2, when a trust relationship with a non-Windows Kerberos realm exists, allows remote authenticated users to cause a denial of service (NULL pointer dereference and domain controller outage) via a crafted Ticket Granting Ticket (TGT) renewal request, aka "Kerberos Null Pointer Dereference Vulnerability."
4107| [CVE-2010-0034] Stack-based buffer overflow in Microsoft Office PowerPoint 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "Office PowerPoint Viewer TextCharsAtom Record Stack Overflow Vulnerability."
4108| [CVE-2010-0033] Stack-based buffer overflow in Microsoft Office PowerPoint 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint Viewer TextBytesAtom Record Stack Overflow Vulnerability."
4109| [CVE-2010-0032] Use-after-free vulnerability in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "OEPlaceholderAtom Use After Free Vulnerability."
4110| [CVE-2010-0031] Array index error in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3, and PowerPoint in Office 2004 for Mac, allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint OEPlaceholderAtom 'placementId' Invalid Array Indexing Vulnerability."
4111| [CVE-2010-0030] Heap-based buffer overflow in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint LinkedSlideAtom Heap Overflow Vulnerability."
4112| [CVE-2010-0029] Buffer overflow in Microsoft Office PowerPoint 2002 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint File Path Handling Buffer Overflow Vulnerability."
4113| [CVE-2010-0028] Integer overflow in Microsoft Paint in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted JPEG (.JPG) file, aka "MS Paint Integer Overflow Vulnerability."
4114| [CVE-2010-0027] The URL validation functionality in Microsoft Internet Explorer 5.01, 6, 6 SP1, 7 and 8, and the ShellExecute API function in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, does not properly process input parameters, which allows remote attackers to execute arbitrary local programs via a crafted URL, aka "URL Validation Vulnerability."
4115| [CVE-2010-0026] The Hyper-V server implementation in Microsoft Windows Server 2008 Gold, SP2, and R2 on the x64 platform allows guest OS users to cause a denial of service (host OS hang) via a crafted application that executes a malformed series of machine instructions, aka "Hyper-V Instruction Set Validation Vulnerability."
4116| [CVE-2010-0025] The SMTP component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Server 2008 Gold, SP2, and R2, and Exchange Server 2000 SP3, does not properly allocate memory for SMTP command replies, which allows remote attackers to read fragments of e-mail messages by sending a series of invalid commands and then sending a STARTTLS command, aka "SMTP Memory Allocation Vulnerability."
4117| [CVE-2010-0024] The SMTP component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Server 2008 Gold, SP2, and R2, and Exchange Server 2003 SP2, does not properly parse MX records, which allows remote DNS servers to cause a denial of service (service outage) via a crafted response to a DNS MX record query, aka "SMTP Server MX Record Vulnerability."
4118| [CVE-2010-0023] The Client/Server Run-time Subsystem (CSRSS) in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly kill processes after a logout, which allows local users to obtain sensitive information or gain privileges via a crafted application that continues to execute throughout the logout of one user and the login session of the next user, aka "CSRSS Local Privilege Elevation Vulnerability."
4119| [CVE-2010-0022] The SMB implementation in the Server service in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate the share and servername fields in SMB packets, which allows remote attackers to cause a denial of service (system hang) via a crafted packet, aka "SMB Null Pointer Vulnerability."
4120| [CVE-2010-0021] Multiple race conditions in the SMB implementation in the Server service in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allow remote attackers to cause a denial of service (system hang) via a crafted (1) SMBv1 or (2) SMBv2 Negotiate packet, aka "SMB Memory Corruption Vulnerability."
4121| [CVE-2010-0020] The SMB implementation in the Server service in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate request fields, which allows remote authenticated users to execute arbitrary code via a malformed request, aka "SMB Pathname Overflow Vulnerability."
4122| [CVE-2010-0018] Integer overflow in the Embedded OpenType (EOT) Font Engine (t2embed.dll) in Microsoft Windows 2000 SP4
4123| [CVE-2010-0017] Race condition in the SMB client implementation in Microsoft Windows Server 2008 R2 and Windows 7 allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code, and in the SMB client implementation in Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 allows local users to gain privileges, via a crafted SMB Negotiate response, aka "SMB Client Race Condition Vulnerability."
4124| [CVE-2010-0016] The SMB client implementation in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly validate response fields, which allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code via a crafted response, aka "SMB Client Pool Corruption Vulnerability."
4125| [CVE-2009-4313] ir32_32.dll 3.24.15.3 in the Indeo32 codec in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to cause a denial of service (heap corruption) or execute arbitrary code via malformed data in a stream in a media file, as demonstrated by an AVI file.
4126| [CVE-2009-4312] Unspecified vulnerability in the Indeo codec in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via crafted media content, as reported to Microsoft by Dave Lenoe of Adobe.
4127| [CVE-2009-4311] Unspecified vulnerability in the Indeo codec in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via crafted media content, as reported to Microsoft by Paul Byrne of NGS Software. NOTE: this might overlap CVE-2008-3615.
4128| [CVE-2009-4310] Stack-based buffer overflow in the Intel Indeo41 codec for Windows Media Player in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via crafted compressed video data in an IV41 stream in a media file, leading to many loop iterations, as demonstrated by data in an AVI file.
4129| [CVE-2009-4309] Heap-based buffer overflow in the Intel Indeo41 codec for Windows Media Player in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via a large size value in a movi record in an IV41 stream in a media file, as demonstrated by an AVI file.
4130| [CVE-2009-4210] The Indeo codec in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via crafted media content.
4131| [CVE-2009-3830] The download functionality in Team Services in Microsoft Office SharePoint Server 2007 12.0.0.4518 and 12.0.0.6219 allows remote attackers to read ASP.NET source code via pathnames in the SourceUrl and Source parameters to _layouts/download.aspx.
4132| [CVE-2009-3678] Integer overflow in cdd.dll in the Canonical Display Driver (CDD) in Microsoft Windows Server 2008 R2 and Windows 7 on 64-bit platforms, when the Windows Aero theme is installed, allows context-dependent attackers to cause a denial of service (reboot) or possibly execute arbitrary code via a crafted image file that triggers incorrect data parsing after user-mode data is copied to kernel mode, as demonstrated using "Browse with Irfanview" and certain actions on a folder containing a large number of thumbnail images in Resample mode, possibly related to the ATI graphics driver or win32k.sys, aka "Canonical Display Driver Integer Overflow Vulnerability."
4133| [CVE-2009-3677] The Internet Authentication Service (IAS) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold and SP1, and Server 2008 Gold does not properly verify the credentials in an MS-CHAP v2 Protected Extensible Authentication Protocol (PEAP) authentication request, which allows remote attackers to access network resources via a malformed request, aka "MS-CHAP Authentication Bypass Vulnerability."
4134| [CVE-2009-3676] The SMB client in the kernel in Microsoft Windows Server 2008 R2 and Windows 7 allows remote SMB servers and man-in-the-middle attackers to cause a denial of service (infinite loop and system hang) via a (1) SMBv1 or (2) SMBv2 response packet that contains (a) an incorrect length value in a NetBIOS header or (b) an additional length field at the end of this response packet, aka "SMB Client Incomplete Response Vulnerability."
4135| [CVE-2009-3675] LSASS.exe in the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote authenticated users to cause a denial of service (CPU consumption) via a malformed ISAKMP request over IPsec, aka "Local Security Authority Subsystem Service Resource Exhaustion Vulnerability."
4136| [CVE-2009-3450] Multiple cross-site scripting (XSS) vulnerabilities in WebCoreModule.ashx in RADactive I-Load before 2008.2.5.0 allow remote attackers to inject arbitrary web script or HTML via parameters with names beginning with __ (underscore underscore) sequences, which are incompatible with an XSS protection mechanism provided by Microsoft ASP.NET.
4137| [CVE-2009-3135] Stack-based buffer overflow in Microsoft Office Word 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, Open XML File Format Converter for Mac, Office Word Viewer 2003 SP3, and Office Word Viewer allow remote attackers to execute arbitrary code via a Word document with a malformed File Information Block (FIB) structure, aka "Microsoft Office Word File Information Memory Corruption Vulnerability."
4138| [CVE-2009-3134] Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2
4139| [CVE-2009-3133] Microsoft Office Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code via a spreadsheet containing a malformed object that triggers memory corruption, related to "loading Excel records," aka "Excel Document Parsing Memory Corruption Vulnerability."
4140| [CVE-2009-3132] Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2
4141| [CVE-2009-3131] Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2
4142| [CVE-2009-3130] Heap-based buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via a spreadsheet containing a malformed Binary File Format (aka BIFF) record that triggers memory corruption, aka "Excel Document Parsing Heap Overflow Vulnerability."
4143| [CVE-2009-3129] Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2
4144| [CVE-2009-3128] Microsoft Office Excel 2002 SP3 and 2003 SP3, and Office Excel Viewer 2003 SP3, does not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a spreadsheet with a malformed record object, aka "Excel SxView Memory Corruption Vulnerability."
4145| [CVE-2009-3127] Microsoft Office Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, Open XML File Format Converter for Mac, and Office Excel Viewer 2003 SP3 do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel Cache Memory Corruption Vulnerability."
4146| [CVE-2009-3126] Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a crafted PNG image file, aka "GDI+ PNG Integer Overflow Vulnerability."
4147| [CVE-2009-3103] Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, and Windows 7 RC allows remote attackers to execute arbitrary code or cause a denial of service (system crash) via an & (ampersand) character in a Process ID High header field in a NEGOTIATE PROTOCOL REQUEST packet, which triggers an attempted dereference of an out-of-bounds memory location, aka "SMBv2 Negotiation Vulnerability." NOTE: some of these details are obtained from third party information.
4148| [CVE-2009-3020] win32k.sys in Microsoft Windows Server 2003 SP2 allows remote attackers to cause a denial of service (system crash) by referencing a crafted .eot file in the src descriptor of an @font-face Cascading Style Sheets (CSS) rule in an HTML document, possibly related to the Embedded OpenType (EOT) Font Engine, a different vulnerability than CVE-2006-0010, CVE-2009-0231, and CVE-2009-0232. NOTE: some of these details are obtained from third party information.
4149| [CVE-2009-2653] ** DISPUTED ** The NtUserConsoleControl function in win32k.sys in Microsoft Windows XP SP2 and SP3, and Server 2003 before SP1, allows local administrators to bypass unspecified "security software" and gain privileges via a crafted call that triggers an overwrite of an arbitrary memory location. NOTE: the vendor disputes the significance of this report, stating that 'the Administrator to SYSTEM "escalation" is not a security boundary we defend.'
4150| [CVE-2009-2532] Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, and Windows 7 RC do not properly process the command value in an SMB Multi-Protocol Negotiate Request packet, which allows remote attackers to execute arbitrary code via a crafted SMBv2 packet to the Server service, aka "SMBv2 Command Value Vulnerability."
4151| [CVE-2009-2526] Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 do not properly validate fields in SMBv2 packets, which allows remote attackers to cause a denial of service (infinite loop and system hang) via a crafted packet to the Server service, aka "SMBv2 Infinite Loop Vulnerability."
4152| [CVE-2009-2524] Integer underflow in the NTLM authentication feature in the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows remote attackers to cause a denial of service (reboot) via a malformed packet, aka "Local Security Authority Subsystem Service Integer Overflow Vulnerability."
4153| [CVE-2009-2523] The License Logging Server (llssrv.exe) in Microsoft Windows 2000 SP4 allows remote attackers to execute arbitrary code via an RPC message containing a string without a null terminator, which triggers a heap-based buffer overflow in the LlsrLicenseRequestW method, aka "License Logging Server Heap Overflow Vulnerability."
4154| [CVE-2009-2519] The DHTML Editing Component ActiveX control in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly format HTML markup, which allows remote attackers to execute arbitrary code via a crafted web site that triggers "system state" corruption, aka "DHTML Editing Component ActiveX Control Vulnerability."
4155| [CVE-2009-2517] The kernel in Microsoft Windows Server 2003 SP2 does not properly handle unspecified exceptions when an error condition occurs, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Exception Handler Vulnerability."
4156| [CVE-2009-2516] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold and SP1, and Server 2008 Gold does not properly validate data sent from user mode, which allows local users to gain privileges via a crafted PE .exe file that triggers a NULL pointer dereference during chain traversal, aka "Windows Kernel NULL Pointer Dereference Vulnerability."
4157| [CVE-2009-2515] Integer underflow in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows local users to gain privileges via a crafted application that triggers an incorrect truncation of a 64-bit integer to a 32-bit integer, aka "Windows Kernel Integer Underflow Vulnerability."
4158| [CVE-2009-2514] win32k.sys in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not correctly parse font code during construction of a directory-entry table, which allows remote attackers to execute arbitrary code via a crafted Embedded OpenType (EOT) font, aka "Win32k EOT Parsing Vulnerability."
4159| [CVE-2009-2513] The Graphics Device Interface (GDI) in win32k.sys in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Win32k Insufficient Data Validation Vulnerability."
4160| [CVE-2009-2511] Integer overflow in the CryptoAPI component in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows man-in-the-middle attackers to spoof arbitrary SSL servers and other entities via an X.509 certificate that has a malformed ASN.1 Object Identifier (OID) and was issued by a legitimate Certification Authority, aka "Integer Overflow in X.509 Object Identifiers Vulnerability."
4161| [CVE-2009-2510] The CryptoAPI component in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, as used by Internet Explorer and other applications, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, aka "Null Truncation in X.509 Common Name Vulnerability," a related issue to CVE-2009-2408.
4162| [CVE-2009-2509] Active Directory Federation Services (ADFS) in Microsoft Windows Server 2003 SP2 and Server 2008 Gold and SP2 does not properly validate headers in HTTP requests, which allows remote authenticated users to execute arbitrary code via a crafted request to an IIS web server, aka "Remote Code Execution in ADFS Vulnerability."
4163| [CVE-2009-2508] The single sign-on implementation in Active Directory Federation Services (ADFS) in Microsoft Windows Server 2003 SP2 and Server 2008 Gold and SP2 does not properly remove credentials at the end of a network session, which allows physically proximate attackers to obtain the credentials of a previous user of the same web browser by using data from the browser's cache, aka "Single Sign On Spoofing in ADFS Vulnerability."
4164| [CVE-2009-2507] A certain ActiveX control in the Indexing Service in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly process URLs, which allows remote attackers to execute arbitrary programs via unspecified vectors that cause a "vulnerable binary" to load and run, aka "Memory Corruption in Indexing Service Vulnerability."
4165| [CVE-2009-2506] Integer overflow in the text converters in Microsoft Office Word 2002 SP3 and 2003 SP3
4166| [CVE-2009-2505] The Internet Authentication Service (IAS) in Microsoft Windows Vista SP2 and Server 2008 SP2 does not properly validate MS-CHAP v2 Protected Extensible Authentication Protocol (PEAP) authentication requests, which allows remote attackers to execute arbitrary code via crafted structures in a malformed request, aka "Internet Authentication Service Memory Corruption Vulnerability."
4167| [CVE-2009-2504] Multiple integer overflows in unspecified APIs in GDI+ in Microsoft .NET Framework 1.1 SP1, .NET Framework 2.0 SP1 and SP2, Windows XP SP2 and SP3, Windows Server 2003 SP2, Vista Gold and SP1, Server 2008 Gold, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allow remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "GDI+ .NET API Vulnerability."
4168| [CVE-2009-2503] GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Windows Server 2003 SP2, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 does not properly allocate an unspecified buffer, which allows remote attackers to execute arbitrary code via a crafted TIFF image file that triggers memory corruption, aka "GDI+ TIFF Memory Corruption Vulnerability."
4169| [CVE-2009-2502] Buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a crafted TIFF image file, aka "GDI+ TIFF Buffer Overflow Vulnerability."
4170| [CVE-2009-2501] Heap-based buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a crafted PNG image file, aka "GDI+ PNG Heap Overflow Vulnerability."
4171| [CVE-2009-2500] Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a crafted WMF image file, aka "GDI+ WMF Integer Overflow Vulnerability."
4172| [CVE-2009-2498] Microsoft Windows Media Format Runtime 9.0, 9.5, and 11 and Windows Media Services 9.1 and 2008 do not properly parse malformed headers in Advanced Systems Format (ASF) files, which allows remote attackers to execute arbitrary code via a crafted (1) .asf, (2) .wmv, or (3) .wma file, aka "Windows Media Header Parsing Invalid Free Vulnerability."
4173| [CVE-2009-2497] The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0, 2.0 SP1, 2.0 SP2, 3.5, and 3.5 SP1, and Silverlight 2, does not properly handle interfaces, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP), (2) a crafted Silverlight application, (3) a crafted ASP.NET application, or (4) a crafted .NET Framework application, aka "Microsoft Silverlight and Microsoft .NET Framework CLR Vulnerability."
4174| [CVE-2009-2496] Heap-based buffer overflow in the Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2003 SP3, Office XP Web Components SP3, Office 2003 Web Components SP3, Office 2003 Web Components SP1 for the 2007 Microsoft Office System, Internet Security and Acceleration (ISA) Server 2004 SP3 and 2006 SP1, and Office Small Business Accounting 2006 allows remote attackers to execute arbitrary code via unspecified parameters to unknown methods, aka "Office Web Components Heap Corruption Vulnerability."
4175| [CVE-2009-2495] The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and 2008 Gold and SP1 does not properly enforce string termination, which allows remote attackers to obtain sensitive information via a crafted HTML document with an ATL (1) component or (2) control that triggers a buffer over-read, related to ATL headers and buffer allocation, aka "ATL Null String Vulnerability."
4176| [CVE-2009-2494] The Active Template Library (ATL) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via vectors related to erroneous free operations after reading a variant from a stream and deleting this variant, aka "ATL Object Type Mismatch Vulnerability."
4177| [CVE-2009-2493] The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and 2008 Gold and SP1
4178| [CVE-2009-1930] The Telnet service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote Telnet servers to execute arbitrary code on a client machine by replaying the NTLM credentials of a client user, aka "Telnet Credential Reflection Vulnerability," a related issue to CVE-2000-0834.
4179| [CVE-2009-1929] Heap-based buffer overflow in the Microsoft Terminal Services Client ActiveX control running RDP 6.1 on Windows XP SP2, Vista SP1 or SP2, or Server 2008 Gold or SP2
4180| [CVE-2009-1928] Stack consumption vulnerability in the LDAP service in Active Directory on Microsoft Windows 2000 SP4, Server 2003 SP2, and Server 2008 Gold and SP2
4181| [CVE-2009-1926] Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allow remote attackers to cause a denial of service (TCP outage) via a series of TCP sessions that have pending data and a (1) small or (2) zero receive window size, and remain in the FIN-WAIT-1 or FIN-WAIT-2 state indefinitely, aka "TCP/IP Orphaned Connections Vulnerability."
4182| [CVE-2009-1925] The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 does not properly manage state information, which allows remote attackers to execute arbitrary code by sending packets to a listening service, and thereby triggering misinterpretation of an unspecified field as a function pointer, aka "TCP/IP Timestamps Code Execution Vulnerability."
4183| [CVE-2009-1924] Integer overflow in the Windows Internet Name Service (WINS) component for Microsoft Windows 2000 SP4 allows remote WINS replication partners to execute arbitrary code via crafted data structures in a packet, aka "WINS Integer Overflow Vulnerability."
4184| [CVE-2009-1923] Heap-based buffer overflow in the Windows Internet Name Service (WINS) component for Microsoft Windows 2000 SP4 and Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted WINS replication packet that triggers an incorrect buffer-length calculation, aka "WINS Heap Overflow Vulnerability."
4185| [CVE-2009-1922] The Message Queuing (aka MSMQ) service for Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP2, and Vista Gold does not properly validate unspecified IOCTL request data from user mode before passing this data to kernel mode, which allows local users to gain privileges via a crafted request, aka "MSMQ Null Pointer Vulnerability."
4186| [CVE-2009-1546] Integer overflow in Avifil32.dll in the Windows Media file handling functionality in Microsoft Windows allows remote attackers to execute arbitrary code on a Windows 2000 SP4 system via a crafted AVI file, or cause a denial of service on a Windows XP SP2 or SP3, Server 2003 SP2, Vista Gold, SP1, or SP2, or Server 2008 Gold or SP2 system via a crafted AVI file, aka "AVI Integer Overflow Vulnerability."
4187| [CVE-2009-1545] Unspecified vulnerability in Avifil32.dll in the Windows Media file handling functionality in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a malformed header in a crafted AVI file, aka "Malformed AVI Header Vulnerability."
4188| [CVE-2009-1544] Double free vulnerability in the Workstation service in Microsoft Windows allows remote authenticated users to gain privileges via a crafted RPC message to a Windows XP SP2 or SP3 or Server 2003 SP2 system, or cause a denial of service via a crafted RPC message to a Vista Gold, SP1, or SP2 or Server 2008 Gold or SP2 system, aka "Workstation Service Memory Corruption Vulnerability."
4189| [CVE-2009-1542] The Virtual Machine Monitor (VMM) in Microsoft Virtual PC 2004 SP1, 2007, and 2007 SP1, and Microsoft Virtual Server 2005 R2 SP1, does not enforce CPU privilege-level requirements for all machine instructions, which allows guest OS users to execute arbitrary kernel-mode code and gain privileges within the guest OS via a crafted application, aka "Virtual PC and Virtual Server Privileged Instruction Decoding Vulnerability."
4190| [CVE-2009-1539] The QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2 does not properly validate unspecified size fields in QuickTime media files, which allows remote attackers to execute arbitrary code via a crafted file, aka "DirectX Size Validation Vulnerability."
4191| [CVE-2009-1538] The QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2 performs updates to pointers without properly validating unspecified data values, which allows remote attackers to execute arbitrary code via a crafted QuickTime media file, aka "DirectX Pointer Validation Vulnerability."
4192| [CVE-2009-1537] Unspecified vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted QuickTime media file, as exploited in the wild in May 2009, aka "DirectX NULL Byte Overwrite Vulnerability."
4193| [CVE-2009-1536] ASP.NET in Microsoft .NET Framework 2.0 SP1 and SP2 and 3.5 Gold and SP1, when ASP 2.0 is used in integrated mode on IIS 7.0, does not properly manage request scheduling, which allows remote attackers to cause a denial of service (daemon outage) via a series of crafted HTTP requests, aka "Remote Unauthenticated Denial of Service in ASP.NET Vulnerability."
4194| [CVE-2009-1534] Buffer overflow in the Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2000 Web Components SP3, Office XP Web Components SP3, BizTalk Server 2002, and Visual Studio .NET 2003 SP1 allows remote attackers to execute arbitrary code via crafted property values, aka "Office Web Components Buffer Overflow Vulnerability."
4195| [CVE-2009-1533] Buffer overflow in the Works for Windows document converters in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, Office 2007 SP1, and Works 8.5 and 9 allows remote attackers to execute arbitrary code via a crafted Works .wps file that triggers memory corruption, aka "File Converter Buffer Overflow Vulnerability."
4196| [CVE-2009-1491] McAfee GroupShield for Microsoft Exchange on Exchange Server 2000, and possibly other anti-virus or anti-spam products from McAfee or other vendors, does not scan X- headers for malicious content, which allows remote attackers to bypass virus detection via a crafted message, as demonstrated by a message with an X-Testing header and no message body.
4197| [CVE-2009-1216] Multiple unspecified vulnerabilities in (1) unlzh.c and (2) unpack.c in the gzip libraries in Microsoft Windows Server 2008, Windows Services for UNIX 3.0 and 3.5, and the Subsystem for UNIX-based Applications (SUA)
4198| [CVE-2009-1141] Microsoft Internet Explorer 6 for Windows XP SP2 and SP3 and Server 2003 SP2 allows remote attackers to execute arbitrary code via unspecified DHTML function calls related to a tr element and the "insertion, deletion and attributes of a table cell," which trigger memory corruption when the window is destroyed, aka "DHTML Object Memory Corruption Vulnerability."
4199| [CVE-2009-1139] Memory leak in the LDAP service in Active Directory on Microsoft Windows 2000 SP4 and Server 2003 SP2, and Active Directory Application Mode (ADAM) on Windows XP SP2 and SP3 and Server 2003 SP2, allows remote attackers to cause a denial of service (memory consumption and service outage) via (1) LDAP or (2) LDAPS requests with unspecified OID filters, aka "Active Directory Memory Leak Vulnerability."
4200| [CVE-2009-1138] The LDAP service in Active Directory on Microsoft Windows 2000 SP4 does not properly free memory for LDAP and LDAPS requests, which allows remote attackers to execute arbitrary code via a request that uses hexadecimal encoding, whose associated memory is not released, related to a "DN AttributeValue," aka "Active Directory Invalid Free Vulnerability." NOTE: this issue is probably a memory leak.
4201| [CVE-2009-1137] Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that uses a PowerPoint 4.0 native file format, leading to memory corruption, aka "Legacy File Format Vulnerability," a different vulnerability than CVE-2009-0222, CVE-2009-0223, CVE-2009-0226, and CVE-2009-0227.
4202| [CVE-2009-1136] The Microsoft Office Web Components Spreadsheet ActiveX control (aka OWC10 or OWC11), as distributed in Office XP SP3 and Office 2003 SP3, Office XP Web Components SP3, Office 2003 Web Components SP3, Office 2003 Web Components SP1 for the 2007 Microsoft Office System, Internet Security and Acceleration (ISA) Server 2004 SP3 and 2006 Gold and SP1, and Office Small Business Accounting 2006, when used in Internet Explorer, allows remote attackers to execute arbitrary code via a crafted call to the msDataSourceObject method, as exploited in the wild in July and August 2009, aka "Office Web Components HTML Script Vulnerability."
4203| [CVE-2009-1135] Microsoft Internet Security and Acceleration (ISA) Server 2006 Gold and SP1, when Radius OTP is enabled, uses the HTTP-Basic authentication method, which allows remote attackers to gain the privileges of an arbitrary account, and access published web pages, via vectors involving attempted access to a network resource behind the ISA Server, aka "Radius OTP Bypass Vulnerability."
4204| [CVE-2009-1134] Excel in 2007 Microsoft Office System SP1 and SP2
4205| [CVE-2009-1133] Heap-based buffer overflow in Microsoft Remote Desktop Connection (formerly Terminal Services Client) running RDP 5.0 through 6.1 on Windows, and Remote Desktop Connection Client for Mac 2.0, allows remote attackers to execute arbitrary code via unspecified parameters, aka "Remote Desktop Connection Heap Overflow Vulnerability."
4206| [CVE-2009-1132] Heap-based buffer overflow in the Wireless LAN AutoConfig Service (aka Wlansvc) in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a malformed wireless frame, aka "Wireless Frame Parsing Remote Code Execution Vulnerability."
4207| [CVE-2009-1131] Multiple stack-based buffer overflows in Microsoft Office PowerPoint 2000 SP3 allow remote attackers to execute arbitrary code via a large amount of data associated with unspecified atoms in a PowerPoint file that triggers memory corruption, aka "Data Out of Bounds Vulnerability."
4208| [CVE-2009-1130] Heap-based buffer overflow in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac, allows remote attackers to execute arbitrary code via a crafted structure in a Notes container in a PowerPoint file that causes PowerPoint to read more data than was allocated when creating a C++ object, leading to an overwrite of a function pointer, aka "Heap Corruption Vulnerability."
4209| [CVE-2009-1129] Multiple stack-based buffer overflows in the PowerPoint 95 importer (PP7X32.DLL) in Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allow remote attackers to execute arbitrary code via an inconsistent record length in sound data in a file that uses a PowerPoint 95 (PPT95) native file format, aka "PP7 Memory Corruption Vulnerability," a different vulnerability than CVE-2009-1128.
4210| [CVE-2009-1128] Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that uses a PowerPoint 95 native file format, leading to memory corruption, aka "PP7 Memory Corruption Vulnerability," a different vulnerability than CVE-2009-1129.
4211| [CVE-2009-1127] win32k.sys in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 does not correctly validate an argument to an unspecified system call, which allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, aka "Win32k NULL Pointer Dereferencing Vulnerability."
4212| [CVE-2009-1126] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly validate the user-mode input associated with the editing of an unspecified desktop parameter, which allows local users to gain privileges via a crafted application, aka "Windows Desktop Parameter Edit Vulnerability."
4213| [CVE-2009-1125] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate an argument to an unspecified system call, which allows local users to gain privileges via a crafted application, aka "Windows Driver Class Registration Vulnerability."
4214| [CVE-2009-1124] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate user-mode pointers in unspecified error conditions, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Pointer Validation Vulnerability."
4215| [CVE-2009-1123] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate changes to unspecified kernel objects, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Desktop Vulnerability."
4216| [CVE-2009-1122] The WebDAV extension in Microsoft Internet Information Services (IIS) 5.0 on Windows 2000 SP4 does not properly decode URLs, which allows remote attackers to bypass authentication, and possibly read or create files, via a crafted HTTP request, aka "IIS 5.0 WebDAV Authentication Bypass Vulnerability," a different vulnerability than CVE-2009-1535.
4217| [CVE-2009-1043] Unspecified vulnerability in Microsoft Internet Explorer 8 on Windows 7 allows remote attackers to execute arbitrary code via unknown vectors triggered by clicking on a link, as demonstrated by Nils during a PWN2OWN competition at CanSecWest 2009.
4218| [CVE-2009-1011] Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.2.2 and 8.3.0 allows local users to affect confidentiality, integrity, and availability, related to HTML. NOTE: the previous information was obtained from the April 2009 CPU. Oracle has not commented on reliable researcher claims that this issue is for multiple integer overflows in a function that parses an optional data stream within a Microsoft Office file, leading to a heap-based buffer overflow.
4219| [CVE-2009-0901] The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold, and Visual C++ 2005 SP1 and 2008 Gold and SP1
4220| [CVE-2009-0568] The RPC Marshalling Engine (aka NDR) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly maintain its internal state, which allows remote attackers to overwrite arbitrary memory locations via a crafted RPC message that triggers incorrect pointer reading, related to "IDL interfaces containing a non-conformant varying array" and FC_SMVARRAY, FC_LGVARRAY, FC_VARIABLE_REPEAT, and FC_VARIABLE_OFFSET, aka "RPC Marshalling Engine Vulnerability."
4221| [CVE-2009-0566] Microsoft Office Publisher 2007 SP1 does not properly calculate object handler data for Publisher files, which allows remote attackers to execute arbitrary code via a crafted file in a legacy format that triggers memory corruption, aka "Pointer Dereference Vulnerability."
4222| [CVE-2009-0565] Buffer overflow in Microsoft Office Word 2000 SP3, 2002 SP3, and 2007 SP1 and SP2
4223| [CVE-2009-0563] Stack-based buffer overflow in Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP1 and SP2
4224| [CVE-2009-0562] The Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2003 SP3, Office XP Web Components SP3, Office 2003 Web Components SP3, Office 2003 Web Components SP1 for the 2007 Microsoft Office System, Internet Security and Acceleration (ISA) Server 2004 SP3 and 2006 SP1, and Office Small Business Accounting 2006 does not properly allocate memory, which allows remote attackers to execute arbitrary code via unspecified vectors that trigger "system state" corruption, aka "Office Web Components Memory Allocation Vulnerability."
4225| [CVE-2009-0561] Integer overflow in Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac
4226| [CVE-2009-0560] Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac
4227| [CVE-2009-0559] Stack-based buffer overflow in Excel in Microsoft Office 2000 SP3 and Office XP SP3 allows remote attackers to execute arbitrary code via a crafted Excel file with a malformed record object, aka "String Copy Stack-Based Overrun Vulnerability."
4228| [CVE-2009-0558] Array index error in Excel in Microsoft Office 2000 SP3 and Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac, allows remote attackers to execute arbitrary code via a crafted Excel file with a malformed record object, aka "Array Indexing Memory Corruption Vulnerability."
4229| [CVE-2009-0557] Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac
4230| [CVE-2009-0556] Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac, allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineTextRefAtom containing an an invalid index value that triggers memory corruption, as exploited in the wild in April 2009 by Exploit:Win32/Apptom.gen, aka "Memory Corruption Vulnerability."
4231| [CVE-2009-0554] Microsoft Internet Explorer 5.01 SP4, 6 SP1, 6 and 7 on Windows XP SP2 and SP3, 6 and 7 on Windows Server 2003 SP1 and SP2, 7 on Windows Vista Gold and SP1, and 7 on Windows Server 2008 allows remote attackers to execute arbitrary code via a web page that triggers presence of an object in memory that was (1) not properly initialized or (2) deleted, aka "Uninitialized Memory Corruption Vulnerability."
4232| [CVE-2009-0553] Microsoft Internet Explorer 6 SP1, 6 and 7 on Windows XP SP2 and SP3, 6 and 7 on Windows Server 2003 SP1 and SP2, 7 on Windows Vista Gold and SP1, and 7 on Windows Server 2008 allows remote attackers to execute arbitrary code via a web page that triggers presence of an object in memory that was (1) not properly initialized or (2) deleted, aka "Uninitialized Memory Corruption Vulnerability."
4233| [CVE-2009-0552] Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4, 6 SP1, 6 on Windows XP SP2 and SP3, and 6 on Windows Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via a web page that triggers presence of an object in memory that was (1) not properly initialized or (2) deleted, aka "Uninitialized Memory Corruption Vulnerability."
4234| [CVE-2009-0551] Microsoft Internet Explorer 6 SP1, 6 and 7 on Windows XP SP2 and SP3, 6 and 7 on Windows Server 2003 SP1 and SP2, 7 on Windows Vista Gold and SP1, and 7 on Windows Server 2008 does not properly handle transition errors in a request for one HTTP document followed by a request for a second HTTP document, which allows remote attackers to execute arbitrary code via vectors involving (1) multiple crafted pages on a web site or (2) a web page with crafted inline content such as banner advertisements, aka "Page Transition Memory Corruption Vulnerability."
4235| [CVE-2009-0550] Windows HTTP Services (aka WinHTTP) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008
4236| [CVE-2009-0549] Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac
4237| [CVE-2009-0320] Microsoft Windows XP, Server 2003 and 2008, and Vista exposes I/O activity measurements of all processes, which allows local users to obtain sensitive information, as demonstrated by reading the I/O Other Bytes column in Task Manager (aka taskmgr.exe) to estimate the number of characters that a different user entered at a runas.exe password prompt, related to a "benchmarking attack."
4238| [CVE-2009-0239] Cross-site scripting (XSS) vulnerability in Windows Search 4.0 for Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows user-assisted remote attackers to inject arbitrary web script or HTML via a crafted file that appears in a preview in a search result, aka "Script Execution in Windows Search Vulnerability."
4239| [CVE-2009-0238] Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1
4240| [CVE-2009-0235] Stack-based buffer overflow in the Word 97 text converter in WordPad in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted Word 97 file that triggers memory corruption, related to use of inconsistent integer data sizes for an unspecified length field, aka "WordPad Word 97 Text Converter Stack Overflow Vulnerability."
4241| [CVE-2009-0234] The DNS Resolver Cache Service (aka DNSCache) in Windows DNS Server in Microsoft Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008 does not properly cache crafted DNS responses, which makes it easier for remote attackers to predict transaction IDs and poison caches by sending many crafted DNS queries that trigger "unnecessary lookups," aka "DNS Server Response Validation Vulnerability."
4242| [CVE-2009-0233] The DNS Resolver Cache Service (aka DNSCache) in Windows DNS Server in Microsoft Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008, when dynamic updates are enabled, does not reuse cached DNS responses in all applicable situations, which makes it easier for remote attackers to predict transaction IDs and poison caches by simultaneously sending crafted DNS queries and responses, aka "DNS Server Query Validation Vulnerability."
4243| [CVE-2009-0232] Integer overflow in the Embedded OpenType (EOT) Font Engine in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a crafted name table, aka "Embedded OpenType Font Integer Overflow Vulnerability."
4244| [CVE-2009-0231] The Embedded OpenType (EOT) Font Engine (T2EMBED.DLL) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a crafted name table in a data record that triggers an integer truncation and a heap-based buffer overflow, aka "Embedded OpenType Font Heap Overflow Vulnerability."
4245| [CVE-2009-0230] The Windows Print Spooler in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 allows remote authenticated users to gain privileges via a crafted RPC message that triggers loading of a DLL file from an arbitrary directory, aka "Print Spooler Load Library Vulnerability."
4246| [CVE-2009-0229] The Windows Printing Service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 allows local users to read arbitrary files via a crafted separator page, aka "Print Spooler Read File Vulnerability."
4247| [CVE-2009-0228] Stack-based buffer overflow in the EnumeratePrintShares function in Windows Print Spooler Service (win32spl.dll) in Microsoft Windows 2000 SP4 allows remote printer servers to execute arbitrary code via a a crafted ShareName in a response to an RPC request, related to "printing data structures," aka "Buffer Overflow in Print Spooler Vulnerability."
4248| [CVE-2009-0227] Stack-based buffer overflow in the PowerPoint 4.2 conversion filter (PP4X32.DLL) in Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via a large number of structures in sound data in a file that uses a PowerPoint 4.0 native file format, leading to memory corruption, aka "Legacy File Format Vulnerability," a different vulnerability than CVE-2009-0222, CVE-2009-0223, CVE-2009-0226, and CVE-2009-1137.
4249| [CVE-2009-0226] Stack-based buffer overflow in the PowerPoint 4.2 conversion filter in Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via a long string in sound data in a file that uses a PowerPoint 4.0 native file format, leading to memory corruption, aka "Legacy File Format Vulnerability," a different vulnerability than CVE-2009-0222, CVE-2009-0223, CVE-2009-0227, and CVE-2009-1137.
4250| [CVE-2009-0225] Microsoft Office PowerPoint 2002 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that uses a PowerPoint 95 native file format, leading to improper "array indexing" and memory corruption, aka "PP7 Memory Corruption Vulnerability."
4251| [CVE-2009-0224] Microsoft Office PowerPoint 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1 and SP2
4252| [CVE-2009-0223] Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that uses a PowerPoint 4.0 native file format, leading to memory corruption, aka "Legacy File Format Vulnerability," a different vulnerability than CVE-2009-0222, CVE-2009-0226, CVE-2009-0227, and CVE-2009-1137.
4253| [CVE-2009-0222] Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that uses a PowerPoint 4.0 native file format, leading to a "pointer overwrite" and memory corruption, aka "Legacy File Format Vulnerability," a different vulnerability than CVE-2009-0223, CVE-2009-0226, CVE-2009-0227, and CVE-2009-1137.
4254| [CVE-2009-0221] Integer overflow in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a PowerPoint file containing a crafted record type for "collaboration information for different slides" that contains a field that specifies a large number of records, which triggers an under-allocated buffer and a heap-based buffer overflow, aka "Integer Overflow Vulnerability."
4255| [CVE-2009-0220] Multiple stack-based buffer overflows in the PowerPoint 4.0 importer (PP4X32.DLL) in Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allow remote attackers to execute arbitrary code via crafted formatting data for paragraphs in a file that uses a PowerPoint 4.0 native file format, related to (1) an incorrect calculation from a record header, or (2) an interget that is used to specify the number of bytes to copy, aka "Legacy File Format Vulnerability."
4256| [CVE-2009-0202] Array index error in FL21WIN.DLL in the PowerPoint Freelance Windows 2.1 Translator in Microsoft PowerPoint 2000 and 2002 allows remote attackers to execute arbitrary code via a Freelance file with unspecified "layout information" that triggers a heap-based buffer overflow.
4257| [CVE-2009-0102] Microsoft Project 2000 SR1 and 2002 SP1, and Office Project 2003 SP3, does not properly handle memory allocation for Project files, which allows remote attackers to execute arbitrary code via a malformed file, aka "Project Memory Validation Vulnerability."
4258| [CVE-2009-0100] Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1
4259| [CVE-2009-0099] The Electronic Messaging System Microsoft Data Base (EMSMDB32) provider in Microsoft Exchange 2000 Server SP3 and Exchange Server 2003 SP2, as used in Exchange System Attendant, allows remote attackers to cause a denial of service (application outage) via a malformed MAPI command, aka "Literal Processing Vulnerability."
4260| [CVE-2009-0098] Microsoft Exchange 2000 Server SP3, Exchange Server 2003 SP2, and Exchange Server 2007 SP1 do not properly interpret Transport Neutral Encapsulation (TNEF) properties, which allows remote attackers to execute arbitrary code via a crafted TNEF message, aka "Memory Corruption Vulnerability."
4261| [CVE-2009-0097] Microsoft Office Visio 2002 SP2 and 2003 SP3 does not properly validate memory allocation for Visio files, which allows remote attackers to execute arbitrary code via a crafted file, aka "Memory Corruption Vulnerability."
4262| [CVE-2009-0096] Microsoft Office Visio 2002 SP2, 2003 SP3, and 2007 SP1 does not properly perform memory copy operations for object data, which allows remote attackers to execute arbitrary code via a crafted Visio document, aka "Memory Corruption Vulnerability."
4263| [CVE-2009-0095] Microsoft Office Visio 2002 SP2, 2003 SP3, and 2007 SP1 does not properly validate object data in Visio files, which allows remote attackers to execute arbitrary code via a crafted file, aka "Memory Validation Vulnerability."
4264| [CVE-2009-0094] The WINS server in Microsoft Windows 2000 SP4 and Server 2003 SP1 and SP2 does not restrict registration of the (1) "wpad" and (2) "isatap" NetBIOS names, which allows remote authenticated users to hijack the Web Proxy Auto-Discovery (WPAD) and Intra-Site Automatic Tunnel Addressing Protocol (ISATAP) features, and conduct man-in-the-middle attacks by spoofing a proxy server or ISATAP route, by registering one of these names in the WINS database, aka "WPAD WINS Server Registration Vulnerability," a related issue to CVE-2007-1692.
4265| [CVE-2009-0093] Windows DNS Server in Microsoft Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008, when dynamic updates are enabled, does not restrict registration of the "wpad" hostname, which allows remote authenticated users to hijack the Web Proxy Auto-Discovery (WPAD) feature, and conduct man-in-the-middle attacks by spoofing a proxy server, via a Dynamic Update request for this hostname, aka "DNS Server Vulnerability in WPAD Registration Vulnerability," a related issue to CVE-2007-1692.
4266| [CVE-2009-0091] Microsoft .NET Framework 2.0, 2.0 SP1, and 3.5 does not properly enforce a certain type-equality constraint in .NET verifiable code, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "Microsoft .NET Framework Type Verification Vulnerability."
4267| [CVE-2009-0090] Microsoft .NET Framework 1.0 SP3, 1.1 SP1, and 2.0 SP1 does not properly validate .NET verifiable code, which allows remote attackers to obtain unintended access to stack memory, and execute arbitrary code, via (1) a crafted XAML browser application (XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "Microsoft .NET Framework Pointer Verification Vulnerability."
4268| [CVE-2009-0089] Windows HTTP Services (aka WinHTTP) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, and Vista Gold allows remote web servers to impersonate arbitrary https web sites by using DNS spoofing to "forward a connection" to a different https web site that has a valid certificate matching its own domain name, but not a certificate matching the domain name of the host requested by the user, aka "Windows HTTP Services Certificate Name Mismatch Vulnerability."
4269| [CVE-2009-0088] The WordPerfect 6.x Converter (WPFT632.CNV, 1998.1.27.0) in Microsoft Office Word 2000 SP3 and Microsoft Office Converter Pack does not properly validate the length of an unspecified string, which allows remote attackers to execute arbitrary code via a crafted WordPerfect 6.x file, related to an unspecified counter and control structures on the stack, aka "Word 2000 WordPerfect 6.x Converter Stack Corruption Vulnerability."
4270| [CVE-2009-0087] Unspecified vulnerability in the Word 6 text converter in WordPad in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2
4271| [CVE-2009-0086] Integer underflow in Windows HTTP Services (aka WinHTTP) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote HTTP servers to execute arbitrary code via crafted parameter values in a response, related to error handling, aka "Windows HTTP Services Integer Underflow Vulnerability."
4272| [CVE-2009-0085] The Secure Channel (aka SChannel) authentication component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008, when certificate authentication is used, does not properly validate the client's key exchange data in Transport Layer Security (TLS) handshake messages, which allows remote attackers to spoof authentication by crafting a TLS packet based on knowledge of the certificate but not the private key, aka "SChannel Spoofing Vulnerability."
4273| [CVE-2009-0083] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 does not properly handle invalid pointers, which allows local users to gain privileges via an application that triggers use of a crafted pointer, aka "Windows Kernel Invalid Pointer Vulnerability."
4274| [CVE-2009-0082] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate handles, which allows local users to gain privileges via a crafted application that triggers unspecified "actions," aka "Windows Kernel Handle Validation Vulnerability."
4275| [CVE-2009-0081] The graphics device interface (GDI) implementation in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate input received from user mode, which allows remote attackers to execute arbitrary code via a crafted (1) Windows Metafile (aka WMF) or (2) Enhanced Metafile (aka EMF) image file, aka "Windows Kernel Input Validation Vulnerability."
4276| [CVE-2009-0079] The RPCSS service in Microsoft Windows XP SP2 and SP3 and Server 2003 SP1 and SP2 does not properly implement isolation among a set of distinct processes that (1) all run under the NetworkService account or (2) all run under the LocalService account, which allows local users to gain privileges by accessing the resources of one of the processes, aka "Windows RPCSS Service Isolation Vulnerability."
4277| [CVE-2009-0078] The Windows Management Instrumentation (WMI) provider in Microsoft Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly implement isolation among a set of distinct processes that (1) all run under the NetworkService account or (2) all run under the LocalService account, which allows local users to gain privileges by accessing the resources of one of the processes, aka "Windows WMI Service Isolation Vulnerability."
4278| [CVE-2008-7217] Microsoft Office 2008 for Mac, when running on Macintosh systems that restrict Office access to administrators, does not enforce this restriction for user ID 502, which allows local users with that ID to bypass intended security policy and access Office programs, related to permissions and ownership for certain directories.
4279| [CVE-2008-6819] win32k.sys in Microsoft Windows Server 2003 and Vista allows local users to cause a denial of service (system crash) via vectors related to CreateWindow, TranslateMessage, and DispatchMessage, possibly a race condition between threads, a different vulnerability than CVE-2008-1084. NOTE: some of these details are obtained from third party information.
4280| [CVE-2008-6219] nsrexecd.exe in multiple EMC Networker products including EMC NetWorker Server, Storage Node, and Client 7.3.x and 7.4, 7.4.1, 7.4.2, Client and Storage Node for Open VMS 7.3.2 ECO6 and earlier, Module for Microsoft Exchange 5.1 and earlier, Module for Microsoft Applications 2.0 and earlier, Module for Meditech 2.0 and earlier, and PowerSnap 2.4 SP1 and earlier does not properly control the allocation of memory, which allows remote attackers to cause a denial of service (memory exhaustion) via multiple crafted RPC requests.
4281| [CVE-2008-6063] Microsoft Word 2007, when the "Save as PDF" add-on is enabled, places an absolute pathname in the Subject field during an "Email as PDF" operation, which allows remote attackers to obtain sensitive information such as the sender's account name and a Temporary Internet Files subdirectory name.
4282| [CVE-2008-5912] An unspecified function in the JavaScript implementation in Microsoft Internet Explorer creates and exposes a "temporary footprint" when there is a current login to a web site, which makes it easier for remote attackers to trick a user into acting upon a spoofed pop-up message, aka an "in-session phishing attack." NOTE: as of 20090116, the only disclosure is a vague pre-advisory with no actionable information. However, because it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.
4283| [CVE-2008-5823] An ActiveX control in prtstb06.dll in Microsoft Money 2006, when used with WScript in Windows Script Host (WSH) on Windows Vista, allows remote attackers to cause a denial of service (access violation and application crash) via a zero value for the Startup property.
4284| [CVE-2008-5416] Heap-based buffer overflow in Microsoft SQL Server 2000 SP4, 8.00.2050, 8.00.2039, and earlier
4285| [CVE-2008-5232] Buffer overflow in the CallHTMLHelp method in the Microsoft Windows Media Services ActiveX control in nskey.dll 4.1.00.3917 in Windows Media Services on Microsoft Windows NT and 2000, and Avaya Media and Message Application servers, allows remote attackers to execute arbitrary code via a long argument. NOTE: the provenance of this information is unknown
4286| [CVE-2008-5112] The LDAP server in Active Directory in Microsoft Windows 2000 SP4 and Server 2003 SP1 and SP2 responds differently to a failed bind attempt depending on whether the user account exists and is permitted to login, which allows remote attackers to enumerate valid usernames via a series of LDAP bind requests, as demonstrated by ldapuserenum.
4287| [CVE-2008-5100] The strong name (SN) implementation in Microsoft .NET Framework 2.0.50727 relies on the digital signature Public Key Token embedded in the pathname of a DLL file instead of the digital signature of this file itself, which makes it easier for attackers to bypass Global Assembly Cache (GAC) and Code Access Security (CAS) protection mechanisms, aka MSRC ticket MSRC8566gs.
4288| [CVE-2008-5044] Race condition in Microsoft Windows Server 2003 and Vista allows local users to cause a denial of service (crash or hang) via a multi-threaded application that makes many calls to UnhookWindowsHookEx while certain other desktop activity is occurring.
4289| [CVE-2008-4844] Use-after-free vulnerability in the CRecordInstance::TransferToDestination function in mshtml.dll in Microsoft Internet Explorer 5.01, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via DSO bindings involving (1) an XML Island, (2) XML DSOs, or (3) Tabular Data Control (TDC) in a crafted HTML or XML document, as demonstrated by nested SPAN or MARQUEE elements, and exploited in the wild in December 2008.
4290| [CVE-2008-4841] The WordPad Text Converter for Word 97 files in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted (1) .doc, (2) .wri, or (3) .rtf Word 97 file that triggers memory corruption, as exploited in the wild in December 2008. NOTE: As of 20081210, it is unclear whether this vulnerability is related to a WordPad issue disclosed on 20080925 with a 2008-crash.doc.rar example, but there are insufficient details to be sure.
4291| [CVE-2008-4837] Stack-based buffer overflow in Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1
4292| [CVE-2008-4835] SMB in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to execute arbitrary code via malformed values of unspecified "fields inside the SMB packets" in an NT Trans2 request, related to "insufficiently validating the buffer size," aka "SMB Validation Remote Code Execution Vulnerability."
4293| [CVE-2008-4834] Buffer overflow in SMB in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via malformed values of unspecified "fields inside the SMB packets" in an NT Trans request, aka "SMB Buffer Overflow Remote Code Execution Vulnerability."
4294| [CVE-2008-4493] Microsoft PicturePusher ActiveX control (PipPPush.DLL 7.00.0709), as used in Microsoft Digital Image 2006 Starter Edition, allows remote attackers to force the upload of arbitrary files by using the AddString and Post methods and a modified PostURL to construct an HTTP POST request. NOTE: this issue might only be exploitable in limited environments or non-default browser settings.
4295| [CVE-2008-4295] Microsoft Windows Mobile 6.0 on HTC Wiza 200 and HTC MDA 8125 devices does not properly handle the first attempt to establish a Bluetooth connection to a peer with a long name, which allows remote attackers to cause a denial of service (device reboot) by configuring a Bluetooth device with a long hci name and (1) connecting directly to the Windows Mobile system or (2) waiting for the Windows Mobile system to scan for nearby devices.
4296| [CVE-2008-4269] The search-ms protocol handler in Windows Explorer in Microsoft Windows Vista Gold and SP1 and Server 2008 uses untrusted parameter data obtained from incorrect parsing, which allows remote attackers to execute arbitrary code via a crafted HTML document, aka "Windows Search Parsing Vulnerability."
4297| [CVE-2008-4268] The Windows Search component in Microsoft Windows Vista Gold and SP1 and Server 2008 does not properly free memory during a save operation for a Windows Search file, which allows remote attackers to execute arbitrary code via a crafted saved-search file, aka "Windows Saved Search Vulnerability."
4298| [CVE-2008-4266] Array index vulnerability in Microsoft Office Excel 2000 SP3, 2002 SP3, and 2003 SP3
4299| [CVE-2008-4265] Microsoft Office Excel 2000 SP3 allows remote attackers to execute arbitrary code via a crafted Excel spreadsheet that contains a malformed object, which triggers memory corruption during the loading of records from this spreadsheet, aka "File Format Parsing Vulnerability."
4300| [CVE-2008-4264] Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1
4301| [CVE-2008-4261] Stack-based buffer overflow in Microsoft Internet Explorer 5.01 SP4, 6 SP1 on Windows 2000, and 6 on Windows XP and Server 2003 does not properly handle extraneous data associated with an object embedded in a web page, which allows remote attackers to execute arbitrary code via crafted HTML tags that trigger memory corruption, aka "HTML Rendering Memory Corruption Vulnerability."
4302| [CVE-2008-4256] The Charts ActiveX control in Microsoft Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2 does not properly handle errors during access to incorrectly initialized objects, which allows remote attackers to execute arbitrary code via a crafted HTML document, related to corruption of the "system state," aka "Charts Control Memory Corruption Vulnerability."
4303| [CVE-2008-4255] Heap-based buffer overflow in mscomct2.ocx (aka Windows Common ActiveX control or Microsoft Animation ActiveX control) in Microsoft Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2, and Office Project 2003 SP3 and 2007 Gold and SP1 allows remote attackers to execute arbitrary code via an AVI file with a crafted stream length, which triggers an "allocation error" and memory corruption, aka "Windows Common AVI Parsing Overflow Vulnerability."
4304| [CVE-2008-4253] The FlexGrid ActiveX control in Microsoft Visual Basic 6.0, Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2, Office FrontPage 2002 SP3, and Office Project 2003 SP3 does not properly handle errors during access to incorrectly initialized objects, which allows remote attackers to execute arbitrary code via a crafted HTML document, related to corruption of the "system state," aka "FlexGrid Control Memory Corruption Vulnerability."
4305| [CVE-2008-4250] The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitrary code via a crafted RPC request that triggers the overflow during path canonicalization, as exploited in the wild by Gimmiv.A in October 2008, aka "Server Service Vulnerability."
4306| [CVE-2008-4114] srv.sys in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to cause a denial of service (system crash) or possibly have unspecified other impact via an SMB WRITE_ANDX packet with an offset that is inconsistent with the packet size, related to "insufficiently validating the buffer size," as demonstrated by a request to the \PIPE\lsarpc named pipe, aka "SMB Validation Denial of Service Vulnerability."
4307| [CVE-2008-4110] Buffer overflow in the SQLVDIRLib.SQLVDirControl ActiveX control in Tools\Binn\sqlvdir.dll in Microsoft SQL Server 2000 (aka SQL Server 8.0) allows remote attackers to cause a denial of service (browser crash) or possibly execute arbitrary code via a long URL in the second argument to the Connect method. NOTE: this issue is not a vulnerability in many environments, since the control is not marked as safe for scripting and would not execute with default Internet Explorer settings.
4308| [CVE-2008-4038] Buffer underflow in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to execute arbitrary code via a Server Message Block (SMB) request that contains a filename with a crafted length, aka "SMB Buffer Underflow Vulnerability."
4309| [CVE-2008-4037] Microsoft Windows 2000 Gold through SP4, XP Gold through SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote SMB servers to execute arbitrary code on a client machine by replaying the NTLM credentials of a client user, as demonstrated by backrush, aka "SMB Credential Reflection Vulnerability." NOTE: some reliable sources report that this vulnerability exists because of an insufficient fix for CVE-2000-0834.
4310| [CVE-2008-4036] Integer overflow in Memory Manager in Microsoft Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows local users to gain privileges via a crafted application that triggers an erroneous decrement of a variable, related to validation of parameters for Virtual Address Descriptors (VADs) and a "memory allocation mapping error," aka "Virtual Address Descriptor Elevation of Privilege Vulnerability."
4311| [CVE-2008-4032] Microsoft Office SharePoint Server 2007 Gold and SP1 and Microsoft Search Server 2008 do not properly perform authentication and authorization for administrative functions, which allows remote attackers to cause a denial of service (server load), obtain sensitive information, and "create scripts that would run in the context of the site" via requests to administrative URIs, aka "Access Control Vulnerability."
4312| [CVE-2008-4031] Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1
4313| [CVE-2008-4030] Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1
4314| [CVE-2008-4028] Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1
4315| [CVE-2008-4027] Double free vulnerability in Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1
4316| [CVE-2008-4026] Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1
4317| [CVE-2008-4025] Integer overflow in Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1
4318| [CVE-2008-4024] Microsoft Office Word 2000 SP3 and 2002 SP3 and Office 2004 for Mac allow remote attackers to execute arbitrary code via a Word document with a crafted lcbPlcfBkfSdt field in the File Information Block (FIB), which bypasses an initialization step and triggers an "arbitrary free," aka "Word Memory Corruption Vulnerability."
4319| [CVE-2008-4023] Active Directory in Microsoft Windows 2000 SP4 does not properly allocate memory for (1) LDAP and (2) LDAPS requests, which allows remote attackers to execute arbitrary code via a crafted request, aka "Active Directory Overflow Vulnerability."
4320| [CVE-2008-4019] Integer overflow in the REPT function in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2 and SP3, and 2007 Gold and SP1
4321| [CVE-2008-3956] orgchart.exe in Microsoft Organization Chart 2.00 allows user-assisted attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted .opx file.
4322| [CVE-2008-3704] Heap-based buffer overflow in the MaskedEdit ActiveX control in Msmask32.ocx 6.0.81.69, and possibly other versions before 6.0.84.18, in Microsoft Visual Studio 6.0, Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2 allows remote attackers to execute arbitrary code via a long Mask parameter, related to not "validating property values with boundary checks," as exploited in the wild in August 2008, aka "Masked Edit Control Memory Corruption Vulnerability."
4323| [CVE-2008-3648] nslookup.exe in Microsoft Windows XP SP2 allows user-assisted remote attackers to execute arbitrary code, as demonstrated by an attempted DNS zone transfer, and as exploited in the wild in August 2008.
4324| [CVE-2008-3636] Integer overflow in the IopfCompleteRequest API in the kernel in Microsoft Windows 2000, XP, Server 2003, and Vista allows context-dependent attackers to gain privileges. NOTE: this issue was originally reported for GEARAspiWDM.sys 2.0.7.5 in Gear Software CD DVD Filter driver before 4.001.7, as used in other products including Apple iTunes and multiple Symantec and Norton products, which allows local users to gain privileges via repeated IoAttachDevice IOCTL calls to \\.\GEARAspiWDMDevice in this GEARAspiWDM.sys. However, the root cause is the integer overflow in the API call itself.
4325| [CVE-2008-3479] Heap-based buffer overflow in the Microsoft Message Queuing (MSMQ) service (mqsvc.exe) in Microsoft Windows 2000 SP4 allows remote attackers to read memory contents and execute arbitrary code via a crafted RPC call, related to improper processing of parameters to string APIs, aka "Message Queuing Service Remote Code Execution Vulnerability."
4326| [CVE-2008-3477] Microsoft Excel 2000 SP3, 2002 SP3, and 2003 SP2 and SP3 does not properly validate data in the VBA Performance Cache when processing an Office document with an embedded object, which allows remote attackers to execute arbitrary code via an Excel file containing a crafted value, leading to heap-based buffer overflows, integer overflows, array index errors, and memory corruption, aka "Calendar Object Validation Vulnerability."
4327| [CVE-2008-3471] Stack-based buffer overflow in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2 and SP3, and 2007 Gold and SP1
4328| [CVE-2008-3466] Microsoft Host Integration Server (HIS) 2000, 2004, and 2006 does not limit RPC access to administrative functions, which allows remote attackers to bypass authentication and execute arbitrary programs via a crafted SNA RPC message using opcode 1 or 6 to call the CreateProcess function, aka "HIS Command Execution Vulnerability."
4329| [CVE-2008-3465] Heap-based buffer overflow in an API in GDI in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows context-dependent attackers to cause a denial of service or execute arbitrary code via a WMF file with a malformed file-size parameter, which would not be properly handled by a third-party application that uses this API for a copy operation, aka "GDI Heap Overflow Vulnerability."
4330| [CVE-2008-3464] afd.sys in the Ancillary Function Driver (AFD) component in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP1 and SP2 does not properly validate input sent from user mode to the kernel, which allows local users to gain privileges via a crafted application, as demonstrated using crafted pointers and lengths that bypass intended ProbeForRead and ProbeForWrite restrictions, aka "AFD Kernel Overwrite Vulnerability."
4331| [CVE-2008-3460] WPGIMP32.FLT in Microsoft Office 2000 SP3, XP SP3, and 2003 SP2
4332| [CVE-2008-3068] Microsoft Crypto API 5.131.2600.2180 through 6.0, as used in Outlook, Windows Live Mail, and Office 2007, performs Certificate Revocation List (CRL) checks by using an arbitrary URL from a certificate embedded in a (1) S/MIME e-mail message or (2) signed document, which allows remote attackers to obtain reading times and IP addresses of recipients, and port-scan results, via a crafted certificate with an Authority Information Access (AIA) extension.
4333| [CVE-2008-3021] Microsoft Office 2000 SP3, XP SP3, and 2003 SP2
4334| [CVE-2008-3020] Microsoft Office 2000 SP3 and XP SP3
4335| [CVE-2008-3019] Microsoft Office 2000 SP3, XP SP3, and 2003 SP2
4336| [CVE-2008-3018] Microsoft Office 2000 SP3, XP SP3, and 2003 SP2
4337| [CVE-2008-3015] Integer overflow in gdiplus.dll in GDI+ in Microsoft Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a BMP image file with a malformed BitMapInfoHeader that triggers a buffer overflow, aka "GDI+ BMP Integer Overflow Vulnerability."
4338| [CVE-2008-3014] Buffer overflow in gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a malformed WMF image file that triggers improper memory allocation, aka "GDI+ WMF Buffer Overrun Vulnerability."
4339| [CVE-2008-3013] gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a malformed GIF image file containing many extension markers for graphic control extensions and subsequent unknown labels, aka "GDI+ GIF Parsing Vulnerability."
4340| [CVE-2008-3012] gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 does not properly perform memory allocation, which allows remote attackers to execute arbitrary code via a malformed EMF image file, aka "GDI+ EMF Memory Corruption Vulnerability."
4341| [CVE-2008-3009] Microsoft Windows Media Player 6.4, Windows Media Format Runtime 7.1 through 11, and Windows Media Services 4.1, 9, and 2008 do not properly use the Service Principal Name (SPN) identifier when validating replies to authentication requests, which allows remote servers to execute arbitrary code via vectors that employ NTLM credential reflection, aka "SPN Vulnerability."
4342| [CVE-2008-3007] Argument injection vulnerability in a URI handler in Microsoft Office XP SP3, 2003 SP2 and SP3, 2007 Office System Gold and SP1, and Office OneNote 2007 Gold and SP1 allow remote attackers to execute arbitrary code via a crafted onenote:// URL, aka "Uniform Resource Locator Validation Error Vulnerability."
4343| [CVE-2008-3006] Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP2 and SP3, and 2007 Gold and SP1
4344| [CVE-2008-3005] Array index vulnerability in Microsoft Office Excel 2000 SP3 and 2002 SP3, and Office 2004 and 2008 for Mac allows remote attackers to execute arbitrary code via an Excel file with a crafted array index for a FORMAT record, aka the "Excel Index Array Vulnerability."
4345| [CVE-2008-3004] Microsoft Office Excel 2000 SP3, 2002 SP3, and 2003 SP2 and SP3
4346| [CVE-2008-3003] Microsoft Office Excel 2007 Gold and SP1 does not properly delete the PWD (password) string from connections.xml when a .xlsx file is configured not to save the remote data session password, which allows local users to obtain sensitive information and obtain access to a remote data source, aka the "Excel Credential Caching Vulnerability."
4347| [CVE-2008-2752] Microsoft Word 2000 9.0.2812 and 2003 11.8106.8172 does not properly handle unordered lists, which allows user-assisted remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted .doc file. NOTE: some of these details are obtained from third party information.
4348| [CVE-2008-2540] Apple Safari on Mac OS X, and before 3.1.2 on Windows, does not prompt the user before downloading an object that has an unrecognized content type, which allows remote attackers to place malware into the (1) Desktop directory on Windows or (2) Downloads directory on Mac OS X, and subsequently allows remote attackers to execute arbitrary code on Windows by leveraging an untrusted search path vulnerability in (a) Internet Explorer 7 on Windows XP or (b) the SearchPath function in Windows XP, Vista, and Server 2003 and 2008, aka a "Carpet Bomb" and a "Blended Threat Elevation of Privilege Vulnerability," a different issue than CVE-2008-1032. NOTE: Apple considers this a vulnerability only because the Microsoft products can load application libraries from the desktop and, as of 20080619, has not covered the issue in an advisory for Mac OS X.
4349| [CVE-2008-2463] The Microsoft Office Snapshot Viewer ActiveX control in snapview.ocx 10.0.5529.0, as distributed in the standalone Snapshot Viewer and Microsoft Office Access 2000 through 2003, allows remote attackers to download arbitrary files to a client machine via a crafted HTML document or e-mail message, probably involving use of the SnapshotPath and CompressedPath properties and the PrintSnapshot method. NOTE: this can be leveraged for code execution by writing to a Startup folder.
4350| [CVE-2008-2252] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate parameters sent from user mode to the kernel, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Memory Corruption Vulnerability."
4351| [CVE-2008-2251] Double free vulnerability in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows local users to gain privileges via a crafted application that makes system calls within multiple threads, aka "Windows Kernel Unhandled Exception Vulnerability." NOTE: according to Microsoft, this is not a duplicate of CVE-2008-4510.
4352| [CVE-2008-2250] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate window properties sent from a parent window to a child window during creation of a new window, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Window Creation Vulnerability."
4353| [CVE-2008-2249] Integer overflow in GDI in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to execute arbitrary code via a malformed header in a crafted WMF file, which triggers a buffer overflow, aka "GDI Integer Overflow Vulnerability."
4354| [CVE-2008-2246] Microsoft Windows Vista through SP1 and Server 2008 do not properly import the default IPsec policy from a Windows Server 2003 domain to a Windows Server 2008 domain, which prevents IPsec rules from being enforced and allows remote attackers to bypass intended access restrictions.
4355| [CVE-2008-2245] Heap-based buffer overflow in the InternalOpenColorProfile function in mscms.dll in Microsoft Windows Image Color Management System (MSCMS) in the Image Color Management (ICM) component on Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted image file.
4356| [CVE-2008-2244] Microsoft Office Word 2002 SP3 allows remote attackers to execute arbitrary code via a .doc file that contains malformed data, as exploited in the wild in July 2008, and as demonstrated by attachement.doc.
4357| [CVE-2008-1898] A certain ActiveX control in WkImgSrv.dll 7.03.0616.0, as distributed in Microsoft Works 7 and Microsoft Office 2003 and 2007, allows remote attackers to execute arbitrary code or cause a denial of service (browser crash) via an invalid WksPictureInterface property value, which triggers an improper function call.
4358| [CVE-2008-1888] Cross-site scripting (XSS) vulnerability in Microsoft Windows SharePoint Services 2.0 allows remote attackers to inject arbitrary web script or HTML via the Picture Source (aka picture object source) field in the Rich Text Editor.
4359| [CVE-2008-1547] Open redirect vulnerability in exchweb/bin/redir.asp in Microsoft Outlook Web Access (OWA) for Exchange Server 2003 SP2 (aka build 6.5.7638) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the URL parameter.
4360| [CVE-2008-1457] The Event System in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate per-user subscriptions, which allows remote authenticated users to execute arbitrary code via a crafted event subscription request.
4361| [CVE-2008-1456] Array index vulnerability in the Event System in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote authenticated users to execute arbitrary code via a crafted event subscription request that is used to access an array of function pointers.
4362| [CVE-2008-1455] A "memory calculation error" in Microsoft Office PowerPoint 2000 SP3, 2002 SP3, 2003 SP2, and 2007 through SP1
4363| [CVE-2008-1454] Unspecified vulnerability in Microsoft DNS in Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008 allows remote attackers to conduct cache poisoning attacks via unknown vectors related to accepting "records from a response that is outside the remote server's authority," aka "DNS Cache Poisoning Vulnerability," a different vulnerability than CVE-2008-1447.
4364| [CVE-2008-1451] The WINS service on Microsoft Windows 2000 SP4, and Server 2003 SP1 and SP2, does not properly validate data structures in WINS network packets, which allows local users to gain privileges via a crafted packet, aka "Memory Overwrite Vulnerability."
4365| [CVE-2008-1446] Integer overflow in the Internet Printing Protocol (IPP) ISAPI extension in Microsoft Internet Information Services (IIS) 5.0 through 7.0 on Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, and Server 2008 allows remote authenticated users to execute arbitrary code via an HTTP POST request that triggers an outbound IPP connection from a web server to a machine operated by the attacker, aka "Integer Overflow in IPP Service Vulnerability."
4366| [CVE-2008-1445] Active Directory on Microsoft Windows 2000 Server SP4, XP Professional SP2 and SP3, Server 2003 SP1 and SP2, and Server 2008 allows remote authenticated users to cause a denial of service (system hang or reboot) via a crafted LDAP request.
4367| [CVE-2008-1444] Stack-based buffer overflow in Microsoft DirectX 7.0 and 8.1 on Windows 2000 SP4 allows remote attackers to execute arbitrary code via a Synchronized Accessible Media Interchange (SAMI) file with crafted parameters for a Class Name variable, aka the "SAMI Format Parsing Vulnerability."
4368| [CVE-2008-1441] Microsoft Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to cause a denial of service (system hang) via a series of Pragmatic General Multicast (PGM) packets with invalid fragment options, aka the "PGM Malformed Fragment Vulnerability."
4369| [CVE-2008-1440] Microsoft Windows XP SP2 and SP3, and Server 2003 SP1 and SP2, does not properly validate the option length field in Pragmatic General Multicast (PGM) packets, which allows remote attackers to cause a denial of service (infinite loop and system hang) via a crafted PGM packet, aka the "PGM Invalid Length Vulnerability."
4370| [CVE-2008-1436] Microsoft Windows XP Professional SP2, Vista, and Server 2003 and 2008 does not properly assign activities to the (1) NetworkService and (2) LocalService accounts, which might allow context-dependent attackers to gain privileges by using one service process to capture a resource from a second service process that has a LocalSystem privilege-escalation ability, related to improper management of the SeImpersonatePrivilege user right, as originally reported for Internet Information Services (IIS), aka Token Kidnapping.
4371| [CVE-2008-1435] Windows Explorer in Microsoft Windows Vista up to SP1, and Server 2008, allows user-assisted remote attackers to execute arbitrary code via crafted saved-search (.search-ms) files that are not properly handled when saving, aka "Windows Saved Search Vulnerability."
4372| [CVE-2008-1434] Use-after-free vulnerability in Microsoft Word in Office 2000 and XP SP3, 2003 SP2 and SP3, and 2007 Office System SP1 and earlier allows remote attackers to execute arbitrary code via an HTML document with a large number of Cascading Style Sheets (CSS) selectors, related to a "memory handling error" that triggers memory corruption.
4373| [CVE-2008-1092] Buffer overflow in msjet40.dll before 4.0.9505.0 in Microsoft Jet Database Engine allows remote attackers to execute arbitrary code via a crafted Word file, as exploited in the wild in March 2008. NOTE: as of 20080513, Microsoft has stated that this is the same issue as CVE-2007-6026.
4374| [CVE-2008-1091] Unspecified vulnerability in Microsoft Word in Office 2000 and XP SP3, 2003 SP2 and SP3, and 2007 Office System SP1 and earlier allows remote attackers to execute arbitrary code via a Rich Text Format (.rtf) file with a malformed string that triggers a "memory calculation error" and a heap-based buffer overflow, aka "Object Parsing Vulnerability."
4375| [CVE-2008-1090] Unspecified vulnerability in Microsoft Visio 2002 SP2, 2003 SP2 and SP3, and 2007 up to SP1 allows user-assisted remote attackers to execute arbitrary code via a crafted .DXF file, aka "Visio Memory Validation Vulnerability."
4376| [CVE-2008-1089] Unspecified vulnerability in Microsoft Visio 2002 SP2, 2003 SP2 and SP3, and 2007 up to SP1 allows user-assisted remote attackers to execute arbitrary code via a Visio file containing crafted object header data, aka "Visio Object Header Vulnerability."
4377| [CVE-2008-1088] Microsoft Project 2000 Service Release 1, 2002 SP1, and 2003 SP2 allows user-assisted remote attackers to execute arbitrary code via a crafted Project file, related to improper validation of "memory resource allocations."
4378| [CVE-2008-1087] Stack-based buffer overflow in GDI in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, and Server 2008 allows remote attackers to execute arbitrary code via an EMF image file with crafted filename parameters, aka "GDI Stack Overflow Vulnerability."
4379| [CVE-2008-1086] The HxTocCtrl ActiveX control (hxvz.dll), as used in Microsoft Internet Explorer 5.01 SP4 and 6 SP1, in Windows XP SP2, Server 2003 SP1 and SP2, Vista SP1, and Server 2008, allows remote attackers to execute arbitrary code via malformed arguments, which triggers memory corruption.
4380| [CVE-2008-1084] Unspecified vulnerability in the kernel in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, through Vista SP1, and Server 2008 allows local users to execute arbitrary code via unknown vectors related to improper input validation. NOTE: it was later reported that one affected function is NtUserFnOUTSTRING in win32k.sys.
4381| [CVE-2008-1083] Heap-based buffer overflow in the CreateDIBPatternBrushPt function in GDI in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, and Server 2008 allows remote attackers to execute arbitrary code via an EMF or WMF image file with a malformed header that triggers an integer overflow, aka "GDI Heap Overflow Vulnerability."
4382| [CVE-2008-0121] A "memory calculation error" in Microsoft PowerPoint Viewer 2003 allows remote attackers to execute arbitrary code via a PowerPoint file with an invalid picture index that triggers memory corruption, aka "Memory Calculation Vulnerability."
4383| [CVE-2008-0120] Integer overflow in Microsoft PowerPoint Viewer 2003 allows remote attackers to execute arbitrary code via a PowerPoint file with a malformed picture index that triggers memory corruption, related to handling of CString objects, aka "Memory Allocation Vulnerability."
4384| [CVE-2008-0119] Unspecified vulnerability in Microsoft Publisher in Office 2000 and XP SP3, 2003 SP2 and SP3, and 2007 SP1 and earlier allows remote attackers to execute arbitrary code via a Publisher file with crafted object header data that triggers memory corruption, aka "Publisher Object Handler Validation Vulnerability."
4385| [CVE-2008-0118] Unspecified vulnerability in Microsoft Office 2000 SP3, XP SP3, 2003 SP2, Excel Viewer 2003 up to SP3, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via a crafted Office document that triggers memory corruption from an "allocation error," aka "Microsoft Office Memory Corruption Vulnerability."
4386| [CVE-2008-0117] Unspecified vulnerability in Microsoft Excel 2000 SP3 and 2002 SP2, and Office 2004 and 2008 for Mac, allows user-assisted remote attackers to execute arbitrary code via crafted conditional formatting values, aka "Excel Conditional Formatting Vulnerability."
4387| [CVE-2008-0116] Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, Compatibility Pack, and Office 2004 and 2008 for Mac allows user-assisted remote attackers to execute arbitrary code via malformed tags in rich text, aka "Excel Rich Text Validation Vulnerability."
4388| [CVE-2008-0115] Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2007, Viewer 2003, Compatibility Pack, and Office for Mac 2004 allows user-assisted remote attackers to execute arbitrary code via malformed formulas, aka "Excel Formula Parsing Vulnerability."
4389| [CVE-2008-0114] Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, and Office for Mac 2004 allows user-assisted remote attackers to execute arbitrary code via crafted Style records that trigger memory corruption.
4390| [CVE-2008-0113] Unspecified vulnerability in Microsoft Office Excel Viewer 2003 up to SP3 allows user-assisted remote attackers to execute arbitrary code via an Excel document with malformed cell comments that trigger memory corruption from an "allocation error," aka "Microsoft Office Cell Parsing Memory Corruption Vulnerability."
4391| [CVE-2008-0112] Unspecified vulnerability in Microsoft Excel 2000 SP3, and Office for Mac 2004 and 2008 allows user-assisted remote attackers to execute arbitrary code via a crafted .SLK file that is not properly handled when importing the file, aka "Excel File Import Vulnerability."
4392| [CVE-2008-0111] Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2007, Viewer 2003, Compatibility Pack, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via crafted data validation records, aka "Excel Data Validation Record Vulnerability."
4393| [CVE-2008-0110] Unspecified vulnerability in Microsoft Outlook in Office 2000 SP3, XP SP3, 2003 SP2 and Sp3, and Office System allows user-assisted remote attackers to execute arbitrary code via a crafted mailto URI.
4394| [CVE-2008-0109] Word in Microsoft Office 2000 SP3, XP SP3, Office 2003 SP2, and Office Word Viewer 2003 allows remote attackers to execute arbitrary code via crafted fields within the File Information Block (FIB) of a Word file, which triggers length calculation errors and memory corruption.
4395| [CVE-2008-0108] Stack-based buffer overflow in wkcvqd01.dll in Microsoft Works 6 File Converter, as used in Office 2003 SP2 and SP3, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted field lengths, aka "Microsoft Works File Converter Field Length Vulnerability."
4396| [CVE-2008-0106] Buffer overflow in Microsoft SQL Server 2005 SP1 and SP2, and 2005 Express Edition SP1 and SP2, allows remote authenticated users to execute arbitrary code via a crafted insert statement.
4397| [CVE-2008-0105] Microsoft Works 6 File Converter, as used in Office 2003 SP2 and SP3, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted section header index table information, aka "Microsoft Works File Converter Index Table Vulnerability."
4398| [CVE-2008-0104] Unspecified vulnerability in Microsoft Office Publisher 2000, 2002, and 2003 SP2 allows remote attackers to execute arbitrary code via a crafted .pub file, aka "Publisher Memory Corruption Vulnerability."
4399| [CVE-2008-0103] Unspecified vulnerability in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP2, and Office 2004 for Mac allows remote attackers to execute arbitrary code via an Office document that contains a malformed object, related to a "memory handling error," aka "Microsoft Office Execution Jump Vulnerability."
4400| [CVE-2008-0102] Unspecified vulnerability in Microsoft Office Publisher 2000, 2002, and 2003 SP2 allows remote attackers to execute arbitrary code via a crafted .pub file, related to invalid "memory values," aka "Publisher Invalid Memory Reference Vulnerability."
4401| [CVE-2008-0088] Unspecified vulnerability in Active Directory on Microsoft Windows 2000 and Windows Server 2003, and Active Directory Application Mode (ADAM) on XP and Server 2003, allows remote attackers to cause a denial of service (hang and restart) via a crafted LDAP request.
4402| [CVE-2008-0087] The DNS client in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, and Vista uses predictable DNS transaction IDs, which allows remote attackers to spoof DNS responses.
4403| [CVE-2008-0086] Buffer overflow in the convert function in Microsoft SQL Server 2000 SP4, 2000 Desktop Engine (MSDE 2000) SP4, and 2000 Desktop Engine (WMSDE) allows remote authenticated users to execute arbitrary code via a crafted SQL expression.
4404| [CVE-2008-0083] The (1) VBScript (VBScript.dll) and (2) JScript (JScript.dll) scripting engines 5.1 and 5.6, as used in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2, do not properly decode script, which allows remote attackers to execute arbitrary code via unknown vectors.
4405| [CVE-2008-0081] Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via crafted macros, aka "Macro Validation Vulnerability," a different vulnerability than CVE-2007-3490.
4406| [CVE-2008-0080] Heap-based buffer overflow in the WebDAV Mini-Redirector in Microsoft Windows XP SP2, Server 2003 SP1 and SP2, and Vista allows remote attackers to execute arbitrary code via a crafted WebDAV response.
4407| [CVE-2008-0020] Unspecified vulnerability in the Load method in the IPersistStreamInit interface in the Active Template Library (ATL), as used in the Microsoft Video ActiveX control in msvidctl.dll in DirectShow, in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via unknown vectors that trigger memory corruption, aka "ATL Header Memcopy Vulnerability," a different vulnerability than CVE-2008-0015.
4408| [CVE-2008-0015] Stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL), as used in the MPEG2TuneRequest ActiveX control in msvidctl.dll in DirectShow, in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a crafted web page, as exploited in the wild in July 2009, aka "Microsoft Video ActiveX Control Vulnerability."
4409| [CVE-2008-0011] Microsoft DirectX 8.1 through 9.0c, and DirectX on Microsoft XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008, does not properly perform MJPEG error checking, which allows remote attackers to execute arbitrary code via a crafted MJPEG stream in a (1) AVI or (2) ASF file, aka the "MJPEG Decoder Vulnerability."
4410| [CVE-2007-6753] Untrusted search path vulnerability in Shell32.dll in Microsoft Windows 2000, Windows XP, Windows Vista, Windows Server 2008, and Windows 7, when using an environment configured with a string such as %APPDATA% or %PROGRAMFILES% in a certain way, allows local users to gain privileges via a Trojan horse DLL under the current working directory, as demonstrated by iTunes and Safari.
4411| [CVE-2007-6357] Stack-based buffer overflow in Microsoft Office Access allows remote, user-assisted attackers to execute arbitrary code via a crafted Microsoft Access Database (.mdb) file. NOTE: due to the lack of details as of 20071210, it is not clear whether this issue is the same as CVE-2007-6026 or CVE-2005-0944.
4412| [CVE-2007-6329] Microsoft Office 2007 12.0.6015.5000 and MSO 12.0.6017.5000 do not sign the metadata of Office Open XML (OOXML) documents, which makes it easier for remote attackers to modify Dublin Core metadata fields, as demonstrated by the (1) LastModifiedBy and (2) creator fields in docProps/core.xml in the OOXML ZIP container.
4413| [CVE-2007-6043] The CryptGenRandom function in Microsoft Windows 2000 generates predictable values, which makes it easier for context-dependent attackers to reduce the effectiveness of cryptographic mechanisms, as demonstrated by attacks on (1) forward security and (2) backward security, related to use of eight instances of the RC4 cipher, and possibly a related issue to CVE-2007-3898.
4414| [CVE-2007-6026] Stack-based buffer overflow in Microsoft msjet40.dll 4.0.8618.0 (aka Microsoft Jet Engine), as used by Access 2003 in Microsoft Office 2003 SP3, allows user-assisted attackers to execute arbitrary code via a crafted MDB file database file containing a column structure with a modified column count. NOTE: this might be the same issue as CVE-2005-0944.
4415| [CVE-2007-5587] Buffer overflow in Macrovision SafeDisc secdrv.sys before 4.3.86.0, as shipped in Microsoft Windows XP SP2, XP Professional x64 and x64 SP2, Server 2003 SP1 and SP2, and Server 2003 x64 and x64 SP2 allows local users to overwrite arbitrary memory locations and gain privileges via a crafted argument to a METHOD_NEITHER IOCTL, as originally discovered in the wild.
4416| [CVE-2007-5352] Unspecified vulnerability in Local Security Authority Subsystem Service (LSASS) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2 allows local users to gain privileges via a crafted local procedure call (LPC) request.
4417| [CVE-2007-5348] Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via an image file with crafted gradient sizes in gradient fill input, which triggers a heap-based buffer overflow related to GdiPlus.dll and VGX.DLL, aka "GDI+ VML Buffer Overrun Vulnerability."
4418| [CVE-2007-4991] The SOCKS4 Proxy in Microsoft Internet Security and Acceleration (ISA) Server 2004 SP1 and SP2 allows remote attackers to obtain potentially sensitive information (the destination IP address of another user's session) via an empty packet.
4419| [CVE-2007-4916] Heap-based buffer overflow in the FileFind::FindFile method in (1) MFC42.dll, (2) MFC42u.dll, (3) MFC71.dll, and (4) MFC71u.dll in Microsoft Foundation Class (MFC) Library 8.0, as used by the ListFiles method in hpqutil.dll 2.0.0.138 in Hewlett-Packard (HP) All-in-One and Photo & Imaging Gallery 1.1 and probably other products, allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long first argument.
4420| [CVE-2007-4814] Buffer overflow in the SQLServer ActiveX control in the Distributed Management Objects OLE DLL (sqldmo.dll) 2000.085.2004.00 in Microsoft SQL Server Enterprise Manager 8.05.2004 allows remote attackers to execute arbitrary code via a long second argument to the Start method.
4421| [CVE-2007-3930] Interpretation conflict between Microsoft Internet Explorer and DocuWiki before 2007-06-26b allows remote attackers to inject arbitrary JavaScript and conduct cross-site scripting (XSS) attacks when spellchecking UTF-8 encoded messages via the spell_utf8test function in lib/exe/spellcheck.php, which triggers HTML document identification and script execution by Internet Explorer even though the Content-Type header is text/plain.
4422| [CVE-2007-3924] Argument injection vulnerability in Microsoft Internet Explorer, when running on systems with Netscape installed and certain URIs registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in a -chrome argument to the navigatorurl URI, which are inserted into the command line that is created when invoking netscape.exe, a related issue to CVE-2007-3670. NOTE: there has been debate about whether the issue is in Internet Explorer or Netscape. As of 20070713, it is CVE's opinion that IE appears to not properly delimit the URL argument when invoking Netscape
4423| [CVE-2007-3899] Unspecified vulnerability in Microsoft Word 2000 SP3, Word 2002 SP3, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via a malformed string in a Word file, aka "Word Memory Corruption Vulnerability."
4424| [CVE-2007-3898] The DNS server in Microsoft Windows 2000 Server SP4, and Server 2003 SP1 and SP2, uses predictable transaction IDs when querying other DNS servers, which allows remote attackers to spoof DNS replies, poison the DNS cache, and facilitate further attack vectors.
4425| [CVE-2007-3896] The URL handling in Shell32.dll in the Windows shell in Microsoft Windows XP and Server 2003, with Internet Explorer 7 installed, allows remote attackers to execute arbitrary programs via invalid "%" sequences in a mailto: or other URI handler, as demonstrated using mIRC, Outlook, Firefox, Adobe Reader, Skype, and other applications. NOTE: this issue might be related to other issues involving URL handlers in Windows systems, such as CVE-2007-3845. There also might be separate but closely related issues in the applications that are invoked by the handlers.
4426| [CVE-2007-3890] Microsoft Excel in Office 2000 SP3, Office XP SP3, Office 2003 SP2, and Office 2004 for Mac allows remote attackers to execute arbitrary code via a Workspace with a certain index value that triggers memory corruption.
4427| [CVE-2007-3670] Argument injection vulnerability in Microsoft Internet Explorer, when running on systems with Firefox installed and certain URIs registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in a (1) FirefoxURL or (2) FirefoxHTML URI, which are inserted into the command line that is created when invoking firefox.exe. NOTE: it has been debated as to whether the issue is in Internet Explorer or Firefox. As of 20070711, it is CVE's opinion that IE appears to be failing to properly delimit the URL argument when invoking Firefox, and this issue could arise with other protocol handlers in IE as well. However, Mozilla has stated that it will address the issue with a "defense in depth" fix that will "prevent IE from sending Firefox malicious data."
4428| [CVE-2007-3490] Unspecified vulnerability in Microsoft Excel 2003 SP2 allows remote attackers to have an unknown impact via unspecified vectors, possibly related to the sheet name, as demonstrated by 2670.xls.
4429| [CVE-2007-3300] Multiple F-Secure anti-virus products for Microsoft Windows and Linux before 20070619 allow remote attackers to bypass scanning via a crafted header in a (1) LHA or (2) RAR archive.
4430| [CVE-2007-3040] Stack-based buffer overflow in agentdpv.dll 2.0.0.3425 in Microsoft Agent on Windows 2000 SP4 allows remote attackers to execute arbitrary code via a crafted URL to the Agent (Agent.Control) ActiveX control, which triggers an overflow within the Agent Service (agentsrv.exe) process, a different issue than CVE-2007-1205.
4431| [CVE-2007-3039] Stack-based buffer overflow in the Microsoft Message Queuing (MSMQ) service in Microsoft Windows 2000 Server SP4, Windows 2000 Professional SP4, and Windows XP SP2 allows attackers to execute arbitrary code via a long string in an opnum 0x06 RPC call to port 2103. NOTE: this is remotely exploitable on Windows 2000 Server.
4432| [CVE-2007-3036] Unspecified vulnerability in the (1) Windows Services for UNIX 3.0 and 3.5, and (2) Subsystem for UNIX-based Applications in Microsoft Windows 2000, XP, Server 2003, and Vista allows local users to gain privileges via unspecified vectors related to "certain setuid binary files."
4433| [CVE-2007-3034] Integer overflow in the AttemptWrite function in Graphics Rendering Engine (GDI) on Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted metafile (image) with a large record length value, which triggers a heap-based buffer overflow.
4434| [CVE-2007-3030] Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, and 2003 Viewer allows user-assisted remote attackers to execute arbitrary code via a malformed Excel file involving the "denoting [of] the start of a Workspace designation", which results in memory corruption, aka the "Workbook Memory Corruption Vulnerability".
4435| [CVE-2007-3029] Unspecified vulnerability in Microsoft Excel 2002 SP3 and 2003 SP2 allows user-assisted remote attackers to execute arbitrary code via a malformed Excel file containing multiple active worksheets, which results in memory corruption.
4436| [CVE-2007-3028] The LDAP service in Windows Active Directory in Microsoft Windows 2000 Server SP4 does not properly check "the number of convertible attributes", which allows remote attackers to cause a denial of service (service unavailability) via a crafted LDAP request, related to "client sent LDAP request logic," aka "Windows Active Directory Denial of Service Vulnerability". NOTE: this is probably a different issue than CVE-2007-0040.
4437| [CVE-2007-2999] Microsoft Windows Server 2003, when time restrictions are in effect for user accounts, generates different error messages for failed login attempts with a valid user name than for those with an invalid user name, which allows context-dependent attackers to determine valid Active Directory account names.
4438| [CVE-2007-2967] Multiple F-Secure anti-virus products for Microsoft Windows and Linux before 20070522 allow remote attackers to cause a denial of service (file scanning infinite loop) via certain crafted (1) ARJ archives or (2) FSG packed files.
4439| [CVE-2007-2966] Buffer overflow in the LHA decompresion component in F-Secure anti-virus products for Microsoft Windows and Linux before 20070529 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted LHA archive, related to an integer wrap, a similar issue to CVE-2006-4335.
4440| [CVE-2007-2903] Buffer overflow in the HelpPopup method in the Microsoft Office 2000 Controllo UA di Microsoft Office ActiveX control (OUACTRL.OCX) 1.0.1.9 allows remote attackers to cause a denial of service (probably winhlp32.exe crash) via a long first argument. NOTE: it is not clear whether this issue crosses privilege boundaries.
4441| [CVE-2007-2593] The Terminal Server in Microsoft Windows 2003 Server, when using TLS, allows remote attackers to bypass SSL and self-signed certificate requirements, downgrade the server security, and possibly conduct man-in-the-middle attacks via unspecified vectors, as demonstrated using the Remote Desktop Protocol (RDP) 6.0 client. NOTE: a third party claims that the vendor may have fixed this in approximately 2006.
4442| [CVE-2007-2581] Multiple cross-site scripting (XSS) vulnerabilities in Microsoft Windows SharePoint Services 3.0 for Windows Server 2003 and Office SharePoint Server 2007 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO (query string) in "every main page," as demonstrated by default.aspx.
4443| [CVE-2007-2374] Unspecified vulnerability in Microsoft Windows 2000, XP, and Server 2003 allows user-assisted remote attackers to execute arbitrary code via unspecified vectors. NOTE: this information is based upon a vague pre-advisory with no actionable information. However, the advisory is from a reliable source.
4444| [CVE-2007-2228] rpcrt4.dll (aka the RPC runtime library) in Microsoft Windows XP SP2, XP Professional x64 Edition, Server 2003 SP1 and SP2, Server 2003 x64 Edition and x64 Edition SP2, and Vista and Vista x64 Edition allows remote attackers to cause a denial of service (RPCSS service stop and system restart) via an RPC request that uses NTLMSSP PACKET authentication with a zero-valued verification trailer signature, which triggers an invalid dereference. NOTE: this also affects Windows 2000 SP4, although the impact is an information leak.
4445| [CVE-2007-2224] Object linking and embedding (OLE) Automation, as used in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Office 2004 for Mac, and Visual Basic 6.0 allows remote attackers to execute arbitrary code via the substringData method on a TextNode object, which causes an integer overflow that leads to a buffer overflow.
4446| [CVE-2007-2221] Unspecified vulnerability in the mdsauth.dll COM object in Microsoft Windows Media Server in the Microsoft Internet Explorer 5.01 SP4 on Windows 2000 SP4
4447| [CVE-2007-2219] Unspecified vulnerability in the Win32 API on Microsoft Windows 2000, XP SP2, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via certain parameters to an unspecified function.
4448| [CVE-2007-2218] Unspecified vulnerability in the Windows Schannel Security Package for Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2, allows remote servers to execute arbitrary code or cause a denial of service via crafted digital signatures that are processed during an SSL handshake.
4449| [CVE-2007-2217] Kodak Image Viewer in Microsoft Windows 2000 SP4, and in some cases XP SP2 and Server 2003 SP1 and SP2, allows remote attackers to execute arbitrary code via crafted image files that trigger memory corruption, as demonstrated by a certain .tif (TIFF) file.
4450| [CVE-2007-1911] Multiple unspecified vulnerabilities in Microsoft Word 2007 allow remote attackers to cause a denial of service (CPU consumption) via crafted documents, as demonstrated by (1) file798-1.doc and (2) file613-1.doc, possibly related to a buffer overflow.
4451| [CVE-2007-1910] Buffer overflow in wwlib.dll in Microsoft Word 2007 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted document, as demonstrated by file789-1.doc.
4452| [CVE-2007-1765] Unspecified vulnerability in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a malformed ANI file, which results in memory corruption when processing cursors, animated cursors, and icons, a similar issue to CVE-2005-0416, as originally demonstrated using Internet Explorer 6 and 7. NOTE: this issue might be a duplicate of CVE-2007-0038
4453| [CVE-2007-1756] Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2003 Viewer, and Office Excel 2007 does not properly validate version information, which allows user-assisted remote attackers to execute arbitrary code via a crafted Excel file, aka "Calculation Error Vulnerability".
4454| [CVE-2007-1754] PUBCONV.DLL in Microsoft Office Publisher 2007 does not properly clear memory when transferring data from disk to memory, which allows user-assisted remote attackers to execute arbitrary code via a malformed .pub page via a certain negative value, which bypasses a sanitization procedure that initializes critical pointers to NULL, aka the "Publisher Invalid Memory Reference Vulnerability".
4455| [CVE-2007-1748] Stack-based buffer overflow in the RPC interface in the Domain Name System (DNS) Server Service in Microsoft Windows 2000 Server SP 4, Server 2003 SP 1, and Server 2003 SP 2 allows remote attackers to execute arbitrary code via a long zone name containing character constants represented by escape sequences.
4456| [CVE-2007-1747] Unspecified vulnerability in MSO.dll in Microsoft Office 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and 2007 allows user-assisted remote attackers to execute arbitrary code via a malformed drawing object, which triggers memory corruption.
4457| [CVE-2007-1645] Buffer overflow in FutureSoft TFTP Server 2000 on Microsoft Windows 2000 SP4 allows remote attackers to execute arbitrary code via a long request on UDP port 69. NOTE: this issue might overlap CVE-2006-4781 or CVE-2005-1812.
4458| [CVE-2007-1537] \Device\NdisTapi (NDISTAPI.sys) in Microsoft Windows XP SP2 and 2003 SP1 uses weak permissions, which allows local users to write to the device and cause a denial of service, as demonstrated by using an IRQL to acquire a spinlock on paged memory via the NdisTapiDispatch function.
4459| [CVE-2007-1512] Stack-based buffer overflow in the AfxOleSetEditMenu function in the MFC component in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 Gold and SP1, and Visual Studio .NET 2002 Gold and SP1, and 2003 Gold and SP1 allows user-assisted remote attackers to have an unknown impact (probably crash) via an RTF file with a malformed OLE object, which results in writing two 0x00 characters past the end of szBuffer, aka the "MFC42u.dll Off-by-Two Overflow." NOTE: this issue is due to an incomplete patch (MS07-012) for CVE-2007-0025.
4460| [CVE-2007-1347] Microsoft Windows Explorer on Windows 2000 SP4 FR and XP SP2 FR, and possibly other versions and platforms, allows remote attackers to cause a denial of service (memory corruption and crash) via an Office file with crafted document summary information, which causes an error in Ole32.dll.
4461| [CVE-2007-1239] Microsoft Excel 2003 does not properly parse .XLS files, which allows remote attackers to cause a denial of service (application crash) via a file with a (1) corrupted XML format or a (2) corrupted XLS format, which triggers a NULL pointer dereference.
4462| [CVE-2007-1238] Microsoft Office 2003 allows user-assisted remote attackers to cause a denial of service (application crash) by attempting to insert a corrupted WMF file.
4463| [CVE-2007-1215] Buffer overflow in the Graphics Device Interface (GDI) in Microsoft Windows 2000 SP4
4464| [CVE-2007-1214] Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2003 Viewer, and 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via a crafted AutoFilter filter record in an Excel BIFF8 format XLS file, which triggers memory corruption.
4465| [CVE-2007-1213] The TrueType Fonts rasterizer in Microsoft Windows 2000 SP4 allows local users to gain privileges via crafted TrueType fonts, which result in an uninitialized function pointer.
4466| [CVE-2007-1212] Buffer overflow in the Graphics Device Interface (GDI) in Microsoft Windows 2000 SP4
4467| [CVE-2007-1211] Unspecified kernel GDI functions in Microsoft Windows 2000 SP4
4468| [CVE-2007-1205] Unspecified vulnerability in Microsoft Agent (msagent\agentsvr.exe) in Windows 2000 SP4, XP SP2, and Server 2003, 2003 SP1, and 2003 SP2 allows remote attackers to execute arbitrary code via crafted URLs, which result in memory corruption.
4469| [CVE-2007-1203] Unspecified vulnerability in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2003 Viewer, 2004 for Mac, and 2007 allows user-assisted remote attackers to execute arbitrary code via a crafted set font value in an Excel file, which results in memory corruption.
4470| [CVE-2007-1202] Word (or Word Viewer) in Microsoft Office 2000 SP3, XP SP3, 2003 SP2, 2004 for Mac, and Works Suite 2004, 2005, and 2006 does not properly parse certain rich text "property strings of certain control words," which allows user-assisted remote attackers to trigger heap corruption and execute arbitrary code, aka the "Word RTF Parsing Vulnerability."
4471| [CVE-2007-1201] Unspecified vulnerability in certain COM objects in Microsoft Office Web Components 2000 allows user-assisted remote attackers to execute arbitrary code via vectors related to DataSource that trigger memory corruption, aka "Office Web Components DataSource Vulnerability."
4472| [CVE-2007-1117] Unspecified vulnerability in Publisher 2007 in Microsoft Office 2007 allows remote attackers to execute arbitrary code via unspecified vectors, related to a "file format vulnerability." NOTE: this information is based upon a vague pre-advisory with no actionable information. However, the advisory is from a reliable source.
4473| [CVE-2007-1090] Microsoft Windows Explorer on Windows XP and 2003 allows remote user-assisted attackers to cause a denial of service (crash) via a malformed WMF file, which triggers the crash when the user browses the folder.
4474| [CVE-2007-1083] Buffer overflow in the Configuration Checker (ConfigChk) ActiveX control in VSCnfChk.dll 2.0.0.2 for Verisign Managed PKI Service, Secure Messaging for Microsoft Exchange, and Go Secure! allows remote attackers to execute arbitrary code via long arguments to the VerCompare method.
4475| [CVE-2007-0948] Heap-based buffer overflow in Microsoft Virtual PC 2004 and PC for Mac 7.1 and 7, and Virtual Server 2005 and 2005 R2, allows local guest OS administrators to execute arbitrary code on the host OS via unspecified vectors related to "interaction and initialization of components."
4476| [CVE-2007-0947] Use-after-free vulnerability in Microsoft Internet Explorer 7 on Windows XP SP2, Windows Server 2003 SP1 or SP2, or Windows Vista allows remote attackers to execute arbitrary code via crafted HTML objects, resulting in accessing deallocated memory of CMarkup objects, aka the second of two "HTML Objects Memory Corruption Vulnerabilities" and a different issue than CVE-2007-0946.
4477| [CVE-2007-0946] Unspecified vulnerability in Microsoft Internet Explorer 7 on Windows XP SP2, Windows Server 2003 SP1 or SP2, or Windows Vista allows remote attackers to execute arbitrary code via crafted HTML objects, which results in memory corruption, aka the first of two "HTML Objects Memory Corruption Vulnerabilities" and a different issue than CVE-2007-0947.
4478| [CVE-2007-0945] Microsoft Internet Explorer 6 SP1 on Windows 2000 SP4
4479| [CVE-2007-0944] Unspecified vulnerability in the CTableCol::OnPropertyChange method in Microsoft Internet Explorer 5.01 SP4 on Windows 2000 SP4
4480| [CVE-2007-0942] Microsoft Internet Explorer 5.01 SP4 on Windows 2000 SP4
4481| [CVE-2007-0940] Unspecified vulnerability in the Cryptographic API Component Object Model Certificates ActiveX control (CAPICOM.dll) in Microsoft CAPICOM and BizTalk Server 2004 SP1 and SP2 allows remote attackers to execute arbitrary code via unspecified vectors, aka the "CAPICOM.Certificates Vulnerability."
4482| [CVE-2007-0939] Cross-site scripting (XSS) vulnerability in Microsoft Content Management Server (MCMS) 2001 SP1 and 2002 SP2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving HTML redirection queries, aka "Cross-site Scripting and Spoofing Vulnerability."
4483| [CVE-2007-0938] Microsoft Content Management Server (MCMS) 2001 SP1 and 2002 SP2 does not properly handle certain characters in a crafted HTTP GET request, which allows remote attackers to execute arbitrary code, aka the "CMS Memory Corruption Vulnerability."
4484| [CVE-2007-0936] Multiple unspecified vulnerabilities in Microsoft Visio 2002 allow remote user-assisted attackers to execute arbitrary code via a Visio (.VSD, VSS, .VST) file with a crafted packed object that triggers memory corruption, aka "Visio Document Packaging Vulnerability."
4485| [CVE-2007-0934] Unspecified vulnerability in Microsoft Visio 2002 allows remote user-assisted attackers to execute arbitrary code via a Visio (.VSD, VSS, .VST) file with a crafted version number that triggers memory corruption.
4486| [CVE-2007-0913] Unspecified vulnerability in Microsoft Powerpoint allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as exploited by Trojan.PPDropper.G. NOTE: as of 20070213, it is not clear whether this is the same issue as CVE-2006-5296, CVE-2006-4694, CVE-2006-3876, CVE-2006-3877, or older issues.
4487| [CVE-2007-0870] Unspecified vulnerability in Microsoft Word 2000 allows remote attackers to cause a denial of service (crash) via unknown vectors, a different vulnerability than CVE-2006-5994, CVE-2006-6456, CVE-2006-6561, and CVE-2007-0515, a variant of Exploit-MS06-027.
4488| [CVE-2007-0843] The ReadDirectoryChangesW API function on Microsoft Windows 2000, XP, Server 2003, and Vista does not check permissions for child objects, which allows local users to bypass permissions by opening a directory with LIST (READ) access and using ReadDirectoryChangesW to monitor changes of files that do not have LIST permissions, which can be leveraged to determine filenames, access times, and other sensitive information.
4489| [CVE-2007-0811] Microsoft Internet Explorer 6.0 SP1 on Windows 2000, and 6.0 SP2 on Windows XP, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an HTML document containing a certain JavaScript for loop with an empty loop body, possibly involving getElementById.
4490| [CVE-2007-0671] Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as demonstrated by Exploit-MSExcel.h in targeted zero-day attacks.
4491| [CVE-2007-0612] Multiple ActiveX controls in Microsoft Windows 2000, XP, 2003, and Vista allows remote attackers to cause a denial of service (Internet Explorer crash) by accessing the bgColor, fgColor, linkColor, alinkColor, vlinkColor, or defaultCharset properties in the (1) giffile, (2) htmlfile, (3) jpegfile, (4) mhtmlfile, (5) ODCfile, (6) pjpegfile, (7) pngfile, (8) xbmfile, (9) xmlfile, (10) xslfile, or (11) wdfile objects in (a) mshtml.dll
4492| [CVE-2007-0515] Unspecified vulnerability in Microsoft Word allows user-assisted remote attackers to execute arbitrary code on Word 2000, and cause a denial of service on Word 2003, via unknown attack vectors that trigger memory corruption, as exploited by Trojan.Mdropper.W and later by Trojan.Mdropper.X, a different issue than CVE-2006-6456, CVE-2006-5994, and CVE-2006-6561.
4493| [CVE-2007-0351] Microsoft Windows XP and Windows Server 2003 do not properly handle user logoff, which might allow local users to gain the privileges of a previous system user, possibly related to user profile unload failure. NOTE: it is not clear whether this is an issue in Windows itself, or an interaction with another product. The issue might involve ZoneAlarm not being able to terminate processes when it cannot prompt the user.
4494| [CVE-2007-0221] Integer overflow in the IMAP (IMAP4) support in Microsoft Exchange Server 2000 SP3 allows remote attackers to cause a denial of service (service hang) via crafted literals in an IMAP command, aka the "IMAP Literal Processing Vulnerability."
4495| [CVE-2007-0220] Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2000 SP3, and 2003 SP1 and SP2 allows remote attackers to execute arbitrary scripts, spoof content, or obtain sensitive information via certain UTF-encoded, script-based e-mail attachments, involving an "incorrectly handled UTF character set label".
4496| [CVE-2007-0216] wkcvqd01.dll in Microsoft Works 6 File Converter, as used in Office 2003 SP2, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted section length headers, aka "Microsoft Works File Converter Input Validation Vulnerability."
4497| [CVE-2007-0215] Stack-based buffer overflow in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, and 2003 Viewer allows user-assisted remote attackers to execute arbitrary code via a .XLS BIFF file with a malformed Named Graph record, which results in memory corruption.
4498| [CVE-2007-0214] The HTML Help ActiveX control (Hhctrl.ocx) in Microsoft Windows 2000 SP3, XP SP2 and Professional, 2003 SP1 allows remote attackers to execute arbitrary code via unspecified functions, related to uninitialized parameters.
4499| [CVE-2007-0213] Microsoft Exchange Server 2000 SP3, 2003 SP1 and SP2, and 2007 does not properly decode certain MIME encoded e-mails, which allows remote attackers to execute arbitrary code via a crafted base64-encoded MIME e-mail message.
4500| [CVE-2007-0211] The hardware detection functionality in the Windows Shell in Microsoft Windows XP SP2 and Professional, and Server 2003 SP1 allows local users to gain privileges via an unvalidated parameter to a function related to the "detection and registration of new hardware."
4501| [CVE-2007-0209] Microsoft Word in Office 2000 SP3, XP SP3, Office 2003 SP2, Works Suite 2004 to 2006, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via a Word file with a malformed drawing object, which leads to memory corruption.
4502| [CVE-2007-0208] Microsoft Word in Office 2000 SP3, XP SP3, Office 2003 SP2, Works Suite 2004 to 2006, and Office 2004 for Mac does not correctly check the properties of certain documents and warn the user of macro content, which allows user-assisted remote attackers to execute arbitrary code.
4503| [CVE-2007-0069] Unspecified vulnerability in the kernel in Microsoft Windows XP SP2, Server 2003, and Vista allows remote attackers to cause a denial of service (CPU consumption) and possibly execute arbitrary code via crafted (1) IGMPv3 and (2) MLDv2 packets that trigger memory corruption, aka "Windows Kernel TCP/IP/IGMPv3 and MLDv2 Vulnerability."
4504| [CVE-2007-0066] The kernel in Microsoft Windows 2000 SP4, XP SP2, and Server 2003, when ICMP Router Discovery Protocol (RDP) is enabled, allows remote attackers to cause a denial of service via fragmented router advertisement ICMP packets that trigger an out-of-bounds read, aka "Windows Kernel TCP/IP/ICMP Vulnerability."
4505| [CVE-2007-0065] Heap-based buffer overflow in Object Linking and Embedding (OLE) Automation in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, Office 2004 for Mac, and Visual basic 6.0 SP6 allows remote attackers to execute arbitrary code via a crafted script request.
4506| [CVE-2007-0064] Heap-based buffer overflow in Windows Media Format Runtime 7.1, 9, 9.5, 9.5 x64 Edition, 11, and Windows Media Services 9.1 for Microsoft Windows 2000, XP, Server 2003, and Vista allows user-assisted remote attackers to execute arbitrary code via a crafted Advanced Systems Format (ASF) file.
4507| [CVE-2007-0043] The Just In Time (JIT) Compiler service in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows user-assisted remote attackers to execute arbitrary code via unspecified vectors involving an "unchecked buffer," probably a buffer overflow, aka ".NET JIT Compiler Vulnerability".
4508| [CVE-2007-0042] Interpretation conflict in ASP.NET in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows remote attackers to access configuration files and obtain sensitive information, and possibly bypass security mechanisms that try to constrain the final substring of a string, via %00 characters, related to use of %00 as a string terminator within POSIX functions but a data character within .NET strings, aka "Null Byte Termination Vulnerability."
4509| [CVE-2007-0041] The PE Loader service in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows remote attackers to execute arbitrary code via unspecified vectors involving an "unchecked buffer" and unvalidated message lengths, probably a buffer overflow.
4510| [CVE-2007-0040] The LDAP service in Windows Active Directory in Microsoft Windows 2000 Server SP4, Server 2003 SP1 and SP2, Server 2003 x64 Edition and SP2, and Server 2003 for Itanium-based Systems SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted LDAP request with an unspecified number of "convertible attributes."
4511| [CVE-2007-0039] The Exchange Collaboration Data Objects (EXCDO) functionality in Microsoft Exchange Server 2000 SP3, 2003 SP1 and SP2, and 2007 allows remote attackers to cause a denial of service (crash) via an Internet Calendar (iCal) file containing multiple X-MICROSOFT-CDO-MODPROPS (MODPROPS) properties in which the second MODPROPS is longer than the first, which triggers a NULL pointer dereference and an unhandled exception.
4512| [CVE-2007-0038] Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a large length value in the second (or later) anih block of a RIFF .ANI, cur, or .ico file, which results in memory corruption when processing cursors, animated cursors, and icons, a variant of CVE-2005-0416, as originally demonstrated using Internet Explorer 6 and 7. NOTE: this might be a duplicate of CVE-2007-1765
4513| [CVE-2007-0035] Word (or Word Viewer) in Microsoft Office 2000 SP3, XP SP3, 2003 SP2, 2004 for Mac, and Works Suite 2004, 2005, and 2006 does not properly handle data in a certain array, which allows user-assisted remote attackers to execute arbitrary code, aka the "Word Array Overflow Vulnerability."
4514| [CVE-2007-0034] Buffer overflow in the Advanced Search (Finder.exe) feature of Microsoft Outlook 2000, 2002, and 2003 allows user-assisted remote attackers to execute arbitrary code via a crafted Outlook Saved Searches (OSS) file that triggers memory corruption, aka "Microsoft Outlook Advanced Find Vulnerability."
4515| [CVE-2007-0033] Microsoft Outlook 2002 and 2003 allows user-assisted remote attackers to execute arbitrary code via a malformed VEVENT record in an .iCal meeting request or ICS file.
4516| [CVE-2007-0031] Heap-based buffer overflow in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows user-assisted remote attackers to execute arbitrary code via a BIFF8 spreadsheet with a PALETTE record that contains a large number of entries.
4517| [CVE-2007-0030] Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows user-assisted remote attackers to execute arbitrary code via an Excel file with an out-of-range Column field in certain BIFF8 record types, which references arbitrary memory.
4518| [CVE-2007-0029] Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows user-assisted remote attackers to execute arbitrary code via a malformed string, aka "Excel Malformed String Vulnerability."
4519| [CVE-2007-0028] Microsoft Excel 2000, 2002, 2003, Viewer 2003, Office 2004 for Mac, and Office v.X for Mac does not properly handle certain opcodes, which allows user-assisted remote attackers to execute arbitrary code via a crafted XLS file, which results in an "Improper Memory Access Vulnerability." NOTE: an early disclosure of this issue used CVE-2006-3432, but only CVE-2007-0028 should be used.
4520| [CVE-2007-0027] Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows remote attackers to execute arbitrary code via malformed IMDATA records that trigger memory corruption.
4521| [CVE-2007-0026] The OLE Dialog component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1 allows user-assisted remote attackers to execute arbitrary code via an RTF file with a malformed OLE object that triggers memory corruption.
4522| [CVE-2007-0025] The MFC component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1 and Visual Studio .NET 2000, 2002 SP1, 2003, and 2003 SP1 allows user-assisted remote attackers to execute arbitrary code via an RTF file with a malformed OLE object that triggers memory corruption. NOTE: this might be due to a stack-based buffer overflow in the AfxOleSetEditMenu function in MFC42u.dll.
4523| [CVE-2007-0024] Integer overflow in the Vector Markup Language (VML) implementation (vgx.dll) in Microsoft Internet Explorer 5.01, 6, and 7 on Windows 2000 SP4, XP SP2, Server 2003, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted web page that contains unspecified integer properties that cause insufficient memory allocation and trigger a buffer overflow, aka the "VML Buffer Overrun Vulnerability."
4524| [CVE-2006-7210] Microsoft Windows 2000, XP, and Server 2003 allows remote attackers to cause a denial of service (cpu consumption) via a PNG image with crafted (1) Width and (2) Height values in the IHDR block.
4525| [CVE-2006-7192] Microsoft ASP .NET Framework 2.0.50727.42 does not properly handle comment (/* */) enclosures, which allows remote attackers to bypass request filtering and conduct cross-site scripting (XSS) attacks, or cause a denial of service, as demonstrated via an xss:expression STYLE attribute in a closing XSS HTML tag.
4526| [CVE-2006-7027] Microsoft Internet Security and Acceleration (ISA) Server 2004 logs unusual ASCII characters in the Host header, including the tab, which allows remote attackers to manipulate portions of the log file and possibly leverage this for other attacks.
4527| [CVE-2006-6723] The Workstation service in Microsoft Windows 2000 SP4 and XP SP2 allows remote attackers to cause a denial of service (memory consumption) via a large maxlen value in an NetrWkstaUserEnum RPC request.
4528| [CVE-2006-6696] Double free vulnerability in Microsoft Windows 2000, XP, 2003, and Vista allows local users to gain privileges by calling the MessageBox function with a MB_SERVICE_NOTIFICATION message with crafted data, which sends a HardError message to Client/Server Runtime Server Subsystem (CSRSS) process, which is not properly handled when invoking the UserHardError and GetHardErrorText functions in WINSRV.DLL.
4529| [CVE-2006-6617] projectserver/logon/pdsrequest.asp in Microsoft Project Server 2003 allows remote authenticated users to obtain the MSProjectUser password for a SQL database via a GetInitializationData request, which includes the information in the UserName and Password tags of the response.
4530| [CVE-2006-6561] Unspecified vulnerability in Microsoft Word 2000, 2002, and Word Viewer 2003 allows user-assisted remote attackers to execute arbitrary code via a crafted DOC file that triggers memory corruption, as demonstrated via the 12122006-djtest.doc file, a different issue than CVE-2006-5994 and CVE-2006-6456.
4531| [CVE-2006-6456] Unspecified vulnerability in Microsoft Word 2000, 2002, and 2003 and Word Viewer 2003 allows remote attackers to execute code via unspecified vectors related to malformed data structures that trigger memory corruption, a different vulnerability than CVE-2006-5994.
4532| [CVE-2006-6296] The RpcGetPrinterData function in the Print Spooler (spoolsv.exe) service in Microsoft Windows 2000 SP4 and earlier, and possibly Windows XP SP1 and earlier, allows remote attackers to cause a denial of service (memory consumption) via an RPC request that specifies a large 'offered' value (output buffer size), a variant of CVE-2005-3644.
4533| [CVE-2006-6134] Heap-based buffer overflow in the WMCheckURLScheme function in WMVCORE.DLL in Microsoft Windows Media Player (WMP) 10.00.00.4036 on Windows XP SP2, Server 2003, and Server 2003 SP1 allows remote attackers to cause a denial of service (application crash) and execute arbitrary code via a long HREF attribute, using an unrecognized protocol, in a REF element in an ASX PlayList file.
4534| [CVE-2006-6133] Stack-based buffer overflow in Visual Studio Crystal Reports for Microsoft Visual Studio .NET 2002 and 2002 SP1, .NET 2003 and 2003 SP1, and 2005 and 2005 SP1 (formerly Business Objects Crystal Reports XI Professional) allows user-assisted remote attackers to execute arbitrary code via a crafted RPT file.
4535| [CVE-2006-5994] Unspecified vulnerability in Microsoft Word 2000 and 2002, Office Word and Word Viewer 2003, Word 2004 and 2004 v. X for Mac, and Works 2004, 2005, and 2006 allows remote attackers to execute arbitrary code via a Word document with a malformed string that triggers memory corruption, a different vulnerability than CVE-2006-6456.
4536| [CVE-2006-5758] The Graphics Rendering Engine in Microsoft Windows 2000 through 2000 SP4 and Windows XP through SP2 maps GDI Kernel structures on a global shared memory section that is mapped with read-only permissions, but can be remapped by other processes as read-write, which allows local users to cause a denial of service (memory corruption and crash) and gain privileges by modifying the kernel structures.
4537| [CVE-2006-5586] The Graphics Rendering Engine in Microsoft Windows 2000 SP4 and XP SP2 allows local users to gain privileges via "invalid application window sizes" in layered application windows, aka the "GDI Invalid Window Size Elevation of Privilege Vulnerability."
4538| [CVE-2006-5585] The Client-Server Run-time Subsystem in Microsoft Windows XP SP2 and Server 2003 allows local users to gain privileges via a crafted file manifest within an application, aka "File Manifest Corruption Vulnerability."
4539| [CVE-2006-5584] The Remote Installation Service (RIS) in Microsoft Windows 2000 SP4 uses a TFTP server that allows anonymous access, which allows remote attackers to upload and overwrite arbitrary files to gain privileges on systems that use RIS.
4540| [CVE-2006-5583] Buffer overflow in the SNMP Service in Microsoft Windows 2000 SP4, XP SP2, Server 2003, Server 2003 SP1, and possibly other versions allows remote attackers to execute arbitrary code via a crafted SNMP packet, aka "SNMP Memory Corruption Vulnerability."
4541| [CVE-2006-5574] Unspecified vulnerability in the Brazilian Portuguese Grammar Checker in Microsoft Office 2003 and the Multilingual Interface for Office 2003, Project 2003, and Visio 2003 allows user-assisted remote attackers to execute arbitrary code via crafted text that is not properly parsed.
4542| [CVE-2006-5296] PowerPoint in Microsoft Office 2003 does not properly handle a container object whose position value exceeds the record length, which allows user-assisted attackers to cause a denial of service (NULL dereference and application crash) via a crafted PowerPoint (.PPT) file, as demonstrated by Nanika.ppt, and a different vulnerability than CVE-2006-3435, CVE-2006-3876, CVE-2006-3877, and CVE-2006-4694. NOTE: the impact of this issue was originally claimed to be arbitrary code execution, but later analysis demonstrated that this was erroneous.
4543| [CVE-2006-4854] ** REJECT ** Unspecified vulnerability in Microsoft Office 2000 (Chinese Edition) and Microsoft PowerPoint 2000 (Chinese Edition) allows user-assisted attackers to execute arbitrary code via a crafted PPT document, as exploited by malware such as Trojan.PPDropper.E. NOTE: on 20060919, Microsoft notified CVE that this is a duplicate of CVE-2006-0009.
4544| [CVE-2006-4704] Cross-zone scripting vulnerability in the WMI Object Broker (WMIScriptUtils.WMIObjectBroker2) ActiveX control (WmiScriptUtils.dll) in Microsoft Visual Studio 2005 allows remote attackers to bypass Internet zone restrictions and execute arbitrary code by instantiating dangerous objects, aka "WMI Object Broker Vulnerability."
4545| [CVE-2006-4702] Buffer overflow in the Windows Media Format Runtime in Microsoft Windows Media Player (WMP) 6.4 and Windows XP SP2, Server 2003, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted Advanced Systems Format (ASF) file.
4546| [CVE-2006-4696] Unspecified vulnerability in the Server service in Microsoft Windows 2000 SP4, Server 2003 SP1 and earlier, and XP SP2 and earlier allows remote attackers to execute arbitrary code via a crafted packet, aka "SMB Rename Vulnerability."
4547| [CVE-2006-4695] Unspecified vulnerability in certain COM objects in Microsoft Office Web Components 2000 allows user-assisted remote attackers to execute arbitrary code via a crafted URL, aka "Office Web Components URL Parsing Vulnerability."
4548| [CVE-2006-4694] Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office XP and Office 2003 allows user-assisted attackers to execute arbitrary code via a crafted record in a PPT file, as exploited by malware such as Exploit:Win32/Controlppt.W, Exploit:Win32/Controlppt.X, and Exploit-PPT.d/Trojan.PPDropper.F. NOTE: it has been reported that the attack vector involves SlideShowWindows.View.GotoNamedShow.
4549| [CVE-2006-4693] Unspecified vulnerability in Microsoft Word 2004 for Mac and v.X for Mac allows remote user-assisted attackers to execute arbitrary code via a crafted string in a Word file, a different issue than CVE-2006-3647 and CVE-2006-3651.
4550| [CVE-2006-4692] Argument injection vulnerability in the Windows Object Packager (packager.exe) in Microsoft Windows XP SP1 and SP2 and Server 2003 SP1 and earlier allows remote user-assisted attackers to execute arbitrary commands via a crafted file with a "/" (slash) character in the filename of the Command Line property, followed by a valid file extension, which causes the command before the slash to be executed, aka "Object Packager Dialogue Spoofing Vulnerability."
4551| [CVE-2006-4691] Stack-based buffer overflow in the NetpManageIPCConnect function in the Workstation service (wkssvc.dll) in Microsoft Windows 2000 SP4 and XP SP2 allows remote attackers to execute arbitrary code via NetrJoinDomain2 RPC messages with a long hostname.
4552| [CVE-2006-4689] Unspecified vulnerability in the driver for the Client Service for NetWare (CSNW) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 allows remote attackers to cause a denial of service (hang and reboot) via has unknown attack vectors, aka "NetWare Driver Denial of Service Vulnerability."
4553| [CVE-2006-4688] Buffer overflow in Client Service for NetWare (CSNW) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 allows remote attackers to execute arbitrary code via crafted messages, aka "Client Service for NetWare Memory Corruption Vulnerability."
4554| [CVE-2006-4534] Unspecified vulnerability in Microsoft Word 2000, 2002, and Office 2003 allows remote user-assisted attackers to execute arbitrary code via unspecified vectors involving a crafted file resulting in a malformed stack, as exploited by malware with names including Trojan.Mdropper.Q, Mofei, and Femo.
4555| [CVE-2006-4495] Microsoft Internet Explorer allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code by instantiating certain Windows 2000 ActiveX COM Objects including (1) ciodm.dll, (2) myinfo.dll, (3) msdxm.ocx, and (4) creator.dll.
4556| [CVE-2006-4274] ** REJECT ** Unknown vulnerability in Microsoft PowerPoint allows user-assisted attackers to execute arbitrary code via a crafted PPT document, as exploited by malware such as TROJ_MDROPPER.BH. NOTE: on 20060822, it was determined that TROJ_MDROPPER.BH was exploiting CVE-2006-0009, so this is not a new vulnerability.
4557| [CVE-2006-4219] The Terminal Services COM object (tsuserex.dll) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by instantiating it as an ActiveX object in Internet Explorer 6.0 SP1 on Microsoft Windows 2003 EE SP1 CN.
4558| [CVE-2006-4183] Heap-based buffer overflow in Microsoft DirectX SDK (February 2006) and probably earlier, including 9.0c End User Runtimes, allows context-dependent attackers to execute arbitrary code via a crafted Targa file with a run-length-encoding (RLE) compression that produces more data than expected when decoding.
4559| [CVE-2006-4071] Sign extension vulnerability in the createBrushIndirect function in the GDI library (gdi32.dll) in Microsoft Windows XP, Server 2003, and possibly other versions, allows user-assisted attackers to cause a denial of service (application crash) via a crafted WMF file.
4560| [CVE-2006-3992] Unspecified vulnerability in the Centrino (1) w22n50.sys, (2) w22n51.sys, (3) w29n50.sys, and (4) w29n51.sys Microsoft Windows drivers for Intel 2200BG and 2915ABG PRO/Wireless Network Connection before 10.5 with driver 9.0.4.16 allows remote attackers to execute arbitrary code via certain frames that trigger memory corruption.
4561| [CVE-2006-3942] The server driver (srv.sys) in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause a denial of service (system crash) via an SMB_COM_TRANSACTION SMB message that contains a string without null character termination, which leads to a NULL dereference in the ExecuteTransaction function, possibly related to an "SMB PIPE," aka the "Mailslot DOS" vulnerability. NOTE: the name "Mailslot DOS" was derived from incomplete initial research
4562| [CVE-2006-3897] Stack overflow in Microsoft Internet Explorer 6 on Windows 2000 allows remote attackers to cause a denial of service (application crash) by creating an NMSA.ASFSourceMediaDescription.1 ActiveX object with a long dispValue property.
4563| [CVE-2006-3880] ** DISPUTED ** Microsoft Windows NT 4.0, Windows 2000, Windows XP, and Windows Small Business Server 2003 allow remote attackers to cause a denial of service (IP stack hang) via a continuous stream of packets on TCP port 135 that have incorrect TCP header checksums and random numbers in certain TCP header fields, as demonstrated by the Achilles Windows Attack Tool. NOTE: the researcher reports that the Microsoft Security Response Center has stated "Our investigation which has included code review, review of the TCPDump, and attempts on reproing the issue on multiple fresh installs of various Windows Operating Systems have all resulted in non confirmation."
4564| [CVE-2006-3877] Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office 2002, Office 2003, Office 2004 for Mac, and Office v.X for Mac allows user-assisted attackers to execute arbitrary code via an unspecified "crafted file," a different vulnerability than CVE-2006-3435, CVE-2006-4694, and CVE-2006-3876.
4565| [CVE-2006-3876] Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office 2002, Office 2003, Office 2004 for Mac, and Office v.X for Mac allows user-assisted attackers to execute arbitrary code via a crafted Data record in a PPT file, a different vulnerability than CVE-2006-3435 and CVE-2006-4694.
4566| [CVE-2006-3875] Unspecified vulnerability in Microsoft Excel 2000, 2002, 2003, 2004 for Mac, v.X for Mac, and Excel Viewer 2003 allows user-assisted attackers to execute arbitrary code via a crafted COLINFO record in an XLS file, a different vulnerability than CVE-2006-2387 and CVE-2006-3867.
4567| [CVE-2006-3873] Heap-based buffer overflow in URLMON.DLL in Microsoft Internet Explorer 6 SP1 on Windows 2000 and XP SP1, with versions the MS06-042 patch before 20060912, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long URL in a GZIP-encoded website that was the target of an HTTP redirect, due to an incomplete fix for CVE-2006-3869.
4568| [CVE-2006-3869] Heap-based buffer overflow in URLMON.DLL in Microsoft Internet Explorer 6 SP1 on Windows 2000 and XP SP1, with versions the MS06-042 patch before 20060824, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long URL on a website that uses HTTP 1.1 compression.
4569| [CVE-2006-3868] Unspecified vulnerability in Microsoft Office XP and 2003 allows remote user-assisted attackers to execute arbitrary code via a malformed Smart Tag.
4570| [CVE-2006-3867] Unspecified vulnerability in Microsoft Excel 2000, 2002, 2003, 2004 for Mac, v.X for Mac, and Excel Viewer 2003 allows user-assisted attackers to execute arbitrary code via a crafted Lotus 1-2-3 file, a different vulnerability than CVE-2006-2387 and CVE-2006-3875.
4571| [CVE-2006-3864] Unspecified vulnerability in mso.dll in Microsoft Office 2000, XP, and 2003, and Microsoft PowerPoint 2000, XP, and 2003, allows remote user-assisted attackers to execute arbitrary code via a malformed record in a (1) .DOC, (2) .PPT, or (3) .XLS file that triggers memory corruption, related to an "array boundary condition" (possibly an array index overflow), a different vulnerability than CVE-2006-3434, CVE-2006-3650, and CVE-2006-3868.
4572| [CVE-2006-3841] Cross-site scripting (XSS) vulnerability in WebScarab before 20060718-1904, when used with Microsoft Internet Explorer 6 SP2 or Konqueror 3.5.3, allows remote attackers to inject arbitrary web script or HTML via the URL, which is not sanitized before being returned in an error message when WebScarab is not able to access the URL.
4573| [CVE-2006-3660] Unspecified vulnerability in Microsoft PowerPoint 2003 has unknown impact and user-assisted attack vectors related to powerpnt.exe. NOTE: due to the lack of available details as of 20060717, it is unclear how this is related to CVE-2006-3655, CVE-2006-3656, and CVE-2006-3590, although it is possible that they are all different.
4574| [CVE-2006-3656] Unspecified vulnerability in Microsoft PowerPoint 2003 allows user-assisted attackers to cause memory corruption via a crafted PowerPoint file, which triggers the corruption when the file is closed. NOTE: due to the lack of available details as of 20060717, it is unclear how this is related to CVE-2006-3655, CVE-2006-3660, and CVE-2006-3590, although it is possible that they are all different.
4575| [CVE-2006-3655] Unspecified vulnerability in mso.dll in Microsoft PowerPoint 2003 allows user-assisted attackers to execute arbitrary code via a crafted PowerPoint file. NOTE: due to the lack of available details as of 20060717, it is unclear how this is related to CVE-2006-3656, CVE-2006-3660, and CVE-2006-3590, although it is possible that they are all different.
4576| [CVE-2006-3652] Microsoft Internet Security and Acceleration (ISA) Server 2004 allows remote attackers to bypass file extension filters via a request with a trailing "#" character. NOTE: as of 20060715, this could not be reproduced by third parties.
4577| [CVE-2006-3651] Unspecified vulnerability in Microsoft Word 2000, 2002, and Office 2003 allows remote user-assisted attackers to execute arbitrary code via a crafted mail merge file, a different vulnerability than CVE-2006-3647 and CVE-2006-4693.
4578| [CVE-2006-3650] Microsoft Office 2000, XP, 2003, 2004 for Mac, and v.X for Mac do not properly parse the length of a chart record, which allows remote user-assisted attackers to execute arbitrary code via a Word document with an embedded malformed chart record that triggers an overwrite of pointer values with values from the document, a different vulnerability than CVE-2006-3434, CVE-2006-3864, and CVE-2006-3868.
4579| [CVE-2006-3649] Buffer overflow in Microsoft Visual Basic for Applications (VBA) SDK 6.0 through 6.4, as used by Microsoft Office 2000 SP3, Office XP SP3, Project 2000 SR1, Project 2002 SP1, Access 2000 Runtime SP3, Visio 2002 SP2, and Works Suite 2004 through 2006, allows user-assisted attackers to execute arbitrary code via unspecified document properties that are not verified when VBA is invoked to open documents.
4580| [CVE-2006-3648] Unspecified vulnerability in Microsoft Windows 2000 SP4, XP SP1 and SP2, Server 2003 and 2003 SP1, allows remote attackers to execute arbitrary code via unspecified vectors involving unhandled exceptions, memory resident applications, and incorrectly "unloading chained exception."
4581| [CVE-2006-3647] Integer overflow in Microsoft Word 2000, 2002, 2003, 2004 for Mac, and v.X for Mac allows remote user-assisted attackers to execute arbitrary code via a crafted string in a Word document, which overflows a 16-bit integer length value, aka "Memmove Code Execution," a different vulnerability than CVE-2006-3651 and CVE-2006-4693.
4582| [CVE-2006-3643] Cross-site scripting (XSS) vulnerability in Internet Explorer 5.01 and 6 in Microsoft Windows 2000 SP4 permits access to local "HTML-embedded resource files" in the Microsoft Management Console (MMC) library, which allows remote authenticated users to execute arbitrary commands, aka "MMC Redirect Cross-Site Scripting Vulnerability."
4583| [CVE-2006-3590] mso.dll, as used by Microsoft PowerPoint 2000 through 2003, allows user-assisted attackers to execute arbitrary commands via a malformed shape container in a PPT file that leads to memory corruption, as exploited by Trojan.PPDropper.B, a different issue than CVE-2006-1540 and CVE-2006-3493.
4584| [CVE-2006-3510] The Remote Data Service Object (RDS.DataControl) in Microsoft Internet Explorer 6 on Windows 2000 allows remote attackers to cause a denial of service (crash) via a series of operations that result in an invalid length calculation when using SysAllocStringLen, then triggers a buffer over-read.
4585| [CVE-2006-3493] Buffer overflow in LsCreateLine function (mso_203) in mso.dll and mso9.dll, as used by Microsoft Word and possibly other products in Microsoft Office 2003, 2002, and 2000, allows remote user-assisted attackers to cause a denial of service (crash) via a crafted Word DOC or other Office file type. NOTE: this issue was originally reported to allow code execution, but on 20060710 Microsoft stated that code execution is not possible, and the original researcher agrees.
4586| [CVE-2006-3449] Unspecified vulnerability in Microsoft PowerPoint 2000 through 2003, possibly a buffer overflow, allows user-assisted remote attackers to execute arbitrary commands via a malformed record in the BIFF file format used in a PPT file, a different issue than CVE-2006-1540, aka "Microsoft PowerPoint Malformed Record Vulnerability."
4587| [CVE-2006-3448] Buffer overflow in the Step-by-Step Interactive Training in Microsoft Windows 2000 SP4, XP SP2 and Professional, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a long Syllabus string in crafted bookmark link files (cbo, cbl, or .cbm), a different issue than CVE-2005-1212.
4588| [CVE-2006-3445] Integer overflow in the ReadWideString function in agentdpv.dll in Microsoft Agent on Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 allows remote attackers to execute arbitrary code via a large length value in an .ACF file, which results in a heap-based buffer overflow.
4589| [CVE-2006-3444] Unspecified vulnerability in the kernel in Microsoft Windows 2000 SP4, probably a buffer overflow, allows local users to obtain privileges via unspecified vectors involving an "unchecked buffer."
4590| [CVE-2006-3443] Untrusted search path vulnerability in Winlogon in Microsoft Windows 2000 SP4, when SafeDllSearchMode is disabled, allows local users to gain privileges via a malicious DLL in the UserProfile directory, aka "User Profile Elevation of Privilege Vulnerability."
4591| [CVE-2006-3441] Buffer overflow in the DNS Client service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted record response. NOTE: while MS06-041 implies that there is a single issue, there are multiple vectors, and likely multiple vulnerabilities, related to (1) a heap-based buffer overflow in a DNS server response to the client, (2) a DNS server response with malformed ATMA records, and (3) a length miscalculation in TXT, HINFO, X25, and ISDN records.
4592| [CVE-2006-3440] Buffer overflow in the Winsock API in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via unknown vectors, aka "Winsock Hostname Vulnerability."
4593| [CVE-2006-3439] Buffer overflow in the Server Service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers, including anonymous users, to execute arbitrary code via a crafted RPC message, a different vulnerability than CVE-2006-1314.
4594| [CVE-2006-3436] Cross-site scripting (XSS) vulnerability in Microsoft .NET Framework 2.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving "ASP.NET controls that set the AutoPostBack property to true".
4595| [CVE-2006-3435] PowerPoint in Microsoft Office 2000, XP, 2003, 2004 for Mac, and v.X for Mac does not properly parse the slide notes field in a document, which allows remote user-assisted attackers to execute arbitrary code via crafted data in this field, which triggers an erroneous object pointer calculation that uses data from within the document. NOTE: this issue is different than other PowerPoint vulnerabilities including CVE-2006-4694.
4596| [CVE-2006-3434] Unspecified vulnerability in Microsoft Office 2000, XP, 2003, 2004 for Mac, and v.X for Mac allows remote user-assisted attackers to execute arbitrary code via a crafted string that triggers memory corruption.
4597| [CVE-2006-3431] Buffer overflow in certain Asian language versions of Microsoft Excel might allow user-assisted attackers to execute arbitrary code via a crafted STYLE record in a spreadsheet that triggers the overflow when the user attempts to repair the document or selects the "Style" option, as demonstrated by nanika.xls. NOTE: Microsoft has confirmed to CVE via e-mail that this is different than the other Excel vulnerabilities announced before 20060707, including CVE-2006-3059 and CVE-2006-3086.
4598| [CVE-2006-3059] Unspecified vulnerability in Microsoft Excel 2000 through 2004 allows remote user-assisted attackers to execute arbitrary code via unspecified vectors. NOTE: this is a different vulnerability than CVE-2006-3086.
4599| [CVE-2006-2492] Buffer overflow in Microsoft Word in Office 2000 SP3, Office XP SP3, Office 2003 Sp1 and SP2, and Microsoft Works Suites through 2006, allows user-assisted attackers to execute arbitrary code via a malformed object pointer, as originally reported by ISC on 20060519 for a zero-day attack.
4600| [CVE-2006-2389] Unspecified vulnerability in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via an Office file with a malformed property that triggers memory corruption related to record lengths, aka "Microsoft Office Property Vulnerability," a different vulnerability than CVE-2006-1316.
4601| [CVE-2006-2388] Microsoft Office Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via malformed cell comments, which lead to modification of "critical data offsets" during the rebuilding process.
4602| [CVE-2006-2387] Unspecified vulnerability in Microsoft Excel 2000, 2002, 2003, 2004 for Mac, v.X for Mac, Excel Viewer 2003, and Microsoft Works Suite 2004 through 2006 allows user-assisted attackers to execute arbitrary code via a crafted DATETIME record in an XLS file, a different vulnerability than CVE-2006-3867 and CVE-2006-3875.
4603| [CVE-2006-2380] Microsoft Windows 2000 SP4 does not properly validate an RPC server during mutual authentication over SSL, which allows remote attackers to spoof an RPC server, aka the "RPC Mutual Authentication Vulnerability."
4604| [CVE-2006-2379] Buffer overflow in the TCP/IP Protocol driver in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote attackers to execute arbitrary code via unknown vectors related to IP source routing.
4605| [CVE-2006-2378] Buffer overflow in the ART Image Rendering component (jgdw400.dll) in Microsoft Windows XP SP1 and Sp2, Server 2003 SP1 and earlier, and Windows 98 and Me allows remote attackers to execute arbitrary code via a crafted ART image that causes heap corruption.
4606| [CVE-2006-2374] The Server Message Block (SMB) driver (MRXSMB.SYS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows local users to cause a denial of service (hang) by calling the MrxSmbCscIoctlCloseForCopyChunk with the file handle of the shadow device, which results in a deadlock, aka the "SMB Invalid Handle Vulnerability."
4607| [CVE-2006-2373] The Server Message Block (SMB) driver (MRXSMB.SYS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows local users to execute arbitrary code by calling the MrxSmbCscIoctlOpenForCopyChunk function with the METHOD_NEITHER method flag and an arbitrary address, possibly for kernel memory, aka the "SMB Driver Elevation of Privilege Vulnerability."
4608| [CVE-2006-2372] Buffer overflow in the DHCP Client service for Microsoft Windows 2000 SP4, Windows XP SP1 and SP2, and Server 2003 up to SP1 allows remote attackers to execute arbitrary code via a crafted DHCP response.
4609| [CVE-2006-2371] Buffer overflow in the Remote Access Connection Manager service (RASMAN) service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote unauthenticated or authenticated attackers to execute arbitrary code via certain crafted "RPC related requests," that lead to registry corruption and stack corruption, aka the "RASMAN Registry Corruption Vulnerability."
4610| [CVE-2006-2370] Buffer overflow in the Routing and Remote Access service (RRAS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote unauthenticated or authenticated attackers to execute arbitrary code via certain crafted "RPC related requests," aka the "RRAS Memory Corruption Vulnerability."
4611| [CVE-2006-2334] The RtlDosPathNameToNtPathName_U API function in NTDLL.DLL in Microsoft Windows 2000 SP4 and XP SP2 does not properly convert DOS style paths with trailing spaces into NT style paths, which allows context-dependent attackers to create files that cannot be accessed through the expected DOS path or prevent access to other similarly named files in the same directory, which prevents those files from being detected or disinfected by certain anti-virus and anti-spyware software.
4612| [CVE-2006-2094] Microsoft Internet Explorer before Windows XP Service Pack 2 and Windows Server 2003 Service Pack 1, when Prompt is configured in Security Settings, uses modal dialogs to verify that a user wishes to run an ActiveX control or perform other risky actions, which allows user-assisted remote attackers to construct a race condition that tricks a user into clicking an object or pressing keys that are actually applied to a "Yes" approval for executing the control.
4613| [CVE-2006-2055] Argument injection vulnerability in Microsoft Outlook 2003 SP1 allows user-assisted remote attackers to modify command line arguments to an invoked mail client via " (double quote) characters in a mailto: scheme handler, as demonstrated by launching Microsoft Outlook with an arbitrary filename as an attachment. NOTE: it is not clear whether this issue is implementation-specific or a problem in the Microsoft API.
4614| [CVE-2006-1654] Directory traversal vulnerability in the HP Color LaserJet 2500 Toolbox and Color LaserJet 4600 Toolbox on Microsoft Windows before 20060402 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP GET request to TCP port 5225.
4615| [CVE-2006-1651] ** DISPUTED ** Microsoft ISA Server 2004 allows remote attackers to bypass certain filtering rules, including ones for (1) ICMP and (2) TCP, via IPv6 packets. NOTE: An established researcher has disputed this issue, saying that "Neither ISA Server 2004 nor Windows 2003 Basic Firewall support IPv6 filtering ... This is different network protocol."
4616| [CVE-2006-1540] MSO.DLL in Microsoft Office 2000, Office XP (2002), and Office 2003 allows user-assisted attackers to cause a denial of service and execute arbitrary code via multiple attack vectors, as originally demonstrated using a crafted document record with a malformed string, as demonstrated by replacing a certain "01 00 00 00" byte sequence with an "FF FF FF FF" byte sequence, possibly causing an invalid array index, in (1) an Excel .xls document, which triggers an access violation in ole32.dll
4617| [CVE-2006-1316] Unspecified vulnerability in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via an Office file with malformed string that triggers memory corruption related to record lengths, aka "Microsoft Office Parsing Vulnerability," a different vulnerability than CVE-2006-2389.
4618| [CVE-2006-1315] The Server Service (SRV.SYS driver) in Microsoft Windows 2000 SP4, XP SP1 and SP2, Server 2003 up to SP1, and other products, allows remote attackers to obtain sensitive information via crafted requests that leak information in SMB buffers, which are not properly initialized, aka "SMB Information Disclosure Vulnerability."
4619| [CVE-2006-1314] Heap-based buffer overflow in the Server Service (SRV.SYS driver) in Microsoft Windows 2000 SP4, XP SP1 and SP2, Server 2003 up to SP1, and other products, allows remote attackers to execute arbitrary code via crafted first-class Mailslot messages that triggers memory corruption and bypasses size restrictions on second-class Mailslot messages.
4620| [CVE-2006-1313] Microsoft JScript 5.1, 5.5, and 5.6 on Windows 2000 SP4, and 5.6 on Windows XP, Server 2003, Windows 98 and Windows Me, will "release objects early" in certain cases, which results in memory corruption and allows remote attackers to execute arbitrary code.
4621| [CVE-2006-1311] The RichEdit component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1
4622| [CVE-2006-1309] Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted LABEL record that triggers memory corruption.
4623| [CVE-2006-1308] Unspecified vulnerability in Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted FNGROUPCOUNT value.
4624| [CVE-2006-1306] Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted BIFF record with an attacker-controlled array index that is used for a function pointer, aka "Malformed OBJECT record Vulnerability."
4625| [CVE-2006-1305] Microsoft Outlook 2000, 2002, and 2003 allows user-assisted remote attackers to cause a denial of service (memory exhaustion and interrupted mail recovery) via malformed e-mail header information, possibly related to (1) long subject lines or (2) large numbers of recipients in To or CC headers.
4626| [CVE-2006-1304] Buffer overflow in Microsoft Excel 2000 through 2003 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted COLINFO record, which triggers the overflow during a "data filling operation."
4627| [CVE-2006-1302] Buffer overflow in Microsoft Excel 2000 through 2003 allows user-assisted attackers to execute arbitrary code via a .xls file with certain crafted fields in a SELECTION record, which triggers memory corruption, aka "Malformed SELECTION record Vulnerability."
4628| [CVE-2006-1301] Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted SELECTION record that triggers memory corruption, a different vulnerability than CVE-2006-1302.
4629| [CVE-2006-1300] Microsoft .NET framework 2.0 (ASP.NET) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1 allows remote attackers to bypass access restrictions via unspecified "URL paths" that can access Application Folder objects "explicitly by name."
4630| [CVE-2006-1257] The sample files in the authfiles directory in Microsoft Commerce Server 2002 before SP2 allow remote attackers to bypass authentication by logging in to authfiles/login.asp with a valid username and any password, then going to the main site twice.
4631| [CVE-2006-1193] Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2000 SP1 through SP3, when running Outlook Web Access (OWA), allows user-assisted remote attackers to inject arbitrary HTML or web script via unknown vectors related to "HTML parsing."
4632| [CVE-2006-1184] Microsoft Distributed Transaction Coordinator (MSDTC) for Windows NT 4.0, 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote attackers to cause a denial of service (crash) via a BuildContextW request with a large (1) UuidString or (2) GuidIn of a certain length, which causes an out-of-range memory access, aka the MSDTC Denial of Service Vulnerability. NOTE: this is a variant of CVE-2005-2119.
4633| [CVE-2006-0988] The default configuration of the DNS Server service on Windows Server 2003 and Windows 2000, and the Microsoft DNS Server service on Windows NT 4.0, allows recursive queries and provides additional delegation information to arbitrary IP addresses, which allows remote attackers to cause a denial of service (traffic amplification) via DNS queries with spoofed source IP addresses.
4634| [CVE-2006-0935] Microsoft Word 2003 allows remote attackers to cause a denial of service (application crash) via a crafted file, as demonstrated by 101_filefuzz.
4635| [CVE-2006-0187] By design, Microsoft Visual Studio 2005 automatically executes code in the Load event of a user-defined control (UserControl1_Load function), which allows user-assisted attackers to execute arbitrary code by tricking the user into opening a malicious Visual Studio project file.
4636| [CVE-2006-0034] Heap-based buffer overflow in the CRpcIoManagerServer::BuildContext function in msdtcprx.dll for Microsoft Distributed Transaction Coordinator (MSDTC) for Windows NT 4.0 and Windows 2000 SP2 and SP3 allows remote attackers to execute arbitrary code via a long fifth argument to the BuildContextW or BuildContext opcode, which triggers a bug in the NdrAllocate function, aka the MSDTC Invalid Memory Access Vulnerability.
4637| [CVE-2006-0033] Unspecified vulnerability in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via a crafted PNG image that triggers memory corruption when it is parsed.
4638| [CVE-2006-0032] Cross-site scripting (XSS) vulnerability in the Indexing Service in Microsoft Windows 2000, XP, and Server 2003, when the Encoding option is set to Auto Select, allows remote attackers to inject arbitrary web script or HTML via a UTF-7 encoded URL, which is injected into an error message whose charset is set to UTF-7.
4639| [CVE-2006-0031] Stack-based buffer overflow in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed record with a modified length value, which leads to memory corruption.
4640| [CVE-2006-0030] Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed graphic, which leads to memory corruption.
4641| [CVE-2006-0029] Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed description, which leads to memory corruption.
4642| [CVE-2006-0028] Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via a BIFF parsing format file containing malformed BOOLERR records that lead to memory corruption, probably involving invalid pointers.
4643| [CVE-2006-0023] Microsoft Windows XP SP1 and SP2 before August 2004, and possibly other operating systems and versions, uses insecure default ACLs that allow the Authenticated Users group to gain privileges by modifying critical configuration information for the (1) Simple Service Discovery Protocol (SSDP), (2) Universal Plug and Play Device Host (UPnP), (3) NetBT, (4) SCardSvr, (5) DHCP, and (6) DnsCache services, aka "Permissive Windows Services DACLs." NOTE: the NetBT, SCardSvr, DHCP, DnsCache already require privileged access to exploit.
4644| [CVE-2006-0022] Unspecified vulnerability in Microsoft PowerPoint in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP1 and SP2, Office 2004 for Mac, and v. X for Mac allows user-assisted attackers to execute arbitrary code via a PowerPoint document with a malformed record, which triggers memory corruption.
4645| [CVE-2006-0021] Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote attackers to cause a denial of service (hang) via an IGMP packet with an invalid IP option, aka the "IGMP v3 DoS Vulnerability."
4646| [CVE-2006-0020] An unspecified Microsoft WMF parsing application, as used in Internet Explorer 5.01 SP4 on Windows 2000 SP4, and 5.5 SP2 on Windows Millennium, and possibly other versions, allows attackers to cause a denial of service (crash) and possibly execute code via a crafted WMF file with a manipulated WMF header size, possibly involving an integer overflow, a different vulnerability than CVE-2005-4560, and aka "WMF Image Parsing Memory Corruption Vulnerability."
4647| [CVE-2006-0015] Cross-site scripting (XSS) vulnerability in _vti_bin/_vti_adm/fpadmdll.dll in Microsoft FrontPage Server Extensions 2002 and SharePoint Team Services allows remote attackers to inject arbitrary web script or HTML, then leverage the attack to execute arbitrary programs or create new accounts, via the (1) operation, (2) command, and (3) name parameters.
4648| [CVE-2006-0013] Buffer overflow in the Web Client service (WebClnt.dll) for Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote authenticated users or Guests to execute arbitrary code via crafted RPC requests, a different vulnerability than CVE-2005-1207.
4649| [CVE-2006-0012] Unspecified vulnerability in Windows Explorer in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via attack vectors involving COM objects and "crafted files and directories," aka the "Windows Shell Vulnerability."
4650| [CVE-2006-0010] Heap-based buffer overflow in T2EMBED.DLL in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1, Windows 98, and Windows ME allows remote attackers to execute arbitrary code via an e-mail message or web page with a crafted Embedded Open Type (EOT) web font that triggers the overflow during decompression.
4651| [CVE-2006-0009] Buffer overflow in Microsoft Office 2000 SP3, XP SP3, and other versions and packages, allows user-assisted attackers to execute arbitrary code via a routing slip that is longer than specified by the provided length field, as exploited by malware such as TROJ_MDROPPER.BH and Trojan.PPDropper.E in attacks against PowerPoint.
4652| [CVE-2006-0008] The ShellAbout API call in Korean Input Method Editor (IME) in Korean versions of Microsoft Windows XP SP1 and SP2, Windows Server 2003 up to SP1, and Office 2003, allows local users to gain privileges by launching the "shell about dialog box" and clicking the "End-User License Agreement" link, which executes Notepad with the privileges of the program that displays the about box.
4653| [CVE-2006-0007] Buffer overflow in GIFIMP32.FLT, as used in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via a crafted GIF image that triggers memory corruption when it is parsed.
4654| [CVE-2006-0006] Heap-based buffer overflow in the bitmap processing routine in Microsoft Windows Media Player 7.1 on Windows 2000 SP4, Media Player 9 on Windows 2000 SP4 and XP SP1, and Media Player 10 on XP SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted bitmap (.BMP) file that specifies a size of 0 but contains additional data.
4655| [CVE-2006-0004] Microsoft PowerPoint 2000 in Office 2000 SP3 has an interaction with Internet Explorer that allows remote attackers to obtain sensitive information via a PowerPoint presentation that attempts to access objects in the Temporary Internet Files Folder (TIFF).
4656| [CVE-2006-0002] Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment, related to message length validation.
4657| [CVE-2006-0001] Stack-based buffer overflow in Microsoft Publisher 2000 through 2003 allows user-assisted remote attackers to execute arbitrary code via a crafted PUB file, which causes an overflow when parsing fonts.
4658| [CVE-2005-4717] Microsoft Internet Explorer 6.0 on Windows NT 4.0 SP6a, Windows 2000 SP4, Windows XP SP1, Windows XP SP2, and Windows Server 2003 SP1 allows remote attackers to cause a denial of service (client crash) via a certain combination of a malformed HTML file and a CSS file that triggers a null dereference, probably related to rendering of a DIV element that contains a malformed IMG tag, as demonstrated by IEcrash.htm and IEcrash.rar.
4659| [CVE-2005-4269] mshtml.dll in Microsoft Windows XP, Server 2003, and Internet Explorer 6.0 SP1 allows attackers to cause a denial of service (access violation) by causing mshtml.dll to process button-focus events at the same time that a document is reloading, as seen in Microsoft Office InfoPath 2003 by repeatedly clicking the "Delete" button in a repeating section in a form. NOTE: the normal operation of InfoPath appears to involve a local user without any privilege boundaries, so this might not be a vulnerability in InfoPath. If no realistic scenarios exist for this problem in other products, then perhaps it should be excluded from CVE.
4660| [CVE-2005-4131] Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed range, which could lead to memory corruption involving an argument to the msvcrt.memmove function, aka "Brand new Microsoft Excel Vulnerability," as originally placed for sale on eBay as item number 7203336538.
4661| [CVE-2005-3981] ** DISPUTED ** NOTE: this issue has been disputed by third parties. Microsoft Windows XP, 2000, and 2003 allows local users to kill a writable process by using the CreateRemoteThread function with certain arguments on a process that has been opened using the OpenProcess function, possibly involving an invalid address for the start routine. NOTE: followup posts have disputed this issue, saying that if a user already has privileges to write to a process, then other functions could be called or the process could be terminated using PROCESS_TERMINATE.
4662| [CVE-2005-3945] The SynAttackProtect protection in Microsoft Windows 2003 before SP1 and Windows 2000 before SP4 with Update Roll-up uses a hash of predictable data, which allows remote attackers to cause a denial of service (CPU consumption) via a flood of SYN packets that produce identical hash values, which slows down the hash table lookups.
4663| [CVE-2005-3644] PNP_GetDeviceList (upnp_getdevicelist) in UPnP for Microsoft Windows 2000 SP4 and earlier, and possibly Windows XP SP1 and earlier, allows remote attackers to cause a denial of service (memory consumption) via a DCE RPC request that specifies a large output buffer size, a variant of CVE-2006-6296, and a different vulnerability than CVE-2005-2120.
4664| [CVE-2005-3177] CHKDSK in Microsoft Windows 2000 before Update Rollup 1 for SP4, Windows XP, and Windows Server 2003, when running in fix mode, does not properly handle security descriptors if the master file table contains a large number of files or if the descriptors do not satisfy certain NTFS conventions, which could cause ACLs for some files to be reverted to less secure defaults, or cause security descriptors to be removed.
4665| [CVE-2005-3176] Microsoft Windows 2000 before Update Rollup 1 for SP4 does not record the IP address of a Windows Terminal Services client in a security log event if the client connects successfully, which could make it easier for attackers to escape detection.
4666| [CVE-2005-3175] Microsoft Windows 2000 before Update Rollup 1 for SP4 allows a local administrator to unlock a computer even if it has been locked by a domain administrator, which allows the local administrator to access the session as the domain administrator.
4667| [CVE-2005-3174] Microsoft Windows 2000 before Update Rollup 1 for SP4 allows users to log on to the domain, even when their password has expired, if the fully qualified domain name (FQDN) is 8 characters long.
4668| [CVE-2005-3173] Microsoft Windows 2000 before Update Rollup 1 for SP4 does not apply group policies if the user logs on using UPN credentials with a trailing dot, which prevents Windows 2000 from finding the correct domain controller and could allow the user to bypass intended restrictions.
4669| [CVE-2005-3172] The WideCharToMultiByte function in Microsoft Windows 2000 before Update Rollup 1 for SP4 does not properly convert strings with Japanese composite characters in the last character, which could prevent the string from being null terminated and lead to data corruption or enable buffer overflow attacks.
4670| [CVE-2005-3171] Microsoft Windows 2000 before Update Rollup 1 for SP4 records Event ID 1704 to indicate that Group Policy security settings were successfully updated, even when the processing fails such as when Ntuser.pol cannot be accessed, which could cause system administrators to believe that the system is compliant with the specified settings.
4671| [CVE-2005-3170] The LDAP client on Microsoft Windows 2000 before Update Rollup 1 for SP4 accepts certificates using LDAP Secure Sockets Layer (LDAPS) even when the Certificate Authority (CA) is not trusted, which could allow attackers to trick users into believing that they are accessing a trusted site.
4672| [CVE-2005-3169] Microsoft Windows 2000 before Update Rollup 1 for SP4, when the "audit directory service access" policy is enabled, does not record a 565 event message for File Delete Child operations on an Active Directory object in the security event log, which could allow attackers to conduct unauthorized activities without detection.
4673| [CVE-2005-3168] The SECEDIT command on Microsoft Windows 2000 before Update Rollup 1 for SP4, when using a security template to set Access Control Lists (ACLs) on folders, does not apply ACLs on folders that are listed after a long folder entry, which could result in less secure permissions than specified by the template.
4674| [CVE-2005-2122] Windows Shell for Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote attackers to execute arbitrary commands via a shortcut (.lnk) file with long font properties that lead to a buffer overflow in the Client/Server Runtime Server Subsystem (CSRSS), a different vulnerability than CVE-2005-2118.
4675| [CVE-2005-2120] Stack-based buffer overflow in the Plug and Play (PnP) service (UMPNPMGR.DLL) in Microsoft Windows 2000 SP4, and XP SP1 and SP2, allows remote or local authenticated attackers to execute arbitrary code via a large number of "\" (backslash) characters in a registry key name, which triggers the overflow in a wsprintfW function call.
4676| [CVE-2005-2118] Windows Shell for Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote user-assisted attackers to execute arbitrary commands via a crafted shortcut (.lnk) file with long font properties that lead to a buffer overflow when the user views the file's properties using Windows Explorer, a different vulnerability than CVE-2005-2122.
4677| [CVE-2005-2117] Web View in Windows Explorer on Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 does not properly handle certain HTML characters in preview fields, which allows remote user-assisted attackers to execute arbitrary code.
4678| [CVE-2005-1985] The Client Service for NetWare (CSNW) on Microsoft Windows 2000 SP4, XP SP1 and Sp2, and Server 2003 SP1 and earlier, allows remote attackers to execute arbitrary code due to an "unchecked buffer" when processing certain crafted network messages.
4679| [CVE-2005-1984] Buffer overflow in the Print Spooler service (Spoolsv.exe) for Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via a malicious message.
4680| [CVE-2005-1983] Stack-based buffer overflow in the Plug and Play (PnP) service for Microsoft Windows 2000 and Windows XP Service Pack 1 allows remote attackers to execute arbitrary code via a crafted packet, and local users to gain privileges via a malicious application, as exploited by the Zotob (aka Mytob) worm.
4681| [CVE-2005-1982] Unknown vulnerability in the PKINIT Protocol for Microsoft Windows 2000, Windows XP, and Windows Server 2003 could allow a local user to obtain information and spoof a server via a man-in-the-middle (MITM) attack between a client and a domain controller when PKINIT smart card authentication is being used.
4682| [CVE-2005-1981] Unknown vulnerability in Microsoft Windows 2000 Server and Windows Server 2003 domain controllers allows remote authenticated users to cause a denial of service (system crash) via a crafted Kerberos message.
4683| [CVE-2005-1907] The ISA Firewall service in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service (Wspsrv.exe crash) via a large amount of SecureNAT network traffic.
4684| [CVE-2005-1683] Buffer overflow in winword.exe 10.2627.6714 and earlier in Microsoft Word for the Macintosh, before SP3 for Word 2002, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted mcw file.
4685| [CVE-2005-1218] The Microsoft Windows kernel in Microsoft Windows 2000 Server, Windows XP, and Windows Server 2003 allows remote attackers to cause a denial of service (crash) via crafted Remote Desktop Protocol (RDP) requests.
4686| [CVE-2005-1216] Microsoft ISA Server 2000 allows remote attackers to connect to services utilizing the NetBIOS protocol via a NetBIOS connection with an ISA Server that uses the NetBIOS (all) predefined packet filter.
4687| [CVE-2005-1215] Microsoft ISA Server 2000 allows remote attackers to poison the ISA cache or bypass content restriction policies via a malformed HTTP request packet containing multiple Content-Length headers.
4688| [CVE-2005-1208] Integer overflow in Microsoft Windows 98, 2000, XP SP2 and earlier, and Server 2003 SP1 and earlier allows remote attackers to execute arbitrary code via a crafted compiled Help (.CHM) file with a large size field that triggers a heap-based buffer overflow, as demonstrated using a "ms-its:" URL in Internet Explorer.
4689| [CVE-2005-1207] Buffer overflow in the Web Client service in Microsoft Windows XP and Windows Server 2003 allows remote authenticated users to execute arbitrary code via a crafted WebDAV request containing special parameters.
4690| [CVE-2005-1206] Buffer overflow in the Server Message Block (SMB) functionality for Microsoft Windows 2000, XP SP1 and SP2, and Server 2003 and SP1 allows remote attackers to execute arbitrary code via unknown vectors, aka the "Server Message Block Vulnerability."
4691| [CVE-2005-1205] The Telnet client for Microsoft Windows XP, Windows Server 2003, and Windows Services for UNIX allows remote attackers to read sensitive environment variables via the NEW-ENVIRON option with a SEND ENV_USERVAR command.
4692| [CVE-2005-1052] Microsoft Outlook 2003 and Outlook Web Access (OWA) 2003 do not properly display comma separated addresses in the From field in an e-mail message, which could allow remote attackers to spoof e-mail addresses.
4693| [CVE-2005-0921] Microsoft Outlook 2002 Connector for IBM Lotus Domino 2.0 allows local users to save passwords and login credentials locally, even when password caching is disabled by a group policy.
4694| [CVE-2005-0820] Microsoft Office InfoPath 2003 SP1 includes sensitive information in the Manifest.xsf file in a custom .xsn form, which allows attackers to obtain printer and network information, obtain the database name, username, and password, or obtain the internal web server name.
4695| [CVE-2005-0738] Stack consumption vulnerability in Microsoft Exchange Server 2003 SP1 allows users to cause a denial of service (hang) by deleting or moving a folder with deeply nested subfolders, which causes Microsoft Exchange Information Store service (Store.exe) to hang as a result of a large number of recursive calls.
4696| [CVE-2005-0564] Stack-based buffer overflow in Microsoft Word 2000 and Word 2002, and Microsoft Works Suites 2000 through 2004, might allow remote attackers to execute arbitrary code via a .doc file with long font information.
4697| [CVE-2005-0558] Buffer overflow in Microsoft Word 2000, Word 2002, and Word 2003 allows remote attackers to execute arbitrary code via a crafted document.
4698| [CVE-2005-0551] Stack-based buffer overflow in WINSRV.DLL in the Client Server Runtime System (CSRSS) process of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application that provides console window information with a long FaceName value.
4699| [CVE-2005-0550] Buffer overflow in Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to cause a denial of service (i.e., system crash) via a malformed request, aka "Object Management Vulnerability".
4700| [CVE-2005-0545] Microsoft Windows XP Pro SP2 and Windows 2000 Server SP4 running Active Directory allow local users to bypass group policies that restrict access to hidden drives by using the browse feature in Office 10 applications such as Word or Excel, or using a flash drive. NOTE: this issue has been disputed in a followup post.
4701| [CVE-2005-0063] The document processing application used by the Windows Shell in Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by modifying the CLSID stored in a file so that it is processed by HTML Application Host (MSHTA), as demonstrated using a Microsoft Word document.
4702| [CVE-2005-0061] The kernel of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via certain access requests.
4703| [CVE-2005-0060] Buffer overflow in the font processing component of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application.
4704| [CVE-2005-0059] Buffer overflow in the Message Queuing component of Microsoft Windows 2000 and Windows XP SP1 allows remote attackers to execute arbitrary code via a crafted message.
4705| [CVE-2005-0058] Buffer overflow in the Telephony Application Programming Interface (TAPI) for Microsoft Windows 98, Windows 98 SE, Windows ME, Windows 2000, Windows XP, and Windows Server 2003 allows attackers elevate privileges or execute arbitrary code via a crafted message.
4706| [CVE-2005-0048] Microsoft Windows XP SP2 and earlier, 2000 SP3 and SP4, Server 2003, and older operating systems allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted IP packets with malformed options, aka the "IP Validation Vulnerability."
4707| [CVE-2004-2527] The local and remote desktop login screens in Microsoft Windows XP before SP2 and 2003 allow remote attackers to cause a denial of service (CPU and memory consumption) by repeatedly using the WinKey+"U" key combination, which causes multiple copies of Windows Utility Manager to be loaded more quickly than they can be closed when the copies detect that another instance is running.
4708| [CVE-2004-2482] Microsoft Outlook 2000 and 2003, when configured to use Microsoft Word 2000 or 2003 as the e-mail editor and when forwarding e-mail, does not properly handle an opening OBJECT tag that does not have a closing OBJECT tag, which causes Outlook to automatically download the URI in the data property of the OBJECT tag and might allow remote attackers to execute arbitrary code.
4709| [CVE-2004-2365] Memory leak in Microsoft Windows XP and Windows Server 2003 allows local users to cause a denial of service (memory exhaustion) by repeatedly creating and deleting directories using a non-standard tool such as smbmount.
4710| [CVE-2004-2339] ** DISPUTED ** Microsoft Windows 2000, XP, and possibly 2003 allows local users with the SeDebugPrivilege privilege to execute arbitrary code as kernel and read or write kernel memory via the NtSystemDebugControl function, which does not verify its pointer arguments. Note: this issue has been disputed, since Administrator privileges are typically required to exploit this issue, thus privilege boundaries are not crossed.
4711| [CVE-2004-1080] The WINS service (wins.exe) on Microsoft Windows NT Server 4.0, Windows 2000 Server, and Windows Server 2003 allows remote attackers to write to arbitrary memory locations and possibly execute arbitrary code via a modified memory pointer in a WINS replication packet to TCP port 42, aka the "Association Context Vulnerability."
4712| [CVE-2004-0963] Buffer overflow in Microsoft Word 2002 (10.6612.6714) SP3, and possibly other versions, allows remote attackers to cause a denial of service (application exception) and possibly execute arbitrary code in winword.exe via certain unexpected values in a .doc file, including (1) an offset that triggers an out-of-bounds memory access, (2) a certain value that causes a large memory copy as triggered by an integer conversion error, and other values.
4713| [CVE-2004-0897] The Indexing Service for Microsoft Windows XP and Server 2003 does not properly validate the length of a message, which allows remote attackers to execute arbitrary code via a buffer overflow attack.
4714| [CVE-2004-0892] Microsoft Proxy Server 2.0 and Microsoft ISA Server 2000 (which is included in Small Business Server 2000 and Small Business Server 2003 Premium Edition) allows remote attackers to spoof trusted Internet content on a specially crafted webpage via spoofed reverse DNS lookup results.
4715| [CVE-2004-0846] Unknown vulnerability in Microsoft Excel 2000, 2002, 2001 for Mac, and v.X for Mac allows remote attackers to execute arbitrary code via a malicious file containing certain parameters that are not properly validated.
4716| [CVE-2004-0840] The SMTP (Simple Mail Transfer Protocol) component of Microsoft Windows XP 64-bit Edition, Windows Server 2003, Windows Server 2003 64-bit Edition, and the Exchange Routing Engine component of Exchange Server 2003, allows remote attackers to execute arbitrary code via a malicious DNS response message containing length values that are not properly validated.
4717| [CVE-2004-0728] The Remote Control Client service in Microsoft's Systems Management Server (SMS) 2.50.2726.0 allows remote attackers to cause a denial of service (crash) via a data packet to TCP port 2702 that causes the server to read or write to an invalid memory address.
4718| [CVE-2004-0726] The Windows Media Player control in Microsoft Windows 2000 allows remote attackers to execute arbitrary script in the local computer zone via an ASX filename that contains javascript, which is executed in the local context in a preview panel.
4719| [CVE-2004-0575] Integer overflow in DUNZIP32.DLL for Microsoft Windows XP, Windows XP 64-bit Edition, Windows Server 2003, and Windows Server 2003 64-bit Edition allows remote attackers to execute arbitrary code via compressed (zipped) folders that involve an "unchecked buffer" and improper length validation.
4720| [CVE-2004-0574] The Network News Transfer Protocol (NNTP) component of Microsoft Windows NT Server 4.0, Windows 2000 Server, Windows Server 2003, Exchange 2000 Server, and Exchange Server 2003 allows remote attackers to execute arbitrary code via XPAT patterns, possibly related to improper length validation and an "unchecked buffer," leading to off-by-one and heap-based buffer overflows.
4721| [CVE-2004-0573] Buffer overflow in the converter for Microsoft WordPerfect 5.x on Office 2000, Office XP, Office 2003, and Works Suites 2001 through 2004 allows remote attackers to execute arbitrary code via a malicious document or website.
4722| [CVE-2004-0540] Microsoft Windows 2000, when running in a domain whose Fully Qualified Domain Name (FQDN) is exactly 8 characters long, does not prevent users with expired passwords from logging on to the domain.
4723| [CVE-2004-0503] Microsoft Outlook 2003 allows remote attackers to bypass the default zone restrictions and execute script within media files via a Rich Text Format (RTF) message containing an OLE object for the Windows Media Player, which bypasses Media Player's setting to disallow scripting and may lead to unprompted installation of an executable when exploited in conjunction with predictable-file-location exposures such as CVE-2004-0502.
4724| [CVE-2004-0379] Multiple cross-site scripting (XSS) vulnerabilities in Microsoft SharePoint Portal Server 2001 allow remote attackers to process arbitrary web content and steal cookies via certain server scripts.
4725| [CVE-2004-0284] Microsoft Internet Explorer 6.0, Outlook 2002, and Outlook 2003 allow remote attackers to cause a denial of service (CPU consumption), if "Do not save encrypted pages to disk" is disabled, via a web site or HTML e-mail that contains two null characters (%00) after the host name.
4726| [CVE-2004-0214] Buffer overflow in Microsoft Internet Explorer and Explorer on Windows XP SP1, WIndows 2000, Windows 98, and Windows Me may allow remote malicious servers to cause a denial of service (application crash) and possibly execute arbitrary code via long share names, as demonstrated using Samba.
4727| [CVE-2004-0211] The kernel for Microsoft Windows Server 2003 does not reset certain values in CPU data structures, which allows local users to cause a denial of service (system crash) via a malicious program.
4728| [CVE-2004-0210] The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters, possibly by modifying message length values and causing a buffer overflow.
4729| [CVE-2004-0209] Unknown vulnerability in the Graphics Rendering Engine processes of Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats that involve "an unchecked buffer."
4730| [CVE-2004-0208] The Virtual DOS Machine (VDM) subsystem of Microsoft Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows local users to access kernel memory and gain privileges via a malicious program that modified some system structures in a way that is not properly validated by privileged operating system functions.
4731| [CVE-2004-0207] "Shatter" style vulnerability in the Window Management application programming interface (API) for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows local users to gain privileges by using certain API functions to change properties of privileged programs using the SetWindowLong and SetWIndowLongPtr API functions.
4732| [CVE-2004-0206] Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to remotely execute arbitrary code or locally gain privileges via a malicious message or application that involves an "unchecked buffer," possibly a buffer overflow.
4733| [CVE-2004-0204] Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as used in Visual Studio .NET 2003 and Outlook 2003 with Business Contact Manager, Microsoft Business Solutions CRM 1.2, and other products, allows remote attackers to read and delete arbitrary files via ".." sequences in the dynamicimag argument to crystalimagehandler.aspx.
4734| [CVE-2004-0202] IDirectPlay4 Application Programming Interface (API) of Microsoft DirectPlay 7.0a thru 9.0b, as used in Windows Server 2003 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed packet.
4735| [CVE-2004-0201] Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, Me, NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary commands via a .CHM file with a large length field, a different vulnerability than CVE-2003-1041.
4736| [CVE-2004-0199] Help and Support Center in Microsoft Windows XP and Windows Server 2003 SP1 does not properly validate HCP URLs, which allows remote attackers to execute arbitrary code, as demonstrated using certain hcp:// URLs that access the DVD Upgrade capability (dvdupgrd.htm).
4737| [CVE-2004-0124] The DCOM RPC interface for Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause network communications via an "alter context" call that contains additional data, aka the "Object Identity Vulnerability."
4738| [CVE-2004-0121] Argument injection vulnerability in Microsoft Outlook 2002 does not sufficiently filter parameters of mailto: URLs when using them as arguments when calling OUTLOOK.EXE, which allows remote attackers to use script code in the Local Machine zone and execute arbitrary programs.
4739| [CVE-2004-0120] The Microsoft Secure Sockets Layer (SSL) library, as used in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service via malformed SSL messages.
4740| [CVE-2004-0116] An Activation function in the RPCSS Service involved with DCOM activation for Microsoft Windows 2000, XP, and 2003 allows remote attackers to cause a denial of service (memory consumption) via an activation request with a large length field.
4741| [CVE-2003-1378] Microsoft Outlook Express 6.0 and Outlook 2000, with the security zone set to Internet Zone, allows remote attackers to execute arbitrary programs via an HTML email with the CODEBASE parameter set to the program, a vulnerability similar to CAN-2002-0077.
4742| [CVE-2003-1106] The SMTP service in Microsoft Windows 2000 before SP4 allows remote attackers to cause a denial of service (crash or hang) via an e-mail message with a malformed time stamp in the FILETIME attribute.
4743| [CVE-2003-0908] The Utility Manager in Microsoft Windows 2000 executes winhlp32.exe with system privileges, which allows local users to execute arbitrary code via a "Shatter" style attack using a Windows message that accesses the context sensitive help button in the GUI, as demonstrated using the File Open dialog in the Help window, a different vulnerability than CVE-2004-0213.
4744| [CVE-2003-0906] Buffer overflow in the rendering for (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1 allows remote attackers to execute arbitrary code via a malformed WMF or EMF image.
4745| [CVE-2003-0904] Microsoft Exchange 2003 and Outlook Web Access (OWA), when configured to use NTLM authentication, does not properly reuse HTTP connections, which can cause OWA users to view mailboxes of other users when Kerberos has been disabled as an authentication method for IIS 6.0, e.g. when SharePoint Services 2.0 is installed.
4746| [CVE-2003-0839] Directory traversal vulnerability in the "Shell Folders" capability in Microsoft Windows Server 2003 allows remote attackers to read arbitrary files via .. (dot dot) sequences in a "shell:" link.
4747| [CVE-2003-0825] The Windows Internet Naming Service (WINS) for Microsoft Windows Server 2003, and possibly Windows NT and Server 2000, does not properly validate the length of certain packets, which allows attackers to cause a denial of service and possibly execute arbitrary code.
4748| [CVE-2003-0824] Unknown vulnerability in the SmartHTML interpreter (shtml.dll) in Microsoft FrontPage Server Extensions 2000 and 2002, and Microsoft SharePoint Team Services 2002, allows remote attackers to cause a denial of service (response failure) via a certain request.
4749| [CVE-2003-0822] Buffer overflow in the debug functionality in fp30reg.dll of Microsoft FrontPage Server Extensions (FPSE) 2000 and 2002 allows remote attackers to execute arbitrary code via a crafted chunked encoded request.
4750| [CVE-2003-0821] Microsoft Excel 97, 2000, and 2002 allows remote attackers to execute arbitrary code via a spreadsheet with a malicious XLM (Excel 4) macro that bypasses the macro security model.
4751| [CVE-2003-0820] Microsoft Word 97, 98(J), 2000, and 2002, and Microsoft Works Suites 2001 through 2004, do not properly check the length of the "Macro names" data value, which could allow remote attackers to execute arbitrary code via a buffer overflow attack.
4752| [CVE-2003-0819] Buffer overflow in the H.323 filter of Microsoft Internet Security and Acceleration Server 2000 allows remote attackers to execute arbitrary code in the Microsoft Firewall Service via certain H.323 traffic, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.
4753| [CVE-2003-0818] Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DLL, and other Microsoft executables and libraries on Windows NT 4.0, 2000, and XP, allow remote attackers to execute arbitrary code via ASN.1 BER encodings with (1) very large length fields that cause arbitrary heap data to be overwritten, or (2) modified bit strings.
4754| [CVE-2003-0807] Buffer overflow in the COM Internet Services and in the RPC over HTTP Proxy components for Microsoft Windows NT Server 4.0, NT 4.0 Terminal Server Edition, 2000, XP, and Server 2003 allows remote attackers to cause a denial of service via a crafted request.
4755| [CVE-2003-0806] Buffer overflow in the Windows logon process (winlogon) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1, when a member of a domain, allows remote attackers to execute arbitrary code.
4756| [CVE-2003-0719] Buffer overflow in the Private Communications Transport (PCT) protocol implementation in the Microsoft SSL library, as used in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via PCT 1.0 handshake packets.
4757| [CVE-2003-0665] Buffer overflow in the ActiveX control for Microsoft Access Snapshot Viewer for Access 97, 2000, and 2002 allows remote attackers to execute arbitrary code via long parameters to the control.
4758| [CVE-2003-0664] Microsoft Word 2002, 2000, 97, and 98(J) does not properly check certain properties of a document, which allows attackers to bypass the macro security model and automatically execute arbitrary macros via a malicious document.
4759| [CVE-2003-0662] Buffer overflow in Troubleshooter ActiveX Control (Tshoot.ocx) in Microsoft Windows 2000 SP4 and earlier allows remote attackers to execute arbitrary code via an HTML document with a long argument to the RunQuery2 method.
4760| [CVE-2003-0660] The Authenticode capability in Microsoft Windows NT through Server 2003 does not prompt the user to download and install ActiveX controls when the system is low on memory, which could allow remote attackers execute arbitrary code without user approval.
4761| [CVE-2003-0533] Stack-based buffer overflow in certain Active Directory service functions in LSASRV.DLL of the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via a packet that causes the DsRolerUpgradeDownlevelServer function to create long debug entries for the DCPROMO.LOG log file, as exploited by the Sasser worm.
4762| [CVE-2003-0526] Cross-site scripting (XSS) vulnerability in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to inject arbitrary web script via a URL containing the script in the domain name portion, which is not properly cleansed in the default error pages (1) 500.htm for "500 Internal Server error" or (2) 404.htm for "404 Not Found."
4763| [CVE-2003-0506] Microsoft NetMeeting 3.01 2000 before SP4 allows remote attackers to cause a denial of service (shutdown of NetMeeting conference) via malformed packets, as demonstrated via the chat conversation.
4764| [CVE-2003-0505] Directory traversal vulnerability in Microsoft NetMeeting 3.01 2000 before SP4 allows remote attackers to read arbitrary files via "..\.." (dot dot) sequences in a file transfer request.
4765| [CVE-2003-0496] Microsoft SQL Server before Windows 2000 SP4 allows local users to gain privileges as the SQL Server user by calling the xp_fileexist extended stored procedure with a named pipe as an argument instead of a normal file.
4766| [CVE-2003-0352] Buffer overflow in a certain DCOM interface for RPC in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary code via a malformed message, as exploited by the Blaster/MSblast/LovSAN and Nachi/Welchia worms.
4767| [CVE-2003-0345] Buffer overflow in the SMB capability for Microsoft Windows XP, 2000, and NT allows remote attackers to cause a denial of service and possibly execute arbitrary code via an SMB packet that specifies a smaller buffer length than is required.
4768| [CVE-2003-0232] Microsoft SQL Server 7, 2000, and MSDE allows local users to execute arbitrary code via a certain request to the Local Procedure Calls (LPC) port that leads to a buffer overflow.
4769| [CVE-2003-0231] Microsoft SQL Server 7, 2000, and MSDE allows local or remote authenticated users to cause a denial of service (crash or hang) via a long request to a named pipe.
4770| [CVE-2003-0230] Microsoft SQL Server 7, 2000, and MSDE allows local users to gain privileges by hijacking a named pipe during the authentication of another user, aka the "Named Pipe Hijacking" vulnerability.
4771| [CVE-2003-0227] The logging capability for unicast and multicast transmissions in the ISAPI extension for Microsoft Windows Media Services in Microsoft Windows NT 4.0 and 2000, nsiislog.dll, allows remote attackers to cause a denial of service in Internet Information Server (IIS) and execute arbitrary code via a certain network request.
4772| [CVE-2003-0118] SQL injection vulnerability in the Document Tracking and Administration (DTA) website of Microsoft BizTalk Server 2000 and 2002 allows remote attackers to execute operating system commands via a request to (1) rawdocdata.asp or (2) RawCustomSearchField.asp containing an embedded SQL statement.
4773| [CVE-2003-0117] Buffer overflow in the HTTP receiver function (BizTalkHTTPReceive.dll ISAPI) of Microsoft BizTalk Server 2002 allows attackers to execute arbitrary code via a certain request to the HTTP receiver.
4774| [CVE-2003-0110] The Winsock Proxy service in Microsoft Proxy Server 2.0 and the Microsoft Firewall service in Internet Security and Acceleration (ISA) Server 2000 allow remote attackers to cause a denial of service (CPU consumption or packet storm) via a spoofed, malformed packet to UDP port 1745.
4775| [CVE-2003-0109] Buffer overflow in ntdll.dll on Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute arbitrary code, as demonstrated via a WebDAV request to IIS 5.0.
4776| [CVE-2003-0011] Unknown vulnerability in the DNS intrusion detection application filter for Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service (blocked traffic to DNS servers) via a certain type of incoming DNS request that is not properly handled.
4777| [CVE-2003-0007] Microsoft Outlook 2002 does not properly handle requests to encrypt email messages with V1 Exchange Server Security certificates, which causes Outlook to send the email in plaintext, aka "Flaw in how Outlook 2002 handles V1 Exchange Server Security Certificates could lead to Information Disclosure."
4778| [CVE-2003-0003] Buffer overflow in the RPC Locator service for Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute arbitrary code via an RPC call to the service containing certain parameter information.
4779| [CVE-2003-0002] Cross-site scripting vulnerability (XSS) in ManualLogin.asp script for Microsoft Content Management Server (MCMS) 2001 allows remote attackers to execute arbitrary script via the REASONTXT parameter.
4780| [CVE-2002-2101] Microsoft Outlook 2002 allows remote attackers to execute arbitrary JavaScript code, even when scripting is disabled, via an "about:" or "javascript:" URI in the href attribute of an "a" tag.
4781| [CVE-2002-2100] Microsoft Outlook 2002 allows remote attackers to embed bypass the file download restrictions for attachments via an HTML email message that uses an IFRAME to reference malicious content.
4782| [CVE-2002-1984] Microsoft Internet Explorer 5.0.1 through 6.0 on Windows 2000 or Windows XP allows remote attackers to cause a denial of service (crash) via an OBJECT tag that contains a crafted CLASSID (CLSID) value of "CLSID:00022613-0000-0000-C000-000000000046".
4783| [CVE-2002-1981] Microsoft SQL Server 2000 through SQL Server 2000 SP2 allows the "public" role to execute the (1) sp_MSSetServerProperties or (2) sp_MSsetalertinfo stored procedures, which allows attackers to modify configuration including SQL server startup and alert settings.
4784| [CVE-2002-1933] The terminal services screensaver for Microsoft Windows 2000 does not automatically lock the terminal window if the window is minimized, which could allow local users to gain access to the terminal server window.
4785| [CVE-2002-1932] Microsoft Windows XP and Windows 2000, when configured to send administrative alerts and the "Do not overwrite events (clear log manually)" option is set, does not notify the administrator when the log reaches its maximum size, which allows local users and remote attackers to avoid detection.
4786| [CVE-2002-1876] Microsoft Exchange 2000 allows remote authenticated attackers to cause a denial of service via a large number of rapid requests, which consumes all of the licenses that are granted to Exchange by IIS.
4787| [CVE-2002-1873] Microsoft Exchange 2000, when used with Microsoft Remote Procedure Call (MSRPC), allows remote attackers to cause a denial of service (crash or memory consumption) via malformed MSRPC calls.
4788| [CVE-2002-1872] Microsoft SQL Server 6.0 through 2000, with SQL Authentication enabled, uses weak password encryption (XOR), which allows remote attackers to sniff and decrypt the password.
4789| [CVE-2002-1776] ** DISPUTED ** NOTE: this issue has been disputed by the vendor. Symantec Norton AntiVirus 2002 allows remote attackers to bypass virus protection via a Word Macro virus with a .nch or .dbx extension, which is automatically recognized and executed as a Microsoft Office document. NOTE: the vendor has disputed this issue, acknowledging that the initial scan is bypassed, but the Office plug-in would detect the virus before it is executed.
4790| [CVE-2002-1712] Microsoft Windows 2000 allows remote attackers to cause a denial of service (memory consumption) by sending a flood of empty TCP/IP packets with the ACK and FIN bits set to the NetBIOS port (TCP/139), as demonstrated by stream3.
4791| [CVE-2002-1256] The SMB signing capability in the Server Message Block (SMB) protocol in Microsoft Windows 2000 and Windows XP allows attackers to disable the digital signing settings in an SMB session to force the data to be sent unsigned, then inject data into the session without detection, e.g. by modifying group policy information sent from a domain controller.
4792| [CVE-2002-1255] Microsoft Outlook 2002 allows remote attackers to cause a denial of service (repeated failure) via an email message with a certain invalid header field that is accessed using POP3, IMAP, or WebDAV, aka "E-mail Header Processing Flaw Could Cause Outlook 2002 to Fail."
4793| [CVE-2002-1214] Buffer overflow in Microsoft PPTP Service on Windows XP and Windows 2000 allows remote attackers to cause a denial of service (hang) and possibly execute arbitrary code via a certain PPTP packet with malformed control data.
4794| [CVE-2002-1184] The system root folder of Microsoft Windows 2000 has default permissions of Everyone group with Full access (Everyone:F) and is in the search path when locating programs during login or application launch from the desktop, which could allow attackers to gain privileges as other users via Trojan horse programs.
4795| [CVE-2002-1145] The xp_runwebtask stored procedure in the Web Tasks component of Microsoft SQL Server 7.0 and 2000, Microsoft Data Engine (MSDE) 1.0, and Microsoft Desktop Engine (MSDE) 2000 can be executed by PUBLIC, which allows an attacker to gain privileges by updating a webtask that is owned by the database owner through the msdb.dbo.mswebtasks table, which does not have strong permissions.
4796| [CVE-2002-1141] An input validation error in the Sun Microsystems RPC library Services for Unix 3.0 Interix SD, as implemented on Microsoft Windows NT4, 2000, and XP, allows remote attackers to cause a denial of service via malformed fragmented RPC client packets, aka "Denial of service by sending an invalid RPC request."
4797| [CVE-2002-1140] The Sun Microsystems RPC library Services for Unix 3.0 Interix SD, as implemented on Microsoft Windows NT4, 2000, and XP, allows remote attackers to cause a denial of service (service hang) via malformed packet fragments, aka "Improper parameter size check leading to denial of service."
4798| [CVE-2002-1138] Microsoft SQL Server 7.0 and 2000, including Microsoft Data Engine (MSDE) 1.0 and Microsoft Desktop Engine (MSDE) 2000, writes output files for scheduled jobs under its own privileges instead of the entity that launched it, which allows attackers to overwrite system files, aka "Flaw in Output File Handling for Scheduled Jobs."
4799| [CVE-2002-1137] Buffer overflow in the Database Console Command (DBCC) that handles user inputs in Microsoft SQL Server 7.0 and 2000, including Microsoft Data Engine (MSDE) 1.0 and Microsoft Desktop Engine (MSDE) 2000, allows attackers to execute arbitrary code via a long SourceDB argument in a "non-SQL OLEDB data source" such as FoxPro, a variant of CAN-2002-0644.
4800| [CVE-2002-1123] Buffer overflow in the authentication function for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 allows remote attackers to execute arbitrary code via a long request to TCP port 1433, aka the "Hello" overflow.
4801| [CVE-2002-1117] Veritas Backup Exec 8.5 and earlier requires that the "RestrictAnonymous" registry key for Microsoft Exchange 2000 must be set to 0, which enables anonymous listing of the SAM database and shares.
4802| [CVE-2002-1056] Microsoft Outlook 2000 and 2002, when configured to use Microsoft Word as the email editor, does not block scripts that are used while editing email messages in HTML or Rich Text Format (RTF), which could allow remote attackers to execute arbitrary scripts via an email that the user forwards or replies to.
4803| [CVE-2002-0982] Microsoft SQL Server 2000 SP2, when configured as a distributor, allows attackers to execute arbitrary code via the @scriptfile parameter to the sp_MScopyscript stored procedure.
4804| [CVE-2002-0975] Buffer overflow in Microsoft DirectX Files Viewer ActiveX control (xweb.ocx) 2.0.6.15 and earlier allows remote attackers to execute arbitrary via a long File parameter.
4805| [CVE-2002-0863] Remote Data Protocol (RDP) version 5.0 in Microsoft Windows 2000 and RDP 5.1 in Windows XP does not encrypt the checksums of plaintext session data, which could allow a remote attacker to determine the contents of encrypted sessions via sniffing, aka "Weak Encryption in RDP Protocol."
4806| [CVE-2002-0861] Microsoft Office Web Components (OWC) 2000 and 2002 allows remote attackers to bypass the "Allow paste operations via script" setting, even when it is disabled, via the (1) Copy method of the Cell object or (2) the Paste method of the Range object.
4807| [CVE-2002-0860] The LoadText method in the spreadsheet component in Microsoft Office Web Components (OWC) 2000 and 2002 allows remote attackers to read arbitrary files through Internet Explorer via a URL that redirects to the target file.
4808| [CVE-2002-0859] Buffer overflow in the OpenDataSource function of the Jet engine on Microsoft SQL Server 2000 allows remote attackers to execute arbitrary code.
4809| [CVE-2002-0729] Microsoft SQL Server 2000 allows remote attackers to cause a denial of service via a malformed 0x08 packet that is missing a colon separator.
4810| [CVE-2002-0727] The Host function in Microsoft Office Web Components (OWC) 2000 and 2002 is exposed in components that are marked as safe for scripting, which allows remote attackers to execute arbitrary commands via the setTimeout method.
4811| [CVE-2002-0724] Buffer overflow in SMB (Server Message Block) protocol in Microsoft Windows NT, Windows 2000, and Windows XP allows attackers to cause a denial of service (crash) via a SMB_COM_TRANSACTION packet with a request for the (1) NetShareEnum, (2) NetServerEnum2, or (3) NetServerEnum3, aka "Unchecked Buffer in Network Share Provider Can Lead to Denial of Service".
4812| [CVE-2002-0721] Microsoft SQL Server 7.0 and 2000 installs with weak permissions for extended stored procedures that are associated with helper functions, which could allow unprivileged users, and possibly remote attackers, to run stored procedures with administrator privileges via (1) xp_execresultset, (2) xp_printstatements, or (3) xp_displayparamstmt.
4813| [CVE-2002-0719] SQL injection vulnerability in the function that services for Microsoft Content Management Server (MCMS) 2001 allows remote attackers to execute arbitrary commands via an MCMS resource request for image files or other files.
4814| [CVE-2002-0718] Web authoring command in Microsoft Content Management Server (MCMS) 2001 allows attackers to authenticate and upload executable content, by modifying the upload location, aka "Program Execution via MCMS Authoring Function."
4815| [CVE-2002-0700] Buffer overflow in a system function that performs user authentication for Microsoft Content Management Server (MCMS) 2001 allows attackers to execute code in the Local System context by authenticating to a web page that calls the function, aka "Unchecked Buffer in MDAC Function Could Enable SQL Server Compromise."
4816| [CVE-2002-0699] Unknown vulnerability in the Certificate Enrollment ActiveX Control in Microsoft Windows 98, Windows 98 Second Edition, Windows Millennium, Windows NT 4.0, Windows 2000, and Windows XP allow remote attackers to delete digital certificates on a user's system via HTML.
4817| [CVE-2002-0695] Buffer overflow in the Transact-SQL (T-SQL) OpenRowSet component of Microsoft Data Access Components (MDAC) 2.5 through 2.7 for SQL Server 7.0 or 2000 allows remote attackers to execute arbitrary code via a query that calls the OpenRowSet command.
4818| [CVE-2002-0694] The HTML Help facility in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP uses the Local Computer Security Zone when opening .chm files from the Temporary Internet Files folder, which allows remote attackers to execute arbitrary code via HTML mail that references or inserts a malicious .chm file containing shortcuts that can be executed, aka "Code Execution via Compiled HTML Help File."
4819| [CVE-2002-0693] Buffer overflow in the HTML Help ActiveX Control (hhctrl.ocx) in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute code via (1) a long parameter to the Alink function, or (2) script containing a long argument to the showHelp function.
4820| [CVE-2002-0692] Buffer overflow in SmartHTML Interpreter (shtml.dll) in Microsoft FrontPage Server Extensions (FPSE) 2000 and 2002 allows remote attackers to cause a denial of service (CPU consumption) or run arbitrary code, respectively, via a certain type of web file request.
4821| [CVE-2002-0650] The keep-alive mechanism for Microsoft SQL Server 2000 allows remote attackers to cause a denial of service (bandwidth consumption) via a "ping" style packet to the Resolution Service (UDP port 1434) with a spoofed IP address of another SQL Server system, which causes the two servers to exchange packets in an infinite loop.
4822| [CVE-2002-0649] Multiple buffer overflows in the Resolution Service for Microsoft SQL Server 2000 and Microsoft Desktop Engine 2000 (MSDE) allow remote attackers to cause a denial of service or execute arbitrary code via UDP packets to port 1434 in which (1) a 0x04 byte that causes the SQL Monitor thread to generate a long registry key name, or (2) a 0x08 byte with a long string causes heap corruption, as exploited by the Slammer/Sapphire worm.
4823| [CVE-2002-0645] SQL injection vulnerability in stored procedures for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 may allow authenticated users to execute arbitrary commands.
4824| [CVE-2002-0644] Buffer overflow in several Database Consistency Checkers (DBCCs) for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 allows members of the db_owner and db_ddladmin roles to execute arbitrary code.
4825| [CVE-2002-0643] The installation of Microsoft Data Engine 1.0 (MSDE 1.0), and Microsoft SQL Server 2000 creates setup.iss files with insecure permissions and does not delete them after installation, which allows local users to obtain sensitive data, including weakly encrypted passwords, to gain privileges, aka "SQL Server Installation Process May Leave Passwords on System."
4826| [CVE-2002-0642] The registry key containing the SQL Server service account information in Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, has insecure permissions, which allows local users to gain privileges, aka "Incorrect Permission on SQL Server Service Account Registry Key."
4827| [CVE-2002-0641] Buffer overflow in bulk insert procedure of Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, allows attackers with database administration privileges to execute arbitrary code via a long filename in the BULK INSERT query.
4828| [CVE-2002-0624] Buffer overflow in the password encryption function of Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, allows remote attackers to gain control of the database and execute arbitrary code via SQL Server Authentication, aka "Unchecked Buffer in Password Encryption Procedure."
4829| [CVE-2002-0623] Buffer overflow in AuthFilter ISAPI filter on Microsoft Commerce Server 2000 and 2002 allows remote attackers to execute arbitrary code via long authentication data, aka "New Variant of the ISAPI Filter Buffer Overrun".
4830| [CVE-2002-0622] The Office Web Components (OWC) package installer for Microsoft Commerce Server 2000 allows remote attackers to execute commands by passing the commands as input to the OWC package installer, aka "OWC Package Command Execution".
4831| [CVE-2002-0621] Buffer overflow in the Office Web Components (OWC) package installer used by Microsoft Commerce Server 2000 allows remote attackers to cause the process to fail or run arbitrary code in the LocalSystem security context via certain input to the OWC package installer.
4832| [CVE-2002-0620] Buffer overflow in the Profile Service of Microsoft Commerce Server 2000 allows remote attackers to cause the server to fail or run arbitrary code in the LocalSystem security context via an input field using an affected API.
4833| [CVE-2002-0619] The Mail Merge Tool in Microsoft Word 2002 for Windows, when Microsoft Access is present on a system, allows remote attackers to execute Visual Basic (VBA) scripts within a mail merge document that is saved in HTML format, aka a "Variant of MS00-071, Word Mail Merge Vulnerability" (CVE-2000-0788).
4834| [CVE-2002-0618] The Macro Security Model in Microsoft Excel 2000 and 2002 for Windows allows remote attackers to execute code in the Local Computer zone by embedding HTML scripts within an Excel workbook that contains an XSL stylesheet, aka "Excel XSL Stylesheet Script Execution".
4835| [CVE-2002-0617] The Macro Security Model in Microsoft Excel 2000 and 2002 for Windows allows remote attackers to execute code by creating a hyperlink on a drawing shape in a source workbook that points to a destination workbook containing an autoexecute macro, aka "Hyperlinked Excel Workbook Macro Bypass."
4836| [CVE-2002-0616] The Macro Security Model in Microsoft Excel 2000 and 2002 for Windows allows remote attackers to execute code by attaching an inline macro to an object within an Excel workbook, aka the "Excel Inline Macros Vulnerability."
4837| [CVE-2002-0597] LANMAN service on Microsoft Windows 2000 allows remote attackers to cause a denial of service (CPU/memory exhaustion) via a stream of malformed data to microsoft-ds port 445.
4838| [CVE-2002-0444] Microsoft Windows 2000 running the Terminal Server 90-day trial version, and possibly other versions, does not apply group policies to incoming users when the number of connections to the SYSVOL share exceeds the maximum, e.g. with a maximum number of licenses, which can allow remote authenticated users to bypass group policies.
4839| [CVE-2002-0443] Microsoft Windows 2000 allows local users to bypass the policy that prohibits reusing old passwords by changing the current password before it expires, which does not enable the check for previous passwords.
4840| [CVE-2002-0373] The Windows Media Device Manager (WMDM) Service in Microsoft Windows Media Player 7.1 on Windows 2000 systems allows local users to obtain LocalSystem rights via a program that calls the WMDM service to connect to an invalid local storage device, aka "Privilege Elevation through Windows Media Device Manager Service".
4841| [CVE-2002-0371] Buffer overflow in gopher client for Microsoft Internet Explorer 5.1 through 6.0, Proxy Server 2.0, or ISA Server 2000 allows remote attackers to execute arbitrary code via a gopher:// URL that redirects the user to a real or simulated gopher server that sends a long response.
4842| [CVE-2002-0368] The Store Service in Microsoft Exchange 2000 allows remote attackers to cause a denial of service (CPU consumption) via a mail message with a malformed RFC message attribute, aka "Malformed Mail Attribute can Cause Exchange 2000 to Exhaust CPU Resources."
4843| [CVE-2002-0224] The MSDTC (Microsoft Distributed Transaction Service Coordinator) for Microsoft Windows 2000, Microsoft IIS 5.0 and SQL Server 6.5 through SQL 2000 0.0 allows remote attackers to cause a denial of service (crash or hang) via malformed (random) input.
4844| [CVE-2002-0187] Cross-site scripting vulnerability in the SQLXML component of Microsoft SQL Server 2000 allows an attacker to execute arbitrary script via the root parameter as part of an XML SQL query, aka "Script Injection via XML Tag."
4845| [CVE-2002-0186] Buffer overflow in the SQLXML ISAPI extension of Microsoft SQL Server 2000 allows remote attackers to execute arbitrary code via data queries with a long content-type parameter, aka "Unchecked Buffer in SQLXML ISAPI Extension."
4846| [CVE-2002-0154] Buffer overflows in extended stored procedures for Microsoft SQL Server 7.0 and 2000 allow remote attackers to cause a denial of service or execute arbitrary code via a database query with certain long arguments.
4847| [CVE-2002-0152] Buffer overflow in various Microsoft applications for Macintosh allows remote attackers to cause a denial of service (crash) or execute arbitrary code by invoking the file:// directive with a large number of / characters, which affects Internet Explorer 5.1, Outlook Express 5.0 through 5.0.2, Entourage v. X and 2001, PowerPoint v. X, 2001, and 98, and Excel v. X and 2001 for Macintosh.
4848| [CVE-2002-0055] SMTP service in Microsoft Windows 2000, Windows XP Professional, and Exchange 2000 allows remote attackers to cause a denial of service via a command with a malformed data transfer (BDAT) request.
4849| [CVE-2002-0054] SMTP service in (1) Microsoft Windows 2000 and (2) Internet Mail Connector (IMC) in Exchange Server 5.5 does not properly handle responses to NTLM authentication, which allows remote attackers to perform mail relaying via an SMTP AUTH command using null session credentials.
4850| [CVE-2002-0050] Buffer overflow in AuthFilter ISAPI filter on Microsoft Commerce Server 2000 allows remote attackers to execute arbitrary code via long authentication data.
4851| [CVE-2002-0049] Microsoft Exchange Server 2000 System Attendant gives "Everyone" group privileges to the WinReg key, which could allow remote attackers to read or modify registry keys.
4852| [CVE-2002-0034] The Microsoft CONVERT.EXE program, when used on Windows 2000 and Windows XP systems, does not apply the default NTFS permissions when converting a FAT32 file system, which could cause the conversion to produce a file system with less secure permissions than expected.
4853| [CVE-2002-0018] In Microsoft Windows NT and Windows 2000, a trusting domain that receives authorization information from a trusted domain does not verify that the trusted domain is authoritative for all listed SIDs, which allows remote attackers to gain Domain Administrator privileges on the trusting domain by injecting SIDs from untrusted domains into the authorization data that comes from from the trusted domain.
4854| [CVE-2001-1533] ** DISPUTED * Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service via a flood of fragmented UDP packets. NOTE: the vendor disputes this issue, saying that it requires high bandwidth to exploit, and the server does not experience any instability. Therefore this "laws of physics" issue might not be included in CVE.
4855| [CVE-2001-1451] Memory leak in the SNMP LAN Manager (LANMAN) MIB extension for Microsoft Windows 2000 before SP3, when the Print Spooler is not running, allows remote attackers to cause a denial of service (memory consumption) via a large number of GET or GETNEXT requests.
4856| [CVE-2001-1319] Microsoft Exchange 5.5 2000 allows remote attackers to cause a denial of service (hang) via exceptional BER encodings for the LDAP filter type field, as demonstrated by the PROTOS LDAPv3 test suite.
4857| [CVE-2001-1099] The default configuration of Norton AntiVirus for Microsoft Exchange 2000 2.x allows remote attackers to identify the recipient's INBOX file path by sending an email with an attachment containing malicious content, which includes the path in the rejection notice.
4858| [CVE-2001-0986] SQLQHit.asp sample file in Microsoft Index Server 2.0 allows remote attackers to obtain sensitive information such as the physical path, file attributes, or portions of source code by directly calling sqlqhit.asp with a CiScope parameter set to (1) webinfo, (2) extended_fileinfo, (3) extended_webinfo, or (4) fileinfo.
4859| [CVE-2001-0718] Vulnerability in (1) Microsoft Excel 2002 and earlier and (2) Microsoft PowerPoint 2002 and earlier allows attackers to bypass macro restrictions and execute arbitrary commands by modifying the data stream in the document.
4860| [CVE-2001-0666] Outlook Web Access (OWA) in Microsoft Exchange 2000 allows an authenticated user to cause a denial of service (CPU consumption) via a malformed OWA request for a deeply nested folder within the user's mailbox.
4861| [CVE-2001-0658] Cross-site scripting (CSS) vulnerability in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause other clients to execute certain script or read cookies via malicious script in an invalid URL that is not properly quoted in an error message.
4862| [CVE-2001-0628] Microsoft Word 2000 does not check AutoRecovery (.asd) files for macros, which allows a local attacker to execute arbitrary macros with the user ID of the Word user.
4863| [CVE-2001-0547] Memory leak in the proxy service in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows local attackers to cause a denial of service (resource exhaustion).
4864| [CVE-2001-0546] Memory leak in H.323 Gatekeeper Service in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service (resource exhaustion) via a large amount of malformed H.323 data.
4865| [CVE-2001-0542] Buffer overflows in Microsoft SQL Server 7.0 and 2000 allow attackers with access to SQL Server to execute arbitrary code through the functions (1) raiserror, (2) formatmessage, or (3) xp_sprintf. NOTE: the C runtime format string vulnerability reported in MS01-060 is identified by CVE-2001-0879.
4866| [CVE-2001-0538] Microsoft Outlook View ActiveX Control in Microsoft Outlook 2002 and earlier allows remote attackers to execute arbitrary commands via a malicious HTML e-mail message or web page.
4867| [CVE-2001-0509] Vulnerabilities in RPC servers in (1) Microsoft Exchange Server 2000 and earlier, (2) Microsoft SQL Server 2000 and earlier, (3) Windows NT 4.0, and (4) Windows 2000 allow remote attackers to cause a denial of service via malformed inputs.
4868| [CVE-2001-0505] Multiple memory leaks in Microsoft Services for Unix 2.0 allow remote attackers to cause a denial of service (memory exhaustion) via a large number of malformed requests to (1) the Telnet service, or (2) the NFS service.
4869| [CVE-2001-0504] Vulnerability in authentication process for SMTP service in Microsoft Windows 2000 allows remote attackers to use incorrect credentials to gain privileges and conduct activites such as mail relaying.
4870| [CVE-2001-0501] Microsoft Word 2002 and earlier allows attackers to automatically execute macros without warning the user by embedding the macros in a manner that escapes detection by the security scanner.
4871| [CVE-2001-0351] Microsoft Windows 2000 telnet service allows a local user to make a certain system call that allows the user to terminate a Telnet session and cause a denial of service.
4872| [CVE-2001-0350] Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, which allows local users to execute arbitrary commands by creating a named pipe with the predictable name and associating a malicious program with it, the second of two variants of this vulnerability.
4873| [CVE-2001-0349] Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, which allows local users to execute arbitrary commands by creating a named pipe with the predictable name and associating a malicious program with it, the first of two variants of this vulnerability.
4874| [CVE-2001-0348] Microsoft Windows 2000 telnet service allows attackers to cause a denial of service (crash) via a long logon command that contains a backspace.
4875| [CVE-2001-0347] Information disclosure vulnerability in Microsoft Windows 2000 telnet service allows remote attackers to determine the existence of user accounts such as Guest, or log in to the server without specifying the domain name, via a malformed userid.
4876| [CVE-2001-0346] Handle leak in Microsoft Windows 2000 telnet service allows attackers to cause a denial of service by starting a large number of sessions and terminating them.
4877| [CVE-2001-0345] Microsoft Windows 2000 telnet service allows attackers to prevent idle Telnet sessions from timing out, causing a denial of service by creating a large number of idle sessions.
4878| [CVE-2001-0344] An SQL query method in Microsoft SQL Server 2000 Gold and 7.0 using Mixed Mode allows local database users to gain privileges by reusing a cached connection of the sa administrator account.
4879| [CVE-2001-0340] An interaction between the Outlook Web Access (OWA) service in Microsoft Exchange 2000 Server and Internet Explorer allows attackers to execute malicious script code against a user's mailbox via a message attachment that contains HTML code, which is executed automatically.
4880| [CVE-2001-0261] Microsoft Windows 2000 Encrypted File System does not properly destroy backups of files that are encrypted, which allows a local attacker to recover the text of encrypted files.
4881| [CVE-2001-0245] Microsoft Index Server 2.0 in Windows NT 4.0, and Indexing Service in Windows 2000, allows remote attackers to read server-side include files via a malformed search request, aka a new variant of the "Malformed Hit-Highlighting" vulnerability.
4882| [CVE-2001-0244] Buffer overflow in Microsoft Index Server 2.0 allows remote attackers to execute arbitrary commands via a long search parameter.
4883| [CVE-2001-0240] Microsoft Word before Word 2002 allows attackers to automatically execute macros without warning the user via a Rich Text Format (RTF) document that links to a template with the embedded macro.
4884| [CVE-2001-0239] Microsoft Internet Security and Acceleration (ISA) Server 2000 Web Proxy allows remote attackers to cause a denial of service via a long web request with a specific type.
4885| [CVE-2001-0237] Memory leak in Microsoft 2000 domain controller allows remote attackers to cause a denial of service by repeatedly connecting to the Kerberos service and then disconnecting without sending any data.
4886| [CVE-2001-0146] IIS 5.0 and Microsoft Exchange 2000 allow remote attackers to cause a denial of service (memory allocation error) by repeatedly sending a series of specially formatted URL's.
4887| [CVE-2001-0048] The "Configure Your Server" tool in Microsoft 2000 domain controllers installs a blank password for the Directory Service Restore Mode, which allows attackers with physical access to the controller to install malicious programs, aka the "Directory Service Restore Mode Password" vulnerability.
4888| [CVE-2001-0005] Buffer overflow in the parsing mechanism of the file loader in Microsoft PowerPoint 2000 allows attackers to execute arbitrary commands.
4889| [CVE-2001-0003] Web Extender Client (WEC) in Microsoft Office 2000, Windows 2000, and Windows Me does not properly process Internet Explorer security settings for NTLM authentication, which allows attackers to obtain NTLM credentials and possibly obtain the password, aka the "Web Client NTLM Authentication" vulnerability.
4890| [CVE-2000-1218] The default configuration for the domain name resolver for Microsoft Windows 98, NT 4.0, 2000, and XP sets the QueryIpMatching parameter to 0, which causes Windows to accept DNS updates from hosts that it did not query, which allows remote attackers to poison the DNS cache.
4891| [CVE-2000-1217] Microsoft Windows 2000 before Service Pack 2 (SP2), when running in a non-Windows 2000 domain and using NTLM authentication, and when credentials of an account are locally cached, allows local users to bypass account lockout policies and make an unlimited number of login attempts, aka the "Domain Account Lockout" vulnerability.
4892| [CVE-2000-1209] The "sa" account is installed with a default null password on (1) Microsoft SQL Server 2000, (2) SQL Server 7.0, and (3) Data Engine (MSDE) 1.0, including third party packages that use these products such as (4) Tumbleweed Secure Mail (MMS) (5) Compaq Insight Manager, and (6) Visio 2000, which allows remote attackers to gain privileges, as exploited by worms such as Voyager Alpha Force and Spida.
4893| [CVE-2000-1139] The installation of Microsoft Exchange 2000 before Rev. A creates a user account with a known password, which could allow attackers to gain privileges, aka the "Exchange User Account" vulnerability.
4894| [CVE-2000-1088] The xp_SetSQLSecurity function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.
4895| [CVE-2000-1087] The xp_proxiedmetadata function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.
4896| [CVE-2000-1086] The xp_printstatements function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.
4897| [CVE-2000-1085] The xp_peekqueue function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.
4898| [CVE-2000-1079] Interactions between the CIFS Browser Protocol and NetBIOS as implemented in Microsoft Windows 95, 98, NT, and 2000 allow remote attackers to modify dynamic NetBIOS name cache entries via a spoofed Browse Frame Request in a unicast or UDP broadcast datagram.
4899| [CVE-2000-0942] The CiWebHitsFile component in Microsoft Indexing Services for Windows 2000 allows remote attackers to conduct a cross site scripting (CSS) attack via a CiRestriction parameter in a .htw request, aka the "Indexing Services Cross Site Scripting" vulnerability.
4900| [CVE-2000-0854] When a Microsoft Office 2000 document is launched, the directory of that document is first used to locate DLL's such as riched20.dll and msi.dll, which could allow an attacker to execute arbitrary commands by inserting a Trojan Horse DLL into the same directory as the document.
4901| [CVE-2000-0771] Microsoft Windows 2000 allows local users to cause a denial of service by corrupting the local security policy via malformed RPC traffic, aka the "Local Security Policy Corruption" vulnerability.
4902| [CVE-2000-0765] Buffer overflow in the HTML interpreter in Microsoft Office 2000 allows an attacker to execute arbitrary commands via a long embedded object tag, aka the "Microsoft Office HTML Object Tag" vulnerability.
4903| [CVE-2000-0756] Microsoft Outlook 2000 does not properly process long or malformed fields in vCard (.vcf) files, which allows attackers to cause a denial of service.
4904| [CVE-2000-0710] The shtml.exe component of Microsoft FrontPage 2000 Server Extensions 1.1 allows remote attackers determine the physical path of the server components by requesting an invalid URL whose name includes a standard DOS device name.
4905| [CVE-2000-0709] The shtml.exe component of Microsoft FrontPage 2000 Server Extensions 1.1 allows remote attackers to cause a denial of service in some components by requesting a URL whose name includes a standard DOS device name.
4906| [CVE-2000-0637] Microsoft Excel 97 and 2000 allows an attacker to execute arbitrary commands by specifying a malicious .dll using the Register.ID function, aka the "Excel REGISTER.ID Function" vulnerability.
4907| [CVE-2000-0621] Microsoft Outlook 98 and 2000, and Outlook Express 4.0x and 5.0x, allow remote attackers to read files on the client's system via a malformed HTML message that stores files outside of the cache, aka the "Cache Bypass" vulnerability.
4908| [CVE-2000-0597] Microsoft Office 2000 (Excel and PowerPoint) and PowerPoint 97 are marked as safe for scripting, which allows remote attackers to force Internet Explorer or some email clients to save files to arbitrary locations via the Visual Basic for Applications (VBA) SaveAs function, aka the "Office HTML Script" vulnerability.
4909| [CVE-2000-0331] Buffer overflow in Microsoft command processor (CMD.EXE) for Windows NT and Windows 2000 allows a local user to cause a denial of service via a long environment variable, aka the "Malformed Environment Variable" vulnerability.
4910| [CVE-2000-0277] Microsoft Excel 97 and 2000 does not warn the user when executing Excel Macro Language (XLM) macros in external text files, which could allow an attacker to execute a macro virus, aka the "XLM Text Macro" vulnerability.
4911| [CVE-2013-2557] The sandbox protection mechanism in Microsoft Internet Explorer 9 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, as demonstrated against Adobe Flash Player by VUPEN during a Pwn2Own competition at CanSecWest 2013.
4912| [CVE-2013-2556] Unspecified vulnerability in Microsoft Windows 7 allows attackers to bypass the ASLR protection mechanism via unknown vectors, as demonstrated against Adobe Flash Player by VUPEN during a Pwn2Own competition at CanSecWest 2013.
4913| [CVE-2013-2554] Unspecified vulnerability in Microsoft Windows 7 allows attackers to bypass the ASLR and DEP protection mechanisms via unknown vectors, as demonstrated against Firefox by VUPEN during a Pwn2Own competition at CanSecWest 2013, a different vulnerability than CVE-2013-0787.
4914| [CVE-2013-2553] Unspecified vulnerability in the kernel in Microsoft Windows 7 allows local users to gain privileges via unknown vectors, as demonstrated by Nils and Jon of MWR Labs during a Pwn2Own competition at CanSecWest 2013, a different vulnerability than CVE-2013-0912.
4915| [CVE-2013-2552] Unspecified vulnerability in Microsoft Internet Explorer 10 on Windows 8 allows remote attackers to bypass the sandbox protection mechanism by leveraging access to a Medium integrity process, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2013.
4916| [CVE-2013-2551] Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2013, aka "Internet Explorer Use After Free Vulnerability," a different vulnerability than CVE-2013-1308 and CVE-2013-1309.
4917| [CVE-2013-1347] Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly allocated or (2) is deleted, as exploited in the wild in May 2013.
4918| [CVE-2013-1305] HTTP.sys in Microsoft Windows 8, Windows Server 2012, and Windows RT allows remote attackers to cause a denial of service (infinite loop) via a crafted HTTP header, aka "HTTP.sys Denial of Service Vulnerability."
4919| [CVE-2013-1290] Microsoft SharePoint Server 2013, in certain configurations involving legacy My Sites, does not properly establish default access controls for a SharePoint list, which allows remote authenticated users to bypass intended restrictions on reading list items via a direct request for a list's location, aka "Incorrect Access Rights Information Disclosure Vulnerability."
4920| [CVE-2013-1289] Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2010 SP1, Groove Server 2010 SP1, SharePoint Foundation 2010 SP1, and Office Web Apps 2010 SP1 allows remote attackers to inject arbitrary web script or HTML via a crafted string, aka "HTML Sanitization Vulnerability."
4921| [CVE-2013-1284] Race condition in the kernel in Microsoft Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages improper handling of objects in memory, aka "Kernel Race Condition Vulnerability."
4922| [CVE-2013-0096] Writer in Microsoft Windows Essentials 2011 and 2012 allows remote attackers to bypass proxy settings and overwrite arbitrary files via crafted URL parameters, aka "Windows Essentials Improper URI Handling Vulnerability."
4923| [CVE-2013-0086] Microsoft OneNote 2010 SP1 does not properly determine buffer sizes during memory allocation, which allows remote attackers to obtain sensitive information via a crafted OneNote file, aka "Buffer Size Validation Vulnerability."
4924| [CVE-2013-0085] Buffer overflow in Microsoft SharePoint Server 2010 SP1 and SharePoint Foundation 2010 SP1 allows remote attackers to cause a denial of service (W3WP process crash and site outage) via a crafted URL, aka "Buffer Overflow Vulnerability."
4925| [CVE-2013-0084] Directory traversal vulnerability in Microsoft SharePoint Server 2010 SP1 and SharePoint Foundation 2010 SP1 allows remote attackers to bypass intended read restrictions for content, and hijack user accounts, via a crafted URL, aka "SharePoint Directory Traversal Vulnerability."
4926| [CVE-2013-0083] Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2010 SP1 allows remote attackers to inject arbitrary web script or HTML via crafted content, leading to administrative command execution, aka "SharePoint XSS Vulnerability."
4927| [CVE-2013-0080] Microsoft SharePoint Server 2010 SP1 and SharePoint Foundation 2010 SP1 allow remote attackers to bypass intended read restrictions for content, and hijack user accounts, via a crafted URL, aka "Callback Function Vulnerability."
4928| [CVE-2013-0079] Microsoft Visio Viewer 2010 SP1 allows remote attackers to execute arbitrary code via a crafted Visio file that triggers incorrect memory allocation, aka "Visio Viewer Tree Object Type Confusion Vulnerability."
4929| [CVE-2013-0005] The WCF Replace function in the Open Data (aka OData) protocol implementation in Microsoft .NET Framework 3.5, 3.5 SP1, 3.5.1, and 4, and the Management OData IIS Extension on Windows Server 2012, allows remote attackers to cause a denial of service (resource consumption and daemon restart) via crafted values in HTTP requests, aka "Replace Denial of Service Vulnerability."
4930| [CVE-2012-4969] Use-after-free vulnerability in the CMshtmlEd::Exec function in mshtml.dll in Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code via a crafted web site, as exploited in the wild in September 2012.
4931| [CVE-2012-4792] Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not properly allocated or (2) is deleted, as demonstrated by a CDwnBindInfo object, and exploited in the wild in December 2012.
4932| [CVE-2012-3456] Heap-based buffer overflow in the read function in filters/words/msword-odf/wv2/src/styles.cpp in the Microsoft import filter in Calligra 2.4.3 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted ODF style in an ODF document. NOTE: this is the same vulnerability as CVE-2012-3455, but it was SPLIT by the CNA even though Calligra and KOffice share the same codebase.
4933| [CVE-2012-3455] Heap-based buffer overflow in the read function in filters/words/msword-odf/wv2/src/styles.cpp in the Microsoft import filter in KOffice 2.3.3 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted ODF style in an ODF document. NOTE: this is the same vulnerability as CVE-2012-3456, but it was SPLIT by the CNA even though Calligra and KOffice share the same codebase.
4934| [CVE-2012-2290] The client in EMC NetWorker Module for Microsoft Applications (NMM) 2.2.1, 2.3 before build 122, and 2.4 before build 375 allows remote attackers to execute arbitrary code by sending a crafted message over a TCP communication channel.
4935| [CVE-2012-2284] The (1) install and (2) upgrade processes in EMC NetWorker Module for Microsoft Applications (NMM) 2.2.1, 2.3 before build 122, and 2.4 before build 375, when Exchange Server is used, allow local users to read cleartext administrator credentials via unspecified vectors.
4936| [CVE-2012-1945] Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 allow local users to obtain sensitive information via an HTML document that loads a shortcut (aka .lnk) file for display within an IFRAME element, as demonstrated by a network share implemented by (1) Microsoft Windows or (2) Samba.
4937| [CVE-2012-1894] Microsoft Office for Mac 2011 uses world-writable permissions for the "Applications/Microsoft Office 2011/" directory and certain other directories, which allows local users to gain privileges by placing a Trojan horse executable file in one of these directories, aka "Office for Mac Improper Folder Permissions Vulnerability."
4938| [CVE-2012-1892] Cross-site scripting (XSS) vulnerability in Microsoft Visual Studio Team Foundation Server 2010 SP1 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka "XSS Vulnerability."
4939| [CVE-2012-1891] Heap-based buffer overflow in Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2 and Windows Data Access Components (WDAC) 6.0 allows remote attackers to execute arbitrary code via crafted XML data that triggers access to an uninitialized object in memory, aka "ADO Cachesize Heap Overflow RCE Vulnerability."
4940| [CVE-2012-1888] Buffer overflow in Microsoft Visio 2010 SP1 and Visio Viewer 2010 SP1 allows remote attackers to execute arbitrary code via a crafted Visio file, aka "Visio DXF File Format Buffer Overflow Vulnerability."
4941| [CVE-2012-1876] Microsoft Internet Explorer 6 through 9, and 10 Consumer Preview, does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by attempting to access a nonexistent object, leading to a heap-based buffer overflow, aka "Col Element Remote Code Execution Vulnerability," as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2012.
4942| [CVE-2012-1861] Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2010 Gold and SP1, SharePoint Foundation 2010 Gold and SP1, and Office Web Apps 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via crafted JavaScript elements in a URL, aka "SharePoint Script in Username Vulnerability."
4943| [CVE-2012-1859] Cross-site scripting (XSS) vulnerability in scriptresx.ashx in Microsoft SharePoint Server 2010 Gold and SP1, SharePoint Foundation 2010 Gold and SP1, and Office Web Apps 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via crafted JavaScript elements in a URL, aka "XSS scriptresx.ashx Vulnerability."
4944| [CVE-2012-1857] Cross-site scripting (XSS) vulnerability in the Enterprise Portal component in Microsoft Dynamics AX 2012 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "Dynamics AX Enterprise Portal XSS Vulnerability."
4945| [CVE-2012-1849] Untrusted search path vulnerability in Microsoft Lync 2010, 2010 Attendee, and 2010 Attendant allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .ocsmeet file, aka "Lync Insecure Library Loading Vulnerability."
4946| [CVE-2012-1545] Microsoft Internet Explorer 6 through 9, and 10 Consumer Preview, allows remote attackers to bypass Protected Mode or cause a denial of service (memory corruption) by leveraging access to a Low integrity process, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2012.
4947| [CVE-2012-1436] The Microsoft EXE file parser in AhnLab V3 Internet Security 2011.01.18.00, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an EXE file with a \2D\6C\68 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different EXE parser implementations.
4948| [CVE-2012-1435] The Microsoft EXE file parser in AhnLab V3 Internet Security 2011.01.18.00, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an EXE file with a \50\4B\4C\49\54\45 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different EXE parser implementations.
4949| [CVE-2012-1434] The Microsoft EXE file parser in AhnLab V3 Internet Security 2011.01.18.00, Emsisoft Anti-Malware 5.1.0.1, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an EXE file with a \19\04\00\10 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different EXE parser implementations.
4950| [CVE-2012-1433] The Microsoft EXE file parser in AhnLab V3 Internet Security 2011.01.18.00, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an EXE file with a \4a\46\49\46 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different EXE parser implementations.
4951| [CVE-2012-0447] Mozilla Firefox 4.x through 9.0, Thunderbird 5.0 through 9.0, and SeaMonkey before 2.7 do not properly initialize data for image/vnd.microsoft.icon images, which allows remote attackers to obtain potentially sensitive information by reading a PNG image that was created through conversion from an ICO image.
4952| [CVE-2012-0147] Microsoft Forefront Unified Access Gateway (UAG) 2010 SP1 and SP1 Update 1 does not properly configure the default web site, which allows remote attackers to obtain sensitive information via a crafted HTTPS request, aka "Unfiltered Access to UAG Default Website Vulnerability."
4953| [CVE-2012-0146] Open redirect vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 SP1 and SP1 Update 1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL, aka "UAG Blind HTTP Redirect Vulnerability."
4954| [CVE-2012-0145] Cross-site scripting (XSS) vulnerability in wizardlist.aspx in Microsoft Office SharePoint Server 2010 Gold and SP1 and SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via JavaScript sequences in a URL, aka "XSS in wizardlist.aspx Vulnerability."
4955| [CVE-2012-0144] Cross-site scripting (XSS) vulnerability in themeweb.aspx in Microsoft Office SharePoint Server 2010 Gold and SP1 and SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via JavaScript sequences in a URL, aka "XSS in themeweb.aspx Vulnerability."
4956| [CVE-2012-0138] Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitrary code via crafted attributes in a Visio file, aka "VSD File Format Memory Corruption Vulnerability," a different vulnerability than CVE-2012-0019, CVE-2012-0020, CVE-2012-0136, and CVE-2012-0137.
4957| [CVE-2012-0137] Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitrary code via crafted attributes in a Visio file, aka "VSD File Format Memory Corruption Vulnerability," a different vulnerability than CVE-2012-0019, CVE-2012-0020, CVE-2012-0136, and CVE-2012-0138.
4958| [CVE-2012-0136] Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitrary code via crafted attributes in a Visio file, aka "VSD File Format Memory Corruption Vulnerability," a different vulnerability than CVE-2012-0019, CVE-2012-0020, CVE-2012-0137, and CVE-2012-0138.
4959| [CVE-2012-0020] Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitrary code via crafted attributes in a Visio file, aka "VSD File Format Memory Corruption Vulnerability," a different vulnerability than CVE-2012-0019, CVE-2012-0136, CVE-2012-0137, and CVE-2012-0138.
4960| [CVE-2012-0019] Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitrary code via crafted attributes in a Visio file, aka "VSD File Format Memory Corruption Vulnerability," a different vulnerability than CVE-2012-0020, CVE-2012-0136, CVE-2012-0137, and CVE-2012-0138.
4961| [CVE-2012-0018] Microsoft Visio Viewer 2010 Gold and SP1 does not properly validate attributes in Visio files, which allows remote attackers to execute arbitrary code via a crafted file, aka "VSD File Format Memory Corruption Vulnerability."
4962| [CVE-2012-0017] Cross-site scripting (XSS) vulnerability in inplview.aspx in Microsoft SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via JavaScript sequences in a URL, aka "XSS in inplview.aspx Vulnerability."
4963| [CVE-2011-4695] Unspecified vulnerability in Microsoft Windows 7 SP1, when Java is installed, allows local users to bypass Internet Explorer sandbox restrictions and gain privileges via unknown vectors, as demonstrated by the White Phosphorus wp_ie_sandbox_escape module for Immunity CANVAS. NOTE: as of 20111207, this disclosure has no actionable information. However, because the module author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.
4964| [CVE-2011-2012] Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 does not properly validate session cookies, which allows remote attackers to cause a denial of service (IIS outage) via unspecified network traffic, aka "Null Session Cookie Crash."
4965| [CVE-2011-2010] The Microsoft Office Input Method Editor (IME) for Simplified Chinese in Microsoft Pinyin IME 2010, Office Pinyin SimpleFast Style 2010, and Office Pinyin New Experience Style 2010 does not properly restrict access to configuration options, which allows local users to gain privileges via the Microsoft Pinyin (aka MSPY) IME toolbar, aka "Pinyin IME Elevation Vulnerability."
4966| [CVE-2011-1969] Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 provides the MicrosoftClient.jar file containing a signed Java applet, which allows remote attackers to execute arbitrary code on client machines via unspecified vectors, aka "Poisoned Cup of Code Execution Vulnerability."
4967| [CVE-2011-1897] Cross-site scripting (XSS) vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Default Reflected XSS Vulnerability."
4968| [CVE-2011-1896] Cross-site scripting (XSS) vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "ExcelTable Reflected XSS Vulnerability."
4969| [CVE-2011-1895] CRLF injection vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 allows remote attackers to inject arbitrary HTTP headers, and conduct HTTP response splitting attacks and cross-site scripting (XSS) attacks, via unspecified vectors, aka "ExcelTable Response Splitting XSS Vulnerability."
4970| [CVE-2011-1891] Cross-site scripting (XSS) vulnerability in Microsoft Windows SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and SP1, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters in a request to a script, aka "Contact Details Reflected XSS Vulnerability."
4971| [CVE-2011-1890] Cross-site scripting (XSS) vulnerability in EditForm.aspx in Microsoft Office SharePoint Server 2010 and SharePoint Foundation 2010 allows remote attackers to inject arbitrary web script or HTML via a post, aka "Editform Script Injection Vulnerability."
4972| [CVE-2011-1889] The NSPLookupServiceNext function in the client in Microsoft Forefront Threat Management Gateway (TMG) 2010 allows remote attackers to execute arbitrary code via vectors involving unspecified requests, aka "TMG Firewall Client Memory Corruption Vulnerability."
4973| [CVE-2011-1417] Integer overflow in QuickLook, as used in Apple Mac OS X before 10.6.7 and MobileSafari in Apple iOS before 4.2.7 and 4.3.x before 4.3.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a Microsoft Office document with a crafted size field in the OfficeArtMetafileHeader, related to OfficeArtBlip, as demonstrated on the iPhone by Charlie Miller and Dion Blazakis during a Pwn2Own competition at CanSecWest 2011.
4974| [CVE-2011-1347] Unspecified vulnerability in Microsoft Internet Explorer 8 on Windows 7 allows remote attackers to bypass Protected Mode and create arbitrary files by leveraging access to a Low integrity process, as demonstrated by Stephen Fewer as the third of three chained vulnerabilities during a Pwn2Own competition at CanSecWest 2011.
4975| [CVE-2011-1346] Unspecified vulnerability in Microsoft Internet Explorer 8 on Windows 7 allows remote attackers to execute arbitrary code via unknown vectors, as demonstrated by Stephen Fewer as the second of three chained vulnerabilities during a Pwn2Own competition at CanSecWest 2011.
4976| [CVE-2011-1345] Microsoft Internet Explorer 6, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, as demonstrated by Stephen Fewer as the first of three chained vulnerabilities during a Pwn2Own competition at CanSecWest 2011, aka "Object Management Memory Corruption Vulnerability."
4977| [CVE-2011-1265] The Bluetooth Stack 2.1 in Microsoft Windows Vista SP1 and SP2 and Windows 7 Gold and SP1 does not prevent access to objects in memory that (1) were not properly initialized or (2) have been deleted, which allows remote attackers to execute arbitrary code via crafted Bluetooth packets, aka "Bluetooth Stack Vulnerability."
4978| [CVE-2011-0653] Cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint Server 2010 Gold and SP1, and SharePoint Foundation 2010, allows remote attackers to inject arbitrary web script or HTML via the URI, aka "XSS in SharePoint Calendar Vulnerability."
4979| [CVE-2011-0647] The irccd.exe service in EMC Replication Manager Client before 5.3 and NetWorker Module for Microsoft Applications 2.1.x and 2.2.x allows remote attackers to execute arbitrary commands via the RunProgram function to TCP port 6542.
4980| [CVE-2011-0627] Adobe Flash Player before 10.3.181.14 on Windows, Mac OS X, Linux, and Solaris and before 10.3.185.21 on Android allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content, as possibly exploited in the wild in May 2011 by a Microsoft Office document with an embedded .swf file.
4981| [CVE-2011-0037] Microsoft Malware Protection Engine before 1.1.6603.0, as used in Microsoft Malicious Software Removal Tool (MSRT), Windows Defender, Security Essentials, Forefront Client Security, Forefront Endpoint Protection 2010, and Windows Live OneCare, allows local users to gain privileges via a crafted value of an unspecified user registry key.
4982| [CVE-2011-0027] Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2, and Windows Data Access Components (WDAC) 6.0, does not properly validate memory allocation for internal data structures, which allows remote attackers to execute arbitrary code, possibly via a large CacheSize property that triggers an integer wrap and a buffer overflow, aka "ADO Record Memory Vulnerability." NOTE: this might be a duplicate of CVE-2010-1117 or CVE-2010-1118.
4983| [CVE-2011-0026] Integer signedness error in the SQLConnectW function in an ODBC API (odbc32.dll) in Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2, and Windows Data Access Components (WDAC) 6.0, allows remote attackers to execute arbitrary code via a long string in the Data Source Name (DSN) and a crafted szDSN argument, which bypasses a signed comparison and leads to a buffer overflow, aka "DSN Overflow Vulnerability."
4984| [CVE-2010-4643] Heap-based buffer overflow in Impress in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Truevision TGA (TARGA) file in an ODF or Microsoft Office document.
4985| [CVE-2010-4253] Heap-based buffer overflow in Impress in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file in an ODF or Microsoft Office document, as demonstrated by a PowerPoint (aka PPT) document.
4986| [CVE-2010-4121] ** DISPUTED ** The TCP-to-ODBC gateway in IBM Tivoli Provisioning Manager for OS Deployment 7.1.1.3 does not require authentication for SQL statements, which allows remote attackers to modify, create, or read database records via a session on TCP port 2020. NOTE: the vendor disputes this issue, stating that the "default Microsoft Access database is not password protected because it is intended to be used for evaluation purposes only."
4987| [CVE-2010-3967] Untrusted search path vulnerability in Microsoft Windows Movie Maker (WMM) 2.6 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a Movie Maker (MSWMM) file, aka "Insecure Library Loading Vulnerability."
4988| [CVE-2010-3962] Use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code via vectors related to Cascading Style Sheets (CSS) token sequences and the clip attribute, aka an "invalid flag reference" issue or "Uninitialized Memory Corruption Vulnerability," as exploited in the wild in November 2010.
4989| [CVE-2010-3936] Cross-site scripting (XSS) vulnerability in Signurl.asp in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, 2010 Update 1, and 2010 Update 2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "XSS in Signurl.asp Vulnerability."
4990| [CVE-2010-3889] Unspecified vulnerability in Microsoft Windows on 32-bit platforms allows local users to gain privileges via unknown vectors, as exploited in the wild in July 2010 by the Stuxnet worm, and identified by Microsoft researchers and other researchers.
4991| [CVE-2010-3888] Unspecified vulnerability in Microsoft Windows on 32-bit platforms allows local users to gain privileges via unknown vectors, as exploited in the wild in July 2010 by the Stuxnet worm, and identified by Kaspersky Lab researchers and other researchers.
4992| [CVE-2010-3497] Symantec Norton AntiVirus 2011 does not properly interact with the processing of hcp:// URLs by the Microsoft Help and Support Center, which makes it easier for remote attackers to execute arbitrary code via malware that is correctly detected by this product, but with a detection approach that occurs too late to stop the code execution. NOTE: the researcher indicates that a vendor response was received, stating that this issue "falls into the work of our Firewall and not our AV (per our methodology of layers of defense)."
4993| [CVE-2010-3454] Multiple off-by-one errors in the WW8DopTypography::ReadFromMem function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted typography information in a Microsoft Word .DOC file that triggers an out-of-bounds write.
4994| [CVE-2010-3453] The WW8ListManager::WW8ListManager function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 does not properly handle an unspecified number of list levels in user-defined list styles in WW8 data in a Microsoft Word document, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted .DOC file that triggers an out-of-bounds write.
4995| [CVE-2010-3141] Untrusted search path vulnerability in Microsoft PowerPoint 2010 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse pptimpconv.dll that is located in the same folder as a .odp, .pot, .potm, .potx, .ppa, .pps, .ppsm, .ppsx, .ppt, .pptm, .pptx, .pwz, .sldm, or .sldx file.
4996| [CVE-2010-2743] The kernel-mode drivers in Microsoft Windows XP SP3 do not properly perform indexing of a function-pointer table during the loading of keyboard layouts from disk, which allows local users to gain privileges via a crafted application, as demonstrated in the wild in July 2010 by the Stuxnet worm, aka "Win32k Keyboard Layout Vulnerability." NOTE: this might be a duplicate of CVE-2010-3888 or CVE-2010-3889.
4997| [CVE-2010-2734] Cross-site scripting (XSS) vulnerability in the mobile portal in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, 2010 Update 1, and 2010 Update 2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "XSS Issue on UAG Mobile Portal Website in Forefront Unified Access Gateway Vulnerability."
4998| [CVE-2010-2733] Cross-site scripting (XSS) vulnerability in the Web Monitor in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, 2010 Update 1, and 2010 Update 2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "UAG XSS Allows EOP Vulnerability."
4999| [CVE-2010-2732] Open redirect vulnerability in the web interface in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, 2010 Update 1, and 2010 Update 2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, aka "UAG Redirection Spoofing Vulnerability."
5000| [CVE-2010-2564] Buffer overflow in Microsoft Windows Movie Maker (WMM) 2.1, 2.6, and 6.0 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted project file, aka "Movie Maker Memory Corruption Vulnerability."
5001| [CVE-2010-1184] The Microsoft wireless keyboard uses XOR encryption with a key derived from the MAC address, which makes it easier for remote attackers to obtain keystroke information and inject arbitrary commands via a nearby wireless device, as demonstrated by Keykeriki 2.
5002| [CVE-2010-1118] Unspecified vulnerability in Internet Explorer 8 on Microsoft Windows 7 allows remote attackers to execute arbitrary code via unknown vectors, possibly related to a use-after-free issue, as demonstrated by Peter Vreugdenhil during a Pwn2Own competition at CanSecWest 2010.
5003| [CVE-2010-1117] Heap-based buffer overflow in Internet Explorer 8 on Microsoft Windows 7 allows remote attackers to discover the base address of a Windows .dll file, and possibly have unspecified other impact, via unknown vectors, as demonstrated by Peter Vreugdenhil during a Pwn2Own competition at CanSecWest 2010.
5004| [CVE-2010-0806] Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object, as exploited in the wild in March 2010, aka "Uninitialized Memory Corruption Vulnerability."
5005| [CVE-2010-0716] _layouts/Upload.aspx in the Documents module in Microsoft SharePoint before 2010 uses URLs with the same hostname and port number for a web site's primary files and individual users' uploaded files (aka attachments), which allows remote authenticated users to leverage same-origin relationships and conduct cross-site scripting (XSS) attacks by uploading TXT files, a related issue to CVE-2008-5026. NOTE: the vendor disputes the significance of this issue, because cross-domain isolation can be implemented when needed.
5006| [CVE-2009-3555] The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate renegotiation handshakes with an existing connection, which allows man-in-the-middle attackers to insert data into HTTPS sessions, and possibly other types of sessions protected by TLS or SSL, by sending an unauthenticated request that is processed retroactively by a server in a post-renegotiation context, related to a "plaintext injection" attack, aka the "Project Mogul" issue.
5007| [CVE-2008-5750] Argument injection vulnerability in Microsoft Internet Explorer 8 beta 2 on Windows XP SP3 allows remote attackers to execute arbitrary commands via the --renderer-path option in a chromehtml: URI.
5008| [CVE-2008-5556] ** DISPUTED ** The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 does not recognize attack patterns designed to operate against web pages that are encoded with utf-7, which allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks by injecting crafted utf-7 content. NOTE: the vendor reportedly disputes this issue, stating "Behaviour is by design."
5009| [CVE-2008-5555] Microsoft Internet Explorer 8.0 Beta 2 relies on the XDomainRequestAllowed HTTP header to authorize data exchange between domains, which allows remote attackers to bypass the product's XSS Filter protection mechanism, and conduct XSS and cross-domain attacks, by injecting this header after a CRLF sequence, related to "XDomainRequest Allowed Injection (XAI)." NOTE: the vendor has reportedly stated that the XSS Filter intentionally does not attempt to "address every conceivable XSS attack scenario."
5010| [CVE-2008-5554] The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 does not properly handle some HTTP headers that appear after a CRLF sequence in a URI, which allows remote attackers to bypass the XSS protection mechanism and conduct XSS or redirection attacks, as demonstrated by the (1) Location and (2) Set-Cookie HTTP headers. NOTE: the vendor has reportedly stated that the XSS Filter intentionally does not attempt to "address every conceivable XSS attack scenario."
5011| [CVE-2008-5553] The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 disables itself upon encountering a certain X-XSS-Protection HTTP header, which allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks by injecting this header after a CRLF sequence. NOTE: the vendor has reportedly stated that the XSS Filter intentionally does not attempt to "address every conceivable XSS attack scenario."
5012| [CVE-2008-5552] The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks via a CRLF sequence in conjunction with a crafted Content-Type header, as demonstrated by a header with a utf-7 charset value. NOTE: the vendor has reportedly stated that the XSS Filter intentionally does not attempt to "address every conceivable XSS attack scenario."
5013| [CVE-2008-5551] The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks by injecting data at two different positions within an HTML document, related to STYLE elements and the CSS expression property, aka a "double injection."
5014| [CVE-2008-5180] Microsoft Communicator, and Communicator in Microsoft Office 2010 beta, allows remote attackers to cause a denial of service (memory consumption) via a large number of SIP INVITE requests, which trigger the creation of many sessions.
5015| [CVE-2008-4211] Integer signedness error in (1) QuickLook in Apple Mac OS X 10.5.5 and (2) Office Viewer in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via a crafted Microsoft Excel file that triggers an out-of-bounds memory access, related to "handling of columns."
5016| [CVE-2007-5351] Unspecified vulnerability in Server Message Block Version 2 (SMBv2) signing support in Microsoft Windows Vista allows remote attackers to force signature re-computation and execute arbitrary code via a crafted SMBv2 packet, aka "SMBv2 Signing Vulnerability."
5017| [CVE-2007-2729] Comodo Firewall Pro 2.4.18.184 and Comodo Personal Firewall 2.3.6.81, and probably older Comodo Firewall versions, do not properly test for equivalence of process identifiers for certain Microsoft Windows API functions in the NT kernel 5.0 and greater, which allows local users to call these functions, and bypass firewall rules or gain privileges, via a modified identifier that is one, two, or three greater than the canonical identifier.
5018| [CVE-2007-1534] DFSR.exe in Windows Meeting Space in Microsoft Windows Vista remains available for remote connections on TCP port 5722 for 2 minutes after Windows Meeting Space is closed, which allows remote attackers to have an unknown impact by connecting to this port during the time window.
5019| [CVE-2007-0341] Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.8.1 and earlier, when Microsoft Internet Explorer 6 is used, allows remote attackers to inject arbitrary web script or HTML via a javascript: URI in a CSS style in the convcharset parameter to the top-level URI, a different vulnerability than CVE-2005-0992.
5020| [CVE-2006-5559] The Execute method in the ADODB.Connection 2.7 and 2.8 ActiveX control objects (ADODB.Connection.2.7 and ADODB.Connection.2.8) in the Microsoft Data Access Components (MDAC) 2.5 SP3, 2.7 SP1, 2.8, and 2.8 SP1 does not properly track freed memory when the second argument is a BSTR, which allows remote attackers to cause a denial of service (Internet Explorer crash) and possibly execute arbitrary code via certain strings in the second and third arguments.
5021| [CVE-2006-4686] Buffer overflow in the Extensible Stylesheet Language Transformations (XSLT) processing in Microsoft XML Parser 2.6 and XML Core Services 3.0 through 6.0 allows remote attackers to execute arbitrary code via a crafted Web page.
5022| [CVE-2006-4685] The XMLHTTP ActiveX control in Microsoft XML Parser 2.6 and XML Core Services 3.0 through 6.0 does not properly handle HTTP server-side redirects, which allows remote user-assisted attackers to access content from other domains.
5023| [CVE-2006-1359] Microsoft Internet Explorer 6 and 7 Beta 2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a certain createTextRange call on a checkbox object, which results in a dereference of an invalid table pointer.
5024| [CVE-2006-0761] Buffer overflow in BlackBerry Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server 2.2 and 4.0 before SP3 Hotfix 4 for IBM Lotus Domino, 3.6 before SP7 and 5.0 before SP3 Hotfix 3 for Microsoft Exchangem, and 4.0 for Novell GroupWise before SP3 Hotfix 1 might allow user-assisted remote attackers to execute arbitrary code on the server via a crafted Microsoft Word document that is opened on a wireless device.
5025| [CVE-2006-0753] Memory leak in Microsoft Internet Explorer 6 for Windows XP Service Pack 2 allows remote attackers to cause a denial of service (memory consumption) via JavaScript that uses setInterval to repeatedly call a function to set the value of window.status.
5026| [CVE-2006-0544] urlmon.dll in Microsoft Internet Explorer 7.0 beta 2 (aka 7.0.5296.0) allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a BGSOUND element with its SRC attribute set to "file://" followed by a large number of "-" (dash of hyphen) characters.
5027| [CVE-2006-0003] Unspecified vulnerability in the RDS.Dataspace ActiveX control, which is contained in ActiveX Data Objects (ADO) and distributed in Microsoft Data Access Components (MDAC) 2.7 and 2.8, allows remote attackers to execute arbitrary code via unknown attack vectors.
5028| [CVE-2005-1929] Multiple heap-based buffer overflows in (1) isaNVWRequest.dll and (2) relay.dll in Trend Micro ServerProtect Management Console 5.58 and earlier, as used in Control Manager 2.5 and 3.0 and Damage Cleanup Server 1.1, allow remote attackers to execute arbitrary code via "wrapped" length values in Chunked transfer requests. NOTE: the original report suggests that the relay.dll issue is related to a problem in which a Microsoft Foundation Classes (MFC) static library returns invalid values under heavy load. As such, this might not be a vulnerability in Trend Micro's product.
5029| [CVE-2005-0852] Microsoft Windows XP SP1 allows local users to cause a denial of service (system crash) via an empty datagram to a raw IP over IP socket (IP protocol 4), as originally demonstrated using code in Python 2.3.
5030| [CVE-2004-1322] Cisco Unity 2.x, 3.x, and 4.x, when integrated with Microsoft Exchange, has several hard coded usernames and passwords, which allows remote attackers to gain unauthorized access and change configuration settings or read outgoing or incoming e-mail messages.
5031| [CVE-2003-1306] Microsoft URLScan 2.5, with the RemoveServerHeader option enabled, allows remote attackers to obtain sensitive information (server name and version) via an HTTP request that generates certain errors such as 400 "Bad Request," which leak the Server header in the response.
5032| [CVE-2003-0903] Buffer overflow in a component of Microsoft Data Access Components (MDAC) 2.5 through 2.8 allows remote attackers to execute arbitrary code via a malformed UDP response to a broadcast request.
5033| [CVE-2003-0353] Buffer overflow in a component of SQL-DMO for Microsoft Data Access Components (MDAC) 2.5 through 2.7 allows remote attackers to execute arbitrary code via a long response to a broadcast request to UDP port 1434.
5034| [CVE-2002-1918] Buffer overflow in Microsoft Active Data Objects (ADO) in Microsoft MDAC 2.5 through 2.7 allows remote attackers to have unknown impact with unknown attack vectors. NOTE: due to the lack of details available regarding this issue, perhaps it should be REJECTED.
5035| [CVE-2002-1142] Heap-based buffer overflow in the Remote Data Services (RDS) component of Microsoft Data Access Components (MDAC) 2.1 through 2.6, and Internet Explorer 5.01 through 6.0, allows remote attackers to execute code via a malformed HTTP request to the Data Stub.
5036| [CVE-2002-1015] RealJukebox 2 1.0.2.340 and 1.0.2.379, and RealOne Player Gold 6.0.10.505, allows remote attackers to execute arbitrary script in the Local computer zone by inserting the script into the skin.ini file of an RJS archive, then referencing skin.ini from a web page after it has been extracted, which is parsed as HTML by Internet Explorer or other Microsoft-based web readers.
5037| [CVE-2002-0697] Microsoft Metadirectory Services (MMS) 2.2 allows remote attackers to bypass authentication and modify sensitive data by using an LDAP client to directly connect to MMS and bypass the checks for MMS credentials.
5038| [CVE-2002-0057] XMLHTTP control in Microsoft XML Core Services 2.6 and later does not properly handle IE Security Zone settings, which allows remote attackers to read arbitrary files by specifying a local file as an XML Data Source.
5039| [CVE-2001-1218] Microsoft Internet Explorer for Unix 5.0SP1 allows local users to possibly cause a denial of service (crash) in CDE or the X server on Solaris 2.6 by rapidly scrolling Chinese characters or maximizing the window.
5040| [CVE-2000-0563] The URLConnection function in MacOS Runtime Java (MRJ) 2.1 and earlier and the Microsoft virtual machine (VM) for MacOS allows a malicious web site operator to connect to arbitrary hosts using a HTTP redirection, in violation of the Java security model.
5041| [CVE-1999-1097] Microsoft NetMeeting 2.1 allows one client to read the contents of another client's clipboard via a CTRL-C in the chat box when the box is empty.
5042|
5043| SecurityFocus - https://www.securityfocus.com/bid/:
5044| [83154] Microsoft Windows 2000 Server CVE-2004-0540 Remote Security Vulnerability
5045| [45297] Microsoft Exchange Server 2007 Infinite Loop Remote Denial of Service Vulnerability
5046| [43419] Microsoft Excel 2002 Memory Corruption Vulnerability
5047| [43189] Microsoft Visual C++ 2008 Redistributable Package DLL Loading Arbitrary Code Execution Vulnerability
5048| [42742] Microsoft PowerPoint 2007 Multiple DLL Loading Arbitrary Code Execution Vulnerability
5049| [42695] Microsoft Groove 2007 'mso.dll' DLL Loading Arbitrary Code Execution Vulnerability
5050| [42681] Microsoft Visio 2003 'mfc71enu.dll' DLL Loading Arbitrary Code Execution Vulnerability
5051| [41843] Microsoft Outlook Web Access for Exchange Server 2003 Cross Site Request Forgery Vulnerability
5052| [39776] Microsoft SharePoint Server 2007 '_layouts/help.aspx' Cross Site Scripting Vulnerability
5053| [37196] RETIRED: Microsoft December 2009 Advance Notification Multiple Vulnerabilities
5054| [36940] RETIRED: Microsoft November 2009 Advance Notification Multiple Vulnerabilities
5055| [36633] RETIRED: Microsoft October 2009 Advance Notification Multiple Vulnerabilities
5056| [36239] RETIRED: Microsoft September 2009 Advance Notification Multiple Vulnerabilities
5057| [35974] RETIRED: Microsoft August 2009 Advance Notification Multiple Vulnerabilities
5058| [35617] RETIRED: Microsoft July 2009 Advance Notification Multiple Vulnerabilities
5059| [35213] RETIRED: Microsoft June 2009 Advance Notification Multiple Vulnerabilities
5060| [34867] RETIRED: Microsoft May 2009 Advance Notification Multiple Vulnerabilities
5061| [34532] Microsoft IAG 2007 ActiveX Control Multiple Stack Based Buffer Overflow Vulnerabilities
5062| [34469] Microsoft Word 2000 WordPerfect Converter Remote Code Execution Vulnerability
5063| [34450] RETIRED: Microsoft April 2009 Advance Notification Multiple Vulnerabilities
5064| [34005] RETIRED: Microsoft March 2009 Advance Notification Multiple Vulnerabilities
5065| [33639] RETIRED: Microsoft February 2009 Advance Notification Multiple Vulnerabilities
5066| [33170] RETIRED: Microsoft January 2009 Advance Notification Multiple Vulnerabilities
5067| [32632] RETIRED: Microsoft December 2008 Advance Notification Multiple Vulnerabilities
5068| [32153] Retired: Microsoft November 2008 Advance Notification Multiple Vulnerabilities
5069| [31667] Retired: Microsoft October 2008 Advance Notification Multiple Vulnerabilities
5070| [31129] RETIRED: Microsoft SQL Server 2000 'sqlvdir.dll' ActiveX Buffer Overflow Vulnerability
5071| [31014] RETIRED: Microsoft September 2008 Advance Notification Multiple Vulnerabilities
5072| [30593] RETIRED: Microsoft August 2008 Advance Notification Multiple Vulnerabilities
5073| [30075] RETIRED: Microsoft July 2008 Advance Notification Multiple Vulnerabilities
5074| [29576] RETIRED: Microsoft June 2008 Advance Notification Multiple Vulnerabilities
5075| [29108] RETIRED: Microsoft May 2008 Advance Notification Multiple Vulnerabilities
5076| [28598] RETIRED: Microsoft April 2008 Advance Notification Multiple Vulnerabilities
5077| [28124] Retired: Microsoft March 2008 Advance Notification Multiple Vulnerabilities
5078| [27674] RETIRED: Microsoft February 2008 Advance Notification Multiple Vulnerabilities
5079| [27119] RETIRED: Microsoft January 2008 Advance Notification Multiple Vulnerabilities
5080| [26739] RETIRED: Microsoft December 2007 Advance Notification Multiple Vulnerabilities
5081| [26414] Microsoft Forms 2.0 ActiveX Control Memory Access Violation Denial of Service Vulnerabilities
5082| [26380] Retired: Microsoft November 2007 Advance Notification Multiple Vulnerabilities
5083| [25991] RETIRED: Microsoft Office 2000 and XP Unspecified Word Document Handling DoS Vulnerability
5084| [25922] RETIRED: Microsoft October 2007 Advance Notification Multiple Vulnerabilities
5085| [25573] RETIRED: Microsoft September 2007 Advance Notification Multiple Vulnerabilities
5086| [25247] Retired: Microsoft August 2007 Advance Notification Multiple Vulnerabilities
5087| [24771] Retired: Microsoft July 2007 Advance Notification Multiple Vulnerabilities
5088| [24366] RETIRED: Microsoft June 2007 Advance Notification Multiple Vulnerabilities
5089| [24118] Microsoft Office 2000 UA OUACTRL.OCX ActiveX Control Buffer Overflow Vulnerability
5090| [23800] RETIRED: Microsoft May 2007 Advance Notification Multiple Vulnerabilities
5091| [23380] Microsoft Word 2007 WWLib.DLL Unspecified Document File Buffer Overflow Vulnerability
5092| [23335] RETIRED: Microsoft April 2007 Advance Notification Multiple Vulnerabilities
5093| [22716] Microsoft Office 2003 Denial of Service Vulnerability
5094| [22567] Microsoft Word 2000/2002 Document Stream Remote Code Execution Vulnerability
5095| [22328] RETIRED: Microsoft Word 2003 Unspecified Code Execution Vulnerability
5096| [22225] Microsoft Word 2000 Malformed Function Code Execution Vulnerability
5097| [21611] Microsoft Project Server 2003 PDSRequest.ASP XML Request Information Disclosure Vulnerability
5098| [21495] Microsoft Windows 2000 Remote Installation Service Remote Code Execution Vulnerability
5099| [20843] Microsoft Visual Studio 2005 WMI Object Broker Remote Code Execution Vulnerability
5100| [19636] Microsoft Windows 2000 Multiple COM Object Instantiation Code Execution Vulnerabilities
5101| [19388] Microsoft Windows 2000 Kernel Local Privilege Escalation Vulnerability
5102| [17134] Microsoft Commerce Server 2002 Authentication Bypass Vulnerability
5103| [16634] Microsoft PowerPoint 2000 Remote Information Disclosure Vulnerability
5104| [14772] Microsoft Exchange Server 2003 Exchange Information Store Denial Of Service Vulnerability
5105| [14093] Microsoft Update Rollup 1 for Windows 2000 SP4 Released - Multiple Vulnerabilities Fixed
5106| [13564] Microsoft SQL Server 2000 Multiple Vulnerabilities
5107| [13008] Microsoft Windows Server 2003 SMB Redirector Local Denial Of Service Vulnerability
5108| [12972] Microsoft Windows Server 2003 Service Pack 1 Released - Multiple Vulnerabilities Fixed
5109| [12913] Microsoft Outlook 2002 Connector For IBM Lotus Domino Policy Bypass Vulnerability
5110| [12824] Microsoft InfoPath 2003 Insecure Information Storage Vulnerability
5111| [12641] Microsoft Windows 2000 Group Policy Bypass Vulnerability
5112| [12141] Microsoft FrontPage 2000 Internet Publishing Service Provider DAV File Upload Vulnerability
5113| [11820] Microsoft Windows 2000 Resource Kit W3Who.DLL Multiple Remote Vulnerabilities
5114| [11446] Microsoft Outlook 2003 Security Policy Bypass Vulnerability
5115| [11387] Microsoft Windows 2003 Services Default SACL Access Right Weakness
5116| [10901] Microsoft Windows 2000/XP CRL File Failed Integrity Check Denial Of Service Vulnerability
5117| [10693] Microsoft Windows 2000 Media Player Control Media Preview Script Execution Vulnerability
5118| [10484] Microsoft ISA Server 2000 FTP Bounce Filtering Vulnerability
5119| [10480] Microsoft ISA Server 2000 Site And Content Rule Bypass Vulnerability
5120| [10440] Microsoft Windows 2000 Domain Expired Account Security Policy Violation Weakness
5121| [10369] Microsoft Outlook 2003 Media File Script Execution Vulnerability
5122| [10307] Microsoft Outlook 2003 Predictable File Location Weakness
5123| [10114] Microsoft Windows 2000 Domain Controller LDAP Denial Of Service Vulnerability
5124| [9409] Microsoft Exchange Server 2003 Outlook Web Access Random Mailbox Access Vulnerability
5125| [9408] Microsoft ISA Server 2000 H.323 Filter Remote Buffer Overflow Vulnerability
5126| [9118] Microsoft Exchange Server 2003 Outlook Web Access Lowered Security Settings Weakness
5127| [8833] Microsoft Windows 2000 TroubleShooter ActiveX Control Buffer Overflow Vulnerability
5128| [8522] Multiple Microsoft Windows 2003 Stack Protection Implementation Weaknesses
5129| [8397] Microsoft Windows 2000 Subnet Bandwidth Manager RSVP Server Authority Hijacking Vulnerability
5130| [8104] Microsoft Windows 2000 Unauthorized RPC Connection Weakness
5131| [8098] Microsoft Windows 2000 Terminal Services Named Pipe System Account Access Vulnerability
5132| [8093] Microsoft Windows 2000 Active Directory Forest Origin Validation Vulnerability
5133| [8090] Microsoft Windows 2000 ShellExecute() Buffer Overflow Vulnerability
5134| [8089] Microsoft Windows 2000 Unspecified Cryptnet.DLL Memory Leakage Vulnerability
5135| [8086] Microsoft Windows 2000 Port Name Buffers Potential Buffer Overflow Vulnerability
5136| [8085] Microsoft Windows 2000 ModifyDN Request Denial of Service Vulnerability
5137| [8083] Microsoft Windows 2000 Domain Controller Spoofing Vulnerability
5138| [8081] Microsoft Windows 2000 USBH_IoctlGetNodeConnectionDriverKeyName Information Disclosure Vulnerability
5139| [8063] Microsoft Commerce Server 2002 Weak Registry Key Permissions Weakness
5140| [8045] Microsoft Windows 2000 SP4 Released - Multiple Vulnerabilities Fixed
5141| [7930] Microsoft Windows 2000 Active Directory Remote Stack Overflow Vulnerability
5142| [7788] Microsoft Windows 2000/XP/2003 IPV6 ICMP Flood Denial Of Service Vulnerability
5143| [7469] Microsoft BizTalk Server 2002 HTTP Receiver Buffer Overflow Vulnerability
5144| [7360] Microsoft Windows 2000/XP Registry Editor Custom Permissions Weakness
5145| [7102] Microsoft Windows 2000 Help Facility .CNT File :Link Buffer Overflow Vulnerability
5146| [6769] Microsoft Windows 2000 RPC Service Privilege Escalation Vulnerability
5147| [6766] Microsoft Windows 2000 NetBIOS Continuation Packets Kernel Memory Leak Vulnerability
5148| [6667] Microsoft Outlook 2002 V1 Exchange Server Security Certificate Information Leakage Vulnerability
5149| [6319] Microsoft Outlook 2002 Email Header Processing Denial of Service Vulnerability
5150| [6030] Microsoft Windows 2000 SNMP Printer Query Denial of Service Vulnerability
5151| [5972] Microsoft Windows 2000/XP Full Event Log Administrative Alert Weakness
5152| [5922] Microsoft Content Management Server 2001 Cross-Site Scripting Vulnerability
5153| [5480] Microsoft Windows 2000 Network Connection Manager Privilege Elevation Vulnerability
5154| [5422] Microsoft Content Management Server 2001 SQL Injection Vulnerability
5155| [5421] Microsoft Content Management Server 2001 Arbitrary Upload Location Vulnerability
5156| [5420] Microsoft Content Management Server 2001 User Authentication Buffer Overflow Vulnerability
5157| [5415] Microsoft Windows 2000 Insecure Default File Permissions Vulnerability
5158| [5413] Microsoft Exchange 2000 Post Authorization License Exhaustion Denial Of Service Vulnerability
5159| [5412] Microsoft Exchange 2000 Multiple MSRPC Denial Of Service Vulnerabilities
5160| [5312] Microsoft SQL Server 2000 Resolution Service Denial of Service Vulnerability
5161| [5311] Microsoft SQL Server 2000 Resolution Service Stack Overflow Vulnerability
5162| [5310] Microsoft SQL Server 2000 Resolution Service Heap Overflow Vulnerability
5163| [5309] Microsoft SQL Server 2000 sp_MScopyscript SQL Injection Vulnerability
5164| [5307] Microsoft SQL Server 2000 Database Consistency Checkers Buffer Overflow Vulnerability
5165| [5253] Microsoft Windows 2000 Narrator Password Disclosure Vulnerability
5166| [5205] Microsoft SQL Server 2000 Incorrect Registry Key Permissions Vulnerability
5167| [5111] Microsoft Commerce Server 2000 OWC Package Installer Local Command Execution Vulnerability
5168| [5014] Microsoft SQL Server 2000 Password Encrypt Procedure Buffer Overflow Vulnerability
5169| [4881] Microsoft Exchange 2000 Malformed Mail Attribute DoS Vulnerability
5170| [4853] Microsoft Commerce Server 2000 Profile Service Buffer Overflow Vulnerability
5171| [4852] Microsoft Windows 2000 Remote Access Service Buffer Overflow Vulnerability
5172| [4847] Microsoft SQL Server 2000 Bulk Insert Procedure Buffer Overflow Vulnerability
5173| [4797] Microsoft MSDE/SQL Server 2000 Desktop Engine Default Configuration Vulnerability
5174| [4683] Microsoft Windows 2000 / NT Path Precedence Vulnerability
5175| [4532] Microsoft Windows 2000 Lanman Denial of Service Vulnerability
5176| [4438] Microsoft Windows 2000 Group Policy Evasion Vulnerability
5177| [4426] Microsoft Windows 2000 / NT / XP MUP UNC Request Buffer Overflow Vulnerability
5178| [4287] Microsoft Windows 2000 / NT 4.0 Process Handle Local Privilege Elevation Vulnerability
5179| [4256] Microsoft Windows 2000 Password Policy Bypass Vulnerability
5180| [4157] Microsoft Commerce Server 2000 ISAPI Buffer Overflow Vulnerability
5181| [4095] Microsoft Windows 2000 Server Terminal Services Failure To Lock Terminal Vulnerability
5182| [3652] Microsoft Windows 2000 Internet Key Exchange DoS Vulnerability
5183| [3481] Microsoft Windows 2000/XP GDI Denial of Service Vulnerability
5184| [3479] Microsoft Windows 2000 NTFS With Macintosh Client Directory Permission Vulnerability
5185| [3445] Microsoft Windows 2000/NT Terminal Server Service RDP DoS Vulnerability
5186| [3339] Microsoft Index Server 2.0 File Information and Path Disclosure Vulnerability
5187| [3305] Norton AntiVirus for Microsoft Exchange 2000 Information Disclosure Vulnerability
5188| [3291] Microsoft Windows 2000 RunAs Service Denial of Services Vulnerability
5189| [3215] Microsoft Windows 2000 IrDA Buffer Overflow Denial of Service Vulnerability
5190| [3185] Microsoft Windows 2000 RunAs Service Named Pipe Hijacking Vulnerability
5191| [3184] Microsoft Windows 2000 RunAs User Credentials Exposure Vulnerability
5192| [3146] Microsoft Windows 2000 System File Replacement Vulnerability
5193| [3115] Microsoft Windows NT and 2000 Command Prompt Reboot Vulnerability
5194| [3063] Microsoft Windows 2000 Unauthorized Password Change Vulnerability
5195| [3033] Microsoft Windows 2000 Task Manager Process Termination Vulnerability
5196| [2988] Microsoft Windows 2000 SMTP Improper Authentication Vulnerability
5197| [2929] Microsoft Windows 2000 LDAP SSL Password Modification Vulnerability
5198| [2849] Microsoft Windows 2000 Telnet Privilege Escalation Vulnerability
5199| [2846] Microsoft Windows 2000 Telnet System Call DoS Vulnerability
5200| [2844] Microsoft Windows 2000 Telnet Service DoS Vulnerability
5201| [2843] Microsoft Windows 2000 Telnet Multiple Sessions DoS Vulnerability
5202| [2838] Microsoft Windows 2000 Telnet Username DoS Vulnerability
5203| [2460] Microsoft Windows 2000 Event Viewer Buffer Overflow Vulnerability
5204| [2441] Microsoft Exchange 2000 / IIS 5.0 Multiple Invalid URL Request DoS Vulnerability
5205| [2394] Microsoft Windows 2000 Domain Controller DoS Vulnerability
5206| [2341] Microsoft Windows 2000 Network DDE Escalated Privileges Vulnerability
5207| [2326] Microsoft Windows 2000 RDP DoS Vulnerability
5208| [2133] Microsoft Windows 2000 Directory Services Restore Mode Blank Password Vulnerability
5209| [2066] Microsoft Windows NT 4.0 / 2000 SNMP Registry Key Modification Vulnerability
5210| [2018] Microsoft Windows 2000 Telnet Session Timeout DoS Vulnerability
5211| [2007] Microsoft Windows 2000 DNS Memory Leak Vulnerability
5212| [1973] Microsoft Windows 2000 Domain Account Lockout Bypass Vulnerability
5213| [1958] Microsoft Exchange 2000 Server EUSR_EXSTOREEVENT Account Vulnerability
5214| [1933] Microsoft Indexing Services for Windows 2000 File Verification Vulnerability
5215| [1899] Microsoft Windows 2000 ActiveX Control Buffer Overflow Vulnerability
5216| [1811] Microsoft Site Server 2.0 with IIS 4.0 Malicious File Upload Vulnerability
5217| [1758] Microsoft Windows 2000 Unattended Install OEMPreinstall Vulnerability
5218| [1753] Microsoft Windows NT 4.0 / 2000 Spoofed LPC Request Vulnerability
5219| [1748] Microsoft Windows NT 4.0 / 2000 Predictable LPC Message Identifier Multiple Vulnerabilities
5220| [1745] Microsoft Windows NT 4.0 / 2000 LPC Zone Memory Depletion DoS Vulnerability
5221| [1729] Microsoft Windows 2000 Simplified Chinese IME Vulnerability
5222| [1695] Microsoft Proxy 2.0 FTP Permissions Bypass Vulnerability
5223| [1692] Microsoft Proxy 2.0 Internal Network Access Vulnerability
5224| [1683] Microsoft Windows 2000 telnet.exe NTLM Authentication Vulnerability
5225| [1673] Microsoft Windows 2000 Malformed RPC Packet DoS Vulnerability
5226| [1651] Microsoft Windows 2000 Still Image Service Privilege Escalation Vulnerability
5227| [1632] Microsoft Windows 98 / NT 4.0 / 2000 File Extension Validation Vulnerability
5228| [1620] Microsoft Windows 9x / NT 4.0 / 2000 NetBIOS Cache Corruption Vulnerability
5229| [1613] Microsoft Windows 2000 Local Security Policy Corruption Vulnerability
5230| [1566] Microsoft Word 97 / 2000 Mail Merge Code Execution Vulnerability
5231| [1561] Microsoft Word / Excel / Powerpoint 2000 Object Tag Buffer Overflow Vulnerability
5232| [1535] Microsoft Windows 2000 Named Pipes Predictability Vulnerability
5233| [1507] Microsoft Windows NT 4.0 / 2000 Unspecified Executable Path Vulnerability
5234| [1451] Microsoft Excel 97 / 2000 Register.ID Vulnerability
5235| [1435] Microsoft FrontPage 2000 Server Extensions Denial Of Service Vulnerability
5236| [1415] Microsoft Windows 2000 Remote CPU-overload Vulnerability
5237| [1414] Microsoft Windows 2000 Telnet Server DoS Vulnerability
5238| [1399] Microsoft Internet Explorer 5.01 and Excel/Powerpoint 2000 ActiveX Object Execution Vulnerability
5239| [1398] Microsoft Internet Explorer 5.01 and Access 2000 / 97 VBA Code Execution Vulnerability
5240| [1350] Microsoft Windows 2000 Windows Station Access Vulnerability
5241| [1304] Microsoft Windows NT 4.0 / 2000 SMB Write Request DoS Vulnerability
5242| [1301] Microsoft Windows NT 4.0 / 2000 Ignored SMB Response DoS Vulnerability
5243| [1295] Microsoft Windows 2000 Default 40-bit Encrypted Protected Store Vulnerability
5244| [1198] Microsoft Windows 2000 Default SYSKEY Configuration Vulnerability
5245| [1197] Microsoft Office 2000 UA Control Vulnerability
5246| [990] Microsoft Windows 2000 Install Unprotected ADMIN$ Share Vulnerability
5247| [945] Microsoft SMS 2.0 Default Permissions Vulnerability
5248| [539] Microsoft Windows 2000 EFS Vulnerability
5249| [180] Microsoft Windows April Fools 2001 Vulnerability
5250| [71487] Microsoft December 2014 Advance Notification Multiple Vulnerabilities
5251| [70966] RETIRED: Microsoft November 2014 Advance Notification Multiple Vulnerabilities
5252| [70367] RETIRED: Microsoft October 2014 Advance Notification Multiple Vulnerabilities
5253| [69636] RETIRED: Microsoft September 2014 Advance Notification Multiple Vulnerabilities
5254| [69108] Microsoft August 2014 Advance Notification Multiple Vulnerabilities
5255| [68367] Microsoft July 2014 Advance Notification Multiple Vulnerabilities
5256| [67905] Microsoft June 2014 Advance Notification Multiple Vulnerabilities
5257| [67298] Microsoft May 2014 Advance Notification Multiple Vulnerabilities
5258| [66639] RETIRED: Microsoft April 2014 Advance Notification Multiple Vulnerabilities
5259| [66016] Microsoft March 2014 Notification Multiple Vulnerabilities
5260| [65426] Microsoft February 2014 Notification Multiple Vulnerabilities
5261| [64757] RETIRED: Microsoft January 2014 Advance Notification Multiple Vulnerabilities
5262| [64083] RETIRED: Microsoft December 2013 Advance Notification Multiple Vulnerabilities
5263| [63604] RETIRED: Microsoft November 2013 Advance Notification Multiple Vulnerabilities
5264| [62797] RETIRED: Microsoft October 2013 Advance Notification Multiple Vulnerabilities
5265| [62228] RETIRED: Microsoft September 2013 Advance Notification Multiple Vulnerabilities
5266| [62181] Microsoft Office Pinyin IME 2010 CVE-2013-3859 Local Privilege Escalation Vulnerability
5267| [61686] Microsoft August 2013 Advance Notification Multiple Vulnerabilities
5268| [60960] RETIRED: Microsoft July 2013 Advance Notification Multiple Vulnerabilities
5269| [60394] Microsoft June 2013 Advance Notification Multiple Vulnerabilities
5270| [59785] RETIRED: Microsoft May 2013 Advance Notification Multiple Vulnerabilities
5271| [58881] RETIRED: Microsoft April 2013 Advance Notification Multiple Vulnerabilities
5272| [58380] RETIRED: Microsoft March 2013 Advance Notification Multiple Vulnerabilities
5273| [57846] RETIRED: Microsoft February 2013 Advance Notification Multiple Vulnerabilities
5274| [57137] RETIRED: Microsoft January 2013 Advance Notification Multiple Vulnerabilities
5275| [56838] RETIRED: Microsoft December 2012 Advance Notification Multiple Vulnerabilities
5276| [56450] RETIRED: Microsoft November 2012 Advance Notification Multiple Vulnerabilities
5277| [56304] Microsoft Office Excel 2010 Memory Corruption Denial of Service Vulnerability
5278| [55794] RETIRED: Microsoft October 2012 Advance Notification Multiple Vulnerabilities
5279| [55472] RETIRED: Microsoft September 2012 Advance Notification Multiple Vulnerabilities
5280| [54944] RETIRED: Microsoft August 2012 Advance Notification Multiple Vulnerabilities
5281| [54318] RETIRED: Microsoft July 2012 Advance Notification Multiple Vulnerabilities
5282| [53862] RETIRED: Microsoft June 2012 Advance Notification Multiple Vulnerabilities
5283| [53372] RETIRED: Microsoft May 2012 Advance Notification Multiple Vulnerabilities
5284| [52910] RETIRED: Microsoft April 2012 Advance Notification Multiple Vulnerabilities
5285| [52366] RETIRED: Microsoft March 2012 Advance Notification Multiple Vulnerabilities
5286| [51944] RETIRED: Microsoft February 2012 Advance Notification Multiple Vulnerabilities
5287| [51289] RETIRED: Microsoft January 2012 Advance Notification Multiple Vulnerabilities
5288| [50980] RETIRED: Microsoft December 2011 Advance Notification Multiple Vulnerabilities
5289| [50513] RETIRED: Microsoft November 2011 Advance Notification Multiple Vulnerabilities
5290| [49994] RETIRED: Microsoft October 2011 Advance Notification Multiple Vulnerabilities
5291| [49515] RETIRED: Microsoft September 2011 Advance Notification Multiple Vulnerabilities
5292| [49017] RETIRED: Microsoft August 2011 Advance Notification Multiple Vulnerabilities
5293| [48616] RETIRED: Microsoft July 2011 Advance Notification Multiple Vulnerabilities
5294| [48235] Microsoft Lync Server 2010 'ReachJoin.aspx' Remote Command Injection Vulnerability
5295| [48193] RETIRED: Microsoft June 2011 Advance Notification Multiple Vulnerabilities
5296| [47725] RETIRED: Microsoft May 2011 Advance Notification Multiple Vulnerabilities
5297| [47255] RETIRED: Microsoft April 2011 Advance Notification Multiple Vulnerabilities
5298| [46675] RETIRED: Microsoft March 2011 Advance Notification Multiple Vulnerabilities
5299| [46132] RETIRED: Microsoft February 2011 Advance Notification Multiple Vulnerabilities
5300| [45696] RETIRED: Microsoft January 2011 Advance Notification Multiple Vulnerabilities
5301| [45307] RETIRED: Microsoft December 2010 Advance Notification Multiple Vulnerabilities
5302| [44649] RETIRED: Microsoft November 2010 Advance Notification Multiple Vulnerabilities
5303| [43831] RETIRED: Microsoft October 2010 Advance Notification Multiple Vulnerabilities
5304| [43115] RETIRED: Microsoft September 2010 Advance Notification Multiple Vulnerabilities
5305| [42234] RETIRED: Microsoft August 2010 Advance Notification Multiple Vulnerabilities
5306| [41474] RETIRED: Microsoft July 2010 Advance Notification Multiple Vulnerabilities
5307| [40548] RETIRED: Microsoft June 2010 Advance Notification Multiple Vulnerabilities
5308| [39961] RETIRED: Microsoft May 2010 Advance Notification Multiple Vulnerabilities
5309| [39313] RETIRED: Microsoft April 2010 Advance Notification Multiple Vulnerabilities
5310| [38540] RETIRED: Microsoft March 2010 Advance Notification Multiple Vulnerabilities
5311| [38096] RETIRED: Microsoft February 2010 Advance Notification Multiple Vulnerabilities
5312| [37887] RETIRED: Microsoft January 2010 Advance Notification Multiple Vulnerabilities
5313| [37664] RETIRED: Microsoft January 2010 Advance Notification Multiple Vulnerabilities
5314| [32642] Microsoft Word RTF Malformed Control Word Variant 2 Remote Code Execution Vulnerability
5315|
5316| IBM X-Force - https://exchange.xforce.ibmcloud.com:
5317| [82417] Microsoft Windows Knowledge Base Article 2801261 update is not installed
5318| [82415] Microsoft Windows Knowledge Base Article 2807986 update is not installed
5319| [82410] Microsoft Windows Knowledge Base Article 2809289 update is not installed
5320| [81859] Microsoft Windows Knowledge Base Article 2802968 update is not installed
5321| [81857] Microsoft Windows Knowledge Base Article 2809279 update is not installed
5322| [81668] Microsoft Windows Knowledge Base Article 2800277 update is not installed
5323| [77323] Microsoft Windows Knowledge Base Article 2706045 update is not installed
5324| [75949] Microsoft Windows Knowledge Base Article 2707960 update is not installed
5325| [75942] Microsoft Windows Knowledge Base Article 2706726 update is not installed
5326| [75934] Microsoft Windows Knowledge Base Article 2709162 update is not installed
5327| [75926] Microsoft Windows Knowledge Base Article 2709100 update is not installed
5328| [75905] Microsoft Windows Knowledge Base Article 2707956 update is not installed
5329| [71991] Microsoft Windows Knowledge Base Article 2607664 update is not installed
5330| [71542] Microsoft Windows Knowledge Base Article 2607702 update is not installed
5331| [70945] Microsoft Windows Knowledge Base Article 2603381 update is not installed
5332| [70150] Microsoft Windows Knowledge Base Article 2607670 update is not installed
5333| [67755] Microsoft Windows Knowledge Base Article 2503665 update is not installed
5334| [67749] Microsoft Windows Knowledge Base Article 2507938 update is not installed
5335| [66845] Microsoft Windows Knowledge Base Article 2506014 update is not installed
5336| [66844] Microsoft Windows Knowledge Base Article 2501584 update is not installed
5337| [66448] Microsoft Windows Knowledge Base Article 2508272 update is not installed
5338| [66442] Microsoft Windows Knowledge Base Article 2509553 update is not installed
5339| [66440] Microsoft Windows Knowledge Base Article 2508429 update is not installed
5340| [66438] Microsoft Windows Knowledge Base Article 2507618 update is not installed
5341| [66430] Microsoft Windows Knowledge Base Article 2503658 update is not installed
5342| [66425] Microsoft Windows Knowledge Base Article 2506223 update is not installed
5343| [65570] Microsoft Windows Knowledge Base Article 2500212 update is not installed
5344| [65568] Microsoft Windows Knowledge Base Article 2508062 update is not installed
5345| [63840] Microsoft Visual C++ 2008 Redistributable Package dynamic-linked library (DLL) code execution
5346| [63780] Microsoft PowerPoint 2007 dynamic-linked library (rpawinet.dll) code execution
5347| [63775] Microsoft Visio 2003 dynamic-linked library (mfc71enu.dll) code execution
5348| [63586] Microsoft Windows Knowledge Base Article 2207559 update is not installed
5349| [63573] Microsoft Windows Knowledge Base Article 2407132 update is not installed
5350| [62797] Microsoft Windows Knowledge Base Article 2305420 update is not installed
5351| [62149] Microsoft Windows Knowledge Base Article 2207566 update is not installed
5352| [62133] Microsoft Windows Knowledge Base Article 2405882 update is not installed
5353| [53980] Microsoft Windows 2000 License Logging Server buffer overflow
5354| [53601] Microsoft Office 2008 for Mac user ID 502 security bypass
5355| [50973] Microsoft Windows Server 2003 and Vista win32k.sys denial of service
5356| [50759] Microsoft Windows 2000 Active Directory LDAP code execution
5357| [48595] Microsoft Word 2007 Email as PDF information disclosure
5358| [46102] Microsoft Windows 2003 SP2 is not installed on the system
5359| [46101] Microsoft Windows 2003 SP1 is not installed on the system
5360| [45186] Microsoft SQL Server 2000 SQLVDIRLib.SQLVDirControl ActiveX control buffer overflow
5361| [37200] Microsoft SQL Server 2000 Service Pack 1 update is not installed
5362| [37198] Microsoft SQL Server 2000 Service Pack 3 update is not installed
5363| [34634] Microsoft Windows Server 2003 Active Directory information disclosure
5364| [34599] Microsoft Windows Server 2003 terminal server security bypass
5365| [34473] Microsoft Office 2000 ActiveX control buffer overflow
5366| [33713] Microsoft Word 2007 multiple unspecified denial of service
5367| [33712] Microsoft Word 2007 wwlib.dll buffer overflow
5368| [32631] Microsoft SQL Server 2000 Service Pack 2 update is not installed
5369| [31821] Microsoft Windows time zone update for year 2007
5370| [31196] Microsoft Office 2003 Brazilian Grammar Checker buffer overflow
5371| [30905] Microsoft Project Server 2003 pdsrequest.asp information disclosure
5372| [29546] Microsoft Windows 2000/2003 user logoff initiated
5373| [29545] Microsoft Windows 2000/2003 system time changed
5374| [29544] Microsoft Windows 2000/2003 system security access removed
5375| [29543] Microsoft Windows 2000/2003 security access granted
5376| [29542] Microsoft Windows 2000/2003 SAM notification package loaded
5377| [29541] Microsoft Windows 2000/2003 primary security token issued
5378| [29540] Microsoft Windows 2000/2003 user password reset successful
5379| [29539] Microsoft Windows 2000/2003 object indirectly accessed
5380| [29538] Microsoft Windows 2000/2003 object handle duplicated
5381| [29537] Microsoft Windows 2000/2003 logon with explicit credentials success
5382| [29536] Microsoft Windows 2000/2003 logon attempt using explicit credentials unsuccessful
5383| [29535] Microsoft Windows 2000/2003 IPSEC policy agent failed
5384| [29534] Microsoft Windows 2000/2003 IPSEC policy agent disabled
5385| [29533] Microsoft Windows 2000/2003 IPSEC policy agent changed
5386| [29532] Microsoft Windows 2000/2003 IKE security association established
5387| [29531] Microsoft Windows 2000/2003 IKE quick mode association ended
5388| [29530] Microsoft Windows 2000/2003 IKE main mode association ended
5389| [29529] Microsoft Windows 2000/2003 IKE association negotiation failed
5390| [29528] Microsoft Windows 2000/2003 IKE association peer authentication failed
5391| [29527] Microsoft Windows 2000/2003 IKE association failed invalid proposal
5392| [29526] Microsoft Windows 2000/2003 IKE association failed authentication parameters
5393| [29525] Microsoft Windows 2000/2003 DPAPI master key backup attempted
5394| [29524] Microsoft Windows 2000/2003 DPAPI key recovery attempted
5395| [29523] Microsoft Windows 2000/2003 DPAPI auditable data unprotected
5396| [29522] Microsoft Windows 2000/2003 administrative group security descriptor set
5397| [29521] Microsoft Windows 2000/2003 account name changed
5398| [29507] Microsoft Office 2003 unspecified PowerPoint NULL pointer dereference denial of service
5399| [28512] Microsoft Internet Explorer multiple Windows 2000 COM object denial of service
5400| [28005] Microsoft Windows 2000 Management Console (MMC) resource file cross-site scripting
5401| [26118] Microsoft Office 2003 mailto: information disclosure
5402| [25330] Microsoft Commerce Server 2002 authfiles/login.asp authentication bypass
5403| [24474] Microsoft Windows 2000 LDAP client accepts untrusted CA
5404| [24473] Microsoft Windows 2000 event ID 565 not logged
5405| [24472] Microsoft Windows 2000 Event ID 1704 records incorrect group policy settings
5406| [24407] Microsoft Windows 2000 SECEDIT command fails to set ACLs correctly
5407| [24405] Microsoft Windows 2000 UPN credentials with trailing dot group policy bypass
5408| [24403] Microsoft Windows 2000 WideCharToMultiByte() incorrect Japanese character conversion
5409| [24402] Microsoft Windows 2000 Terminal Service client IP not logged
5410| [24400] Microsoft Windows 2000 domain authentication can be bypassed by a local administrator
5411| [23066] Microsoft Windows XP and 2000 Server MSRPC memory allocation denial of service
5412| [22318] Microsoft SQL Server 2000 Service Pack 4 update is not installed
5413| [22183] Microsoft Exchange Server 2003 public folder denial of service
5414| [21345] Microsoft Windows 2000 Update Rollup 1 for Service Pack 4 has not been installed
5415| [21315] Microsoft Outlook 2002 connector for Domino bypass restrictions
5416| [19969] Multiple Microsoft Windows Server 2003 Edition printer driver denial of service
5417| [19965] Multiple Microsoft Windows Server 2003 Editions SMB redirector denial of service
5418| [19727] Microsoft Windows 2000 GDI32.DLL denial of service
5419| [19629] Microsoft Exchange Server 2003 folder denial of service
5420| [17826] Microsoft Outlook 2003 CID security bypass
5421| [17624] Microsoft Windows XP and Windows Server 2003 Compressed Folders buffer overflow
5422| [17621] Microsoft Windows 2003 SMTP service code execution
5423| [17560] Microsoft Windows 2000 and XP GDI library denial of service
5424| [17521] Microsoft Windows 2000 Service Pack 4 is not installed
5425| [16913] Microsoft Windows 2003 users with Synchronize directory service data privilege
5426| [16912] Microsoft Windows 2003 groups with Synchronize directory service data privilege
5427| [16909] Microsoft Windows 2003 groups with Remove computer from docking station privilege
5428| [16907] Microsoft Windows 2003 users with Create global objects privilege
5429| [16905] Microsoft Windows 2003 users or groups with Create global objects privilege
5430| [16851] Microsoft Windows 2003 and XP WinKey and U key denial of service
5431| [16704] Microsoft Windows 2000 Media Player control code execution
5432| [16582] Microsoft Windows Server 2003 kernel CPU denial of service
5433| [16572] Microsoft Windows 2003 Users with Impersonate a client after authentication privilege
5434| [16570] Microsoft Windows 2003 Users with Create global objects privilege
5435| [16564] Microsoft Windows 2003 Groups with Create global objects privilege
5436| [16562] Microsoft Windows 2003 Groups with "
5437| [16522] Microsoft Windows 2003 Impersonate a client after authentication privilege
5438| [16521] Microsoft Windows 2003 Deny Logon Through Terminal Services privilege
5439| [16520] Microsoft Windows 2003 Create global objects privilege
5440| [16276] Microsoft Windows 2000 Advanced Server fully qualified domain name security bypass
5441| [16173] Microsoft Outlook 2003 OLE object bypass restricted security zone
5442| [16119] Microsoft Outlook 2000 URL spoofing
5443| [16104] Microsoft Outlook 2003 predictable file location could allow code execution
5444| [16095] Microsoft Windows XP and Windows Server 2003 HCP URL code execution
5445| [15704] Microsoft Windows XP and Windows Server 2003 HCP URL code execution
5446| [15700] Microsoft Windows 2000 Domain Controller LSASS LDAP message denial of service
5447| [15632] Microsoft Windows 2000 Utility Manger allows privilege escalation
5448| [15414] Microsoft Outlook 2002 mailto URL allows execution of code
5449| [15263] Microsoft Windows XP and 2000 Server kernel allows elevated privileges
5450| [15057] Microsoft Windows XP and Windows Server 2003 smbmount Linux client denial of service
5451| [15038] Microsoft Windows 2000 Server Windows Media Services denial of service
5452| [15037] Microsoft Windows Server 2003 WINS /GS flag denial of service
5453| [14178] Microsoft ISA Exchange Server 2003 MS04-002 patch is not installed
5454| [14167] Microsoft ISA Server 2000 H.323 filter buffer overflow
5455| [13426] Microsoft Windows 2000 and XP RPC race condition
5456| [13423] Microsoft Windows 2000 Local Troubleshooter ActiveX control buffer overflow
5457| [13407] Microsoft Windows 2000 Server mqsvc.exe MQLocateBegin packet buffer overflow
5458| [13385] Microsoft Windows Server 2003 "
5459| [13211] Microsoft Windows 2000 and XP URG memory leak
5460| [13171] Microsoft Windows Server 2003 can allow attacker to bypass mechanism used to detect buffer overflows
5461| [13131] Microsoft Windows 2000 Message Queue Manager buffer overflow
5462| [12684] Microsoft Exchange Server OWA Outlook 2003 denial of service
5463| [12652] Microsoft Windows 2000 and NT 4.0 Server IIS ISAPI nsiislog.dll extension POST request buffer overflow
5464| [12620] Microsoft Windows 2000 Server SMTP FILETIME denial of service
5465| [12543] Microsoft Windows 2000 Accessibility Utility Manager could allow an attacker to gain privileges
5466| [12493] Microsoft Windows Shell32.dll 2000 ShellExecute function buffer overflow
5467| [12489] Microsoft Windows 2000 Server Active Directory buffer overflow
5468| [12128] Microsoft Windows 2000 and Windows NT MS03-019 patch is not installed
5469| [12092] Microsoft Windows 2000 and NT 4.0 Server IIS ISAPI nsiislog.dll extension buffer overflow
5470| [12048] Microsoft Windows 2000 and Windows Server 2003 LAN Manager hash creation enabled
5471| [11901] Microsoft BizTalk Server 2002 SQL injection
5472| [11900] Microsoft BizTalk Server 2002 HTTP Receiver function buffer overflow
5473| [11816] Microsoft Windows 2000 Terminal Services MSGINA.DLL insecure access permissions
5474| [11696] Microsoft Windows 2000 Terminal Services man-in-the-middle attack
5475| [11617] Microsoft Windows 2000 MS03-007 patch is not installed on the system
5476| [11546] Microsoft Windows 2000 Windows Help Facility .cnt file buffer overflow
5477| [11329] Microsoft Windows NT and 2000 cmd.exe CD path name buffer overflow
5478| [11274] Microsoft Windows 2000 NetBIOS continuation packets denial of service
5479| [11273] Microsoft Windows 2000 RPC service could allow an attacker to gain elevated privileges
5480| [11216] Microsoft Windows NT and 2000 command prompt denial of service
5481| [11141] Microsoft Windows 2000 Terminal Services MSGINA.DLL denial of service
5482| [11133] Microsoft Outlook 2002 using V1 Exchange Server Security certificates transmits plaintext emails
5483| [10843] Microsoft Windows 2000 and XP SMB signing group policy modification
5484| [10431] Microsoft Windows 2000 SNMP LANMAN Extension memory leak denial of service
5485| [10400] Microsoft Windows 2000 RPC TCP port 135 denial of service
5486| [10377] Microsoft Windows XP and 2000 administrative alerts fail when security event log is full
5487| [10199] Microsoft Windows 2000/XP PPTP packet buffer overflow
5488| [10195] Microsoft FrontPage Server Extensions (FPSE) 2002 SmartHTML Interpreter buffer overflow
5489| [10194] Microsoft FrontPage Server Extensions (FPSE) 2000 SmartHTML Interpreter denial of service
5490| [9946] Microsoft Windows 2000 Terminal Services session screensaver fails to lock the console
5491| [9856] Microsoft Windows 2000 NCM handler routine could allow elevated privileges
5492| [9779] Microsoft Windows 2000 weak system partition permissions
5493| [9752] Microsoft Windows 2000 Service Pack 3 is not installed
5494| [9746] Microsoft Windows 2000 HTML Help item parameter buffer overflow
5495| [9625] Microsoft Windows 2000 Narrator allows login information to be audible
5496| [9154] Microsoft Data Engine (MSDE) and Microsoft SQL Server 2000 Desktop Engine have a default blank "
5497| [8867] Microsoft Windows 2000 LanMan denial of service
5498| [8813] Microsoft Windows 2000 Terminal Services allows attacker to bypass group policy settings
5499| [8759] Microsoft Windows 2000 could allow an attacker to block the application of Group Policy settings
5500| [8752] Microsoft Windows NT, 2000, and XP MUP buffer overflow
5501| [8739] Microsoft Windows 2000 DCOM memory leak
5502| [8708] Microsoft Outlook 2000 and 2002 executes embedded script in object tag when replying or forwarding HTML mail
5503| [8402] Microsoft Windows 2000 allows an attacker to bypass password policy
5504| [8307] Microsoft Windows 2000, Windows XP, and Exchange 2000 SMTP data transfer command denial of service
5505| [8304] Microsoft Windows 2000 and Exchange 5.5 SMTP service unauthorized mail privileges
5506| [8254] Microsoft Commerce Server 2000 AuthFilter ISAPI filter buffer overflow
5507| [8199] Microsoft Windows 2000 Terminal Services unlocked client
5508| [8094] Microsoft Windows 2000 and Interix 2.2 Telnet protocol option buffer overflow
5509| [8092] Microsoft Exchange 2000 System Attendant sets incorrect registry permissions
5510| [8043] Microsoft Windows NT, 2000, and XP using NTFS could allow files to be hidden
5511| [8037] Microsoft Windows 2000 empty TCP packet denial of service
5512| [8023] Microsoft Windows NT and Windows 2000 SIDs could allow an attacker to gain elevated privileges in another domain
5513| [7919] Microsoft IIS 4.0 and Norton Internet Security 2001 default permissions could allow an attacker to modify log files
5514| [7667] Microsoft Windows 2000 IKE UDP packet flood denial of service
5515| [7566] Microsoft IIS 2.0 and 3.0 upgraded to Microsoft IIS 4.0 fails to remove the ism.dll file
5516| [7538] Microsoft Windows 2000 and XP Terminal services allow an attacker to spoof IP addresses
5517| [7533] Microsoft Windows 2000 RunAs service denial of service
5518| [7532] Microsoft Windows 2000 RunAs service allows local attacker to bypass pipe authentication
5519| [7531] Microsoft Windows 2000 RunAs service reveals sensitive information
5520| [7528] Microsoft Windows NT and Windows 2000 malformed RPC request denial of service
5521| [7409] Microsoft Windows 2000 and Windows XP GDI denial of service
5522| [7302] Microsoft Windows NT and 2000 Terminal Server malformed RDP packet series denial of service
5523| [7008] Microsoft Windows 2000 IrDA device denial of service
5524| [6977] Microsoft Windows NT and 2000 NNTP memory leak denial of service
5525| [6931] Microsoft Windows 2000 without Service Pack 2
5526| [6919] Microsoft Windows 2000 Task Manager does not terminate malicious files with the same name as a system process
5527| [6912] Microsoft Windows NT and 2000 Terminal Server RDP memory leak denial of service
5528| [6876] Microsoft Windows 2000 could allow an attacker to change network passwords
5529| [6803] Microsoft Windows 2000 SMTP service allows mail relaying
5530| [6745] Microsoft Windows 2000 LDAP function could allow domain user password change
5531| [6669] Microsoft Windows 2000 Telnet system call denial of service
5532| [6668] Microsoft Windows 2000 Telnet handle leak denial of service
5533| [6667] Microsoft Windows 2000 Telnet multiple idle sessions denial of service
5534| [6666] Microsoft Windows 2000 Telnet username denial of service
5535| [6665] Microsoft Windows 2000 Telnet service weak domain authentication
5536| [6664] Microsoft Windows 2000 Telnet service predictable pipe names could allow elevation of privileges
5537| [6652] Microsoft Exchange 2000 OWA script execution
5538| [6590] Microsoft Windows 2000 debug registers allow attacker to gain elevated privileges
5539| [6506] Microsoft Windows 2000 Server Kerberos denial of service
5540| [6443] Microsoft Windows 2000 catalog file could remove installed hotfixes
5541| [6160] Microsoft Windows 2000 event viewer buffer overflow
5542| [6136] Microsoft Windows 2000 domain controller denial of service
5543| [6035] Microsoft Windows 2000 Server RDP denial of service
5544| [5973] Microsoft Windows 2000 EFS allows local user to recover sensitive data
5545| [5936] Microsoft Windows 2000 Server Directory Service Restore Mode allows user to login with blank password
5546| [5800] Microsoft Windows 2000 Index Service ActiveX controls allow unauthorized access to file information
5547| [5623] Microsoft Windows NT and 2000 Phone Book service buffer overflow
5548| [5598] Microsoft Windows 2000 Telnet daemon could allow a denial of service
5549| [5585] Microsoft Windows 2000 brute force attack
5550| [5502] Microsoft Windows 2000 Indexing Services ixsso.query
5551| [5467] Microsoft Windows 2000 System Monitor ActiveX control buffer overflow
5552| [5399] Microsoft Windows NT and 2000 Network Monitor buffer overflow
5553| [5301] Microsoft Windows 2000 Simplified Chinese IME State Recognition
5554| [5263] Microsoft Office 2000 executes .dll without users knowledge
5555| [5242] Microsoft Windows 2000 Telnet client NTLM authentication weakness
5556| [5222] Microsoft Windows 2000 malformed RPC packet denial of service
5557| [5203] Microsoft Windows 2000 still image service
5558| [5171] Microsoft Windows 2000 Local Security Policy corruption
5559| [5080] Microsoft Office 2000 HTML object tag buffer overflow
5560| [5033] Microsoft Windows 2000 without Service Pack 1
5561| [5031] Microsoft Windows 2000 Service Control Manager named pipe could allow a unauthorized user to gain privileges
5562| [5015] Microsoft Windows NT and 2000 executable path
5563| [4887] Microsoft Windows 2000 Kerberos ticket renewed
5564| [4886] Microsoft Windows 2000 logon session reconnected
5565| [4885] Microsoft Windows 2000 logon session disconnected
5566| [4882] Microsoft Windows 2000 Kerberos pre-authentication failed
5567| [4873] Microsoft Windows 2000 user account mapped for logon
5568| [4872] Microsoft Windows 2000 account logon failed
5569| [4871] Microsoft Windows 2000 account used for logon
5570| [4855] Microsoft Windows 2000 group type change
5571| [4842] Microsoft Internet Explorer and Microsoft Powerpoint 2000 ActiveX object execution
5572| [4841] Microsoft Internet Explorer and Microsoft Access 2000 VBA code execution
5573| [4823] Microsoft Windows 2000 Telnet server binary stream denial of service
5574| [4819] Microsoft Windows 2000 default SYSKEY configuration
5575| [4787] Microsoft Windows 2000 user account locked out
5576| [4786] Microsoft Windows 2000 computer account created
5577| [4785] Microsoft Windows 2000 computer account changed
5578| [4784] Microsoft Windows 2000 computer account deleted
5579| [4714] Microsoft Windows 2000 "
5580| [4589] Microsoft Windows 2000 protected store can be compromised by brute force attack
5581| [4278] Microsoft Windows 2000 unattended install does not secure All Users profile
5582| [4138] Microsoft Windows 2000 system file integrity feature is disabled
5583| [4086] Microsoft Windows 2000 may not start Jaz drives correctly
5584| [4085] Microsoft Windows 2000 non-Gregorial calendar error
5585| [4084] Microsoft Windows 2000 may prevent Adobe FrameMaker files from being saved in some formats
5586| [4083] Microsoft Windows 2000 Terminal Services may damage Office files saved as HTML
5587| [4082] Microsoft Windows 2000 and Iomega parallel port drives display error
5588| [4080] Microsoft Windows 2000 AOL image support
5589| [4079] Microsoft Windows 2000 High Encryption Pack
5590| [3854] Microsoft Office 2000 security setting
5591| [1376] Microsoft Proxy 2.0 denial of service
5592| [86256] Microsoft Windows Knowledge Base Article 2876063 update is not installed
5593| [86097] Microsoft Windows Knowledge Base Article 2859537 update is not installed
5594| [86091] Microsoft Windows Knowledge Base Article 2868623 update is not installed
5595| [86089] Microsoft Windows Knowledge Base Article 2862772 update is not installed
5596| [86075] Microsoft Windows Knowledge Base Article 2850869 update is not installed
5597| [86073] Microsoft Windows Knowledge Base Article 2873872 update is not installed
5598| [86070] Microsoft Windows Knowledge Base Article 2849568 update is not installed
5599| [85245] Microsoft Windows Knowledge Base Article 2848295 update is not installed
5600| [85244] Microsoft Windows Knowledge Base Article 2847927 update is not installed
5601| [85243] Microsoft Windows Knowledge Base Article 2861561 update is not installed
5602| [85236] Microsoft Windows Knowledge Base Article 2850851 update is not installed
5603| [85227] Microsoft Windows Knowledge Base Article 2847883 update is not installed
5604| [85223] Microsoft Windows Knowledge Base Article 2846071 update is not installed
5605| [85205] Microsoft Windows Knowledge Base Article 2845187 update is not installed
5606| [84621] Microsoft Windows Knowledge Base Article 2845690 update is not installed
5607| [84619] Microsoft Windows Knowledge Base Article 2839894 update is not installed
5608| [84617] Microsoft Windows Knowledge Base Article 2839571 update is not installed
5609| [84615] Microsoft Windows Knowledge Base Article 2839229 update is not installed
5610| [84613] Microsoft Windows Knowledge Base Article 2838727 update is not installed
5611| [84156] Microsoft Windows Knowledge Base Article 2847204 update is not installed
5612| [83912] Microsoft Windows Knowledge Base Article 2829254 update is not installed
5613| [83910] Microsoft Windows Knowledge Base Article 2829530 update is not installed
5614| [83898] Microsoft Windows Knowledge Base Article 2830397 update is not installed
5615| [83886] Microsoft Windows Knowledge Base Article 2830399 update is not installed
5616| [83884] Microsoft Windows Knowledge Base Article 2834692 update is not installed
5617| [83882] Microsoft Windows Knowledge Base Article 2834695 update is not installed
5618| [83880] Microsoft Windows Knowledge Base Article 2836440 update is not installed
5619| [83876] Microsoft Windows Knowledge Base Article 2840221 update is not installed
5620| [83192] Microsoft Windows Knowledge Base Article 2817183 update is not installed
5621| [83100] Microsoft Windows Knowledge Base Article 2830914 update is not installed
5622| [83098] Microsoft Windows Knowledge Base Article 2829996 update is not installed
5623| [83093] Microsoft Windows Knowledge Base Article 2828223 update is not installed
5624| [83091] Microsoft Windows Knowledge Base Article 2813170 update is not installed
5625| [83088] Microsoft Windows Knowledge Base Article 2827663 update is not installed
5626| [83086] Microsoft Windows Knowledge Base Article 2823482 update is not installed
5627| [83084] Microsoft Windows Knowledge Base Article 2821818 update is not installed
5628| [83082] Microsoft Windows Knowledge Base Article 2820917 update is not installed
5629| [82600] Microsoft Windows Knowledge Base Article 2813707 update is not installed
5630| [82424] Microsoft Windows Knowledge Base Article 2814124 update is not installed
5631| [82422] Microsoft Windows Knowledge Base Article 2780176 update is not installed
5632| [82401] Microsoft Windows Knowledge Base Article 2813682 update is not installed
5633| [82399] Microsoft Windows Knowledge Base Article 2816264 update is not installed
5634| [81683] Microsoft Windows Knowledge Base Article 2780091 update is not installed
5635| [81681] Microsoft Windows Knowledge Base Article 2784242 update is not installed
5636| [81680] Microsoft Windows Knowledge Base Article 2790113 update is not installed
5637| [81678] Microsoft Windows Knowledge Base Article 2790655 update is not installed
5638| [81676] Microsoft Windows Knowledge Base Article 2790978 update is not installed
5639| [81674] Microsoft Windows Knowledge Base Article 2797052 update is not installed
5640| [81672] Microsoft Windows Knowledge Base Article 2799494 update is not installed
5641| [81666] Microsoft Windows Knowledge Base Article 2778344 update is not installed
5642| [81634] Microsoft Windows Knowledge Base Article 2792100 update is not installed
5643| [81339] Microsoft Windows Knowledge Base Article 2799329 update is not installed
5644| [80875] Microsoft Windows Knowledge Base Article 2756145 update is not installed
5645| [80872] Microsoft Windows Knowledge Base Article 2769324 update is not installed
5646| [80867] Microsoft Windows Knowledge Base Article 2769327 update is not installed
5647| [80865] Microsoft Windows Knowledge Base Article 2769369 update is not installed
5648| [80863] Microsoft Windows Knowledge Base Article 2778930 update is not installed
5649| [80861] Microsoft Windows Knowledge Base Article 2785220 update is not installed
5650| [80365] Microsoft Windows Knowledge Base Article 2761465 update is not installed
5651| [80360] Microsoft Windows Knowledge Base Article 2765809 update is not installed
5652| [80358] Microsoft Windows Knowledge Base Article 2770660 update is not installed
5653| [80356] Microsoft Windows Knowledge Base Article 2780642 update is not installed
5654| [80352] Microsoft Windows Knowledge Base Article 2783534 update is not installed
5655| [80349] Microsoft Windows Knowledge Base Article 2784126 update is not installed
5656| [79693] Microsoft Windows Knowledge Base Article 2745030 update is not installed
5657| [79687] Microsoft Windows Knowledge Base Article 2761451 update is not installed
5658| [79683] Microsoft Windows Knowledge Base Article 2761226 update is not installed
5659| [79679] Microsoft Windows Knowledge Base Article 2758857 update is not installed
5660| [79677] Microsoft Windows Knowledge Base Article 2727528 update is not installed
5661| [78864] Microsoft Windows Knowledge Base Article 2754670 update is not installed
5662| [78862] Microsoft Windows Knowledge Base Article 2743555 update is not installed
5663| [78858] Microsoft Windows Knowledge Base Article 2754849 update is not installed
5664| [78856] Microsoft Windows Knowledge Base Article 2724197 update is not installed
5665| [78853] Microsoft Windows Knowledge Base Article 2741517 update is not installed
5666| [78851] Microsoft Windows Knowledge Base Article 2742319 update is not installed
5667| [78848] Microsoft Windows Knowledge Base Article 2742321 update is not installed
5668| [78760] Microsoft Windows Knowledge Base Article 2744842 update is not installed
5669| [78077] Microsoft Windows Knowledge Base Article 2741528 update is not installed
5670| [78075] Microsoft Windows Knowledge Base Article 2720184 update is not installed
5671| [78071] Microsoft Windows Knowledge Base Article 2748552 update is not installed
5672| [77512] Microsoft Windows Knowledge Base Article 2740358 update is not installed
5673| [77362] Microsoft Windows Knowledge Base Article 2733918 update is not installed
5674| [77360] Microsoft Windows Knowledge Base Article 2733829 update is not installed
5675| [77357] Microsoft Windows Knowledge Base Article 2733594 update is not installed
5676| [77352] Microsoft Windows Knowledge Base Article 2731879 update is not installed
5677| [77350] Microsoft Windows Knowledge Base Article 2731847 update is not installed
5678| [77348] Microsoft Windows Knowledge Base Article 2723135 update is not installed
5679| [77346] Microsoft Windows Knowledge Base Article 2722913 update is not installed
5680| [77342] Microsoft Windows Knowledge Base Article 2720573 update is not installed
5681| [77325] Microsoft Windows Knowledge Base Article 2719584 update is not installed
5682| [76808] Microsoft Windows Knowledge Base Article 2721015 update is not installed
5683| [76725] Microsoft Windows Knowledge Base Article 2722479 update is not installed
5684| [76724] Microsoft Windows Knowledge Base Article 2719177 update is not installed
5685| [76721] Microsoft Windows Knowledge Base Article 2718523 update is not installed
5686| [76718] Microsoft Windows Knowledge Base Article 2698365 update is not installed
5687| [76711] Microsoft Windows Knowledge Base Article 2695502 update is not installed
5688| [76704] Microsoft Windows Knowledge Base Article 2691442 update is not installed
5689| [76702] Microsoft Windows Knowledge Base Article 2655992 update is not installed
5690| [75963] Microsoft Windows Knowledge Base Article 2699988 update is not installed
5691| [75939] Microsoft Windows Knowledge Base Article 2685939 update is not installed
5692| [75928] Microsoft Windows Knowledge Base Article 2711167 update is not installed
5693| [75136] Microsoft Windows Knowledge Base Article 2693777 update is not installed
5694| [75132] Microsoft Windows Knowledge Base Article 2690533 update is not installed
5695| [75130] Microsoft Windows Knowledge Base Article 2688338 update is not installed
5696| [75127] Microsoft Windows Knowledge Base Article 2681578 update is not installed
5697| [75123] Microsoft Windows Knowledge Base Article 2680352 update is not installed
5698| [75116] Microsoft Windows Knowledge Base Article 2597981 update is not installed
5699| [74556] Microsoft Windows Knowledge Base Article 2639185 update is not installed
5700| [74384] Microsoft Windows Knowledge Base Article 2675157 update is not installed
5701| [74378] Microsoft Windows Knowledge Base Article 2671605 update is not installed
5702| [74373] Microsoft Windows Knowledge Base Article 2664258 update is not installed
5703| [74369] Microsoft Windows Knowledge Base Article 2663860 update is not installed
5704| [73543] Microsoft Windows Knowledge Base Article 2671387 update is not installed
5705| [73540] Microsoft Windows Knowledge Base Article 2665364 update is not installed
5706| [73538] Microsoft Windows Knowledge Base Article 2651019 update is not installed
5707| [73536] Microsoft Windows Knowledge Base Article 2651018 update is not installed
5708| [73533] Microsoft Windows Knowledge Base Article 2647170 update is not installed
5709| [73530] Microsoft Windows Knowledge Base Article 2641653 update is not installed
5710| [72887] Microsoft Windows Knowledge Base Article 2663841 update is not installed
5711| [72873] Microsoft Windows Knowledge Base Article 2663830 update is not installed
5712| [72867] Microsoft Windows Knowledge Base Article 2663510 update is not installed
5713| [72857] Microsoft Windows Knowledge Base Article 2661637 update is not installed
5714| [72855] Microsoft Windows Knowledge Base Article 2660465 update is not installed
5715| [72853] Microsoft Windows Knowledge Base Article 2653956 update is not installed
5716| [72851] Microsoft Windows Knowledge Base Article 2654428 update is not installed
5717| [72849] Microsoft Windows Knowledge Base Article 2651026 update is not installed
5718| [72846] Microsoft Windows Knowledge Base Article 2647516 update is not installed
5719| [72841] Microsoft Windows Knowledge Base Article 2645640 update is not installed
5720| [72838] Microsoft Windows Knowledge Base Article 2643719 update is not installed
5721| [72029] Microsoft Windows Knowledge Base Article 2638420 update is not installed
5722| [72003] Microsoft Windows Knowledge Base Article 2646524 update is not installed
5723| [71998] Microsoft Windows Knowledge Base Article 2644615 update is not installed
5724| [71995] Microsoft Windows Knowledge Base Article 2643584 update is not installed
5725| [71994] Microsoft Windows Knowledge Base Article 2636391 update is not installed
5726| [71565] Microsoft Windows Knowledge Base Article 2648048 update is not installed
5727| [71562] Microsoft Windows Knowledge Base Article 2640241 update is not installed
5728| [71560] Microsoft Windows Knowledge Base Article 2640045 update is not installed
5729| [71558] Microsoft Windows Knowledge Base Article 2639417 update is not installed
5730| [71557] Microsoft Windows Knowledge Base Article 2639142 update is not installed
5731| [71554] Microsoft Windows Knowledge Base Article 2633171 update is not installed
5732| [71552] Microsoft Windows Knowledge Base Article 2624667 update is not installed
5733| [71550] Microsoft Windows Knowledge Base Article 2620712 update is not installed
5734| [71548] Microsoft Windows Knowledge Base Article 2618451 update is not installed
5735| [71546] Microsoft Windows Knowledge Base Article 2618444 update is not installed
5736| [71538] Microsoft Windows Knowledge Base Article 2590602 update is not installed
5737| [70951] Microsoft Windows Knowledge Base Article 2630837 update is not installed
5738| [70949] Microsoft Windows Knowledge Base Article 2620704 update is not installed
5739| [70947] Microsoft Windows Knowledge Base Article 2617657 update is not installed
5740| [70943] Microsoft Windows Knowledge Base Article 2588516 update is not installed
5741| [70152] Microsoft Windows Knowledge Base Article 2623699 update is not installed
5742| [70140] Microsoft Windows Knowledge Base Article 2652016 update is not installed
5743| [70130] Microsoft Windows Knowledge Base Article 2586448 update is not installed
5744| [70115] Microsoft Windows Knowledge Base Article 2567053 update is not installed
5745| [69501] Microsoft Windows Knowledge Base Article 2587634 update is not installed
5746| [69498] Microsoft Windows Knowledge Base Article 2587505 update is not installed
5747| [69492] Microsoft Windows Knowledge Base Article 2571621 update is not installed
5748| [69490] Microsoft Windows Knowledge Base Article 2570947 update is not installed
5749| [68840] Microsoft Windows Knowledge Base Article 2451858 update is not installed
5750| [68833] Microsoft Windows Knowledge Base Article 2567943 update is not installed
5751| [68831] Microsoft Windows Knowledge Base Article 2570222 update is not installed
5752| [68829] Microsoft Windows Knowledge Base Article 2567951 update is not installed
5753| [68827] Microsoft Windows Knowledge Base Article 2578230 update is not installed
5754| [68825] Microsoft Windows Knowledge Base Article 2546250 update is not installed
5755| [68823] Microsoft Windows Knowledge Base Article 2559049 update is not installed
5756| [68816] Microsoft Windows Knowledge Base Article 2556532 update is not installed
5757| [68814] Microsoft Windows Knowledge Base Article 2560656 update is not installed
5758| [68812] Microsoft Windows Knowledge Base Article 2560978 update is not installed
5759| [68809] Microsoft Windows Knowledge Base Article 2562485 update is not installed
5760| [68806] Microsoft Windows Knowledge Base Article 2566454 update is not installed
5761| [68804] Microsoft Windows Knowledge Base Article 2563894 update is not installed
5762| [68801] Microsoft Windows Knowledge Base Article 2567680 update is not installed
5763| [68315] Microsoft Windows Knowledge Base Article 2555917 update is not installed
5764| [68299] Microsoft Windows Knowledge Base Article 2566220 update is not installed
5765| [68283] Microsoft Windows Knowledge Base Article 2560847 update is not installed
5766| [67955] Microsoft Windows Knowledge Base Article 2530548 update is not installed
5767| [67943] Microsoft Windows Knowledge Base Article 2544521 update is not installed
5768| [67762] Microsoft Windows Knowledge Base Article 2543893 update is not installed
5769| [67759] Microsoft Windows Knowledge Base Article 2544893 update is not installed
5770| [67757] Microsoft Windows Knowledge Base Article 2476490 update is not installed
5771| [67753] Microsoft Windows Knowledge Base Article 2514842 update is not installed
5772| [67751] Microsoft Windows Knowledge Base Article 2518295 update is not installed
5773| [67737] Microsoft Windows Knowledge Base Article 2520426 update is not installed
5774| [67733] Microsoft Windows Knowledge Base Article 2525694 update is not installed
5775| [67731] Microsoft Windows Knowledge Base Article 2525835 update is not installed
5776| [67728] Microsoft Windows Knowledge Base Article 2535512 update is not installed
5777| [67725] Microsoft Windows Knowledge Base Article 2536275 update is not installed
5778| [67722] Microsoft Windows Knowledge Base Article 2536276 update is not installed
5779| [67718] Microsoft Windows Knowledge Base Article 2537146 update is not installed
5780| [67709] Microsoft Windows Knowledge Base Article 2538814 update is not installed
5781| [67302] Microsoft Windows Knowledge Base Article 2545814 update is not installed
5782| [67101] Microsoft Windows Knowledge Base Article 2524426 update is not installed
5783| [66446] Microsoft Windows Knowledge Base Article 2514666 update is not installed
5784| [66444] Microsoft Windows Knowledge Base Article 2511455 update is not installed
5785| [66436] Microsoft Windows Knowledge Base Article 2497640 update is not installed
5786| [66432] Microsoft Windows Knowledge Base Article 2527308 update is not installed
5787| [66428] Microsoft Windows Knowledge Base Article 2489979 update is not installed
5788| [66423] Microsoft Windows kernel-mode driver (win32k.sys) variant 29 privilege escalation
5789| [66422] Microsoft Windows kernel-mode driver (win32k.sys) variant 28 privilege escalation
5790| [66421] Microsoft Windows kernel-mode driver (win32k.sys) variant 27 privilege escalation
5791| [66420] Microsoft Windows kernel-mode driver (win32k.sys) variant 26 privilege escalation
5792| [66419] Microsoft Windows kernel-mode driver (win32k.sys) variant 25 privilege escalation
5793| [66418] Microsoft Windows kernel-mode driver (win32k.sys) variant 24 privilege escalation
5794| [66417] Microsoft Windows kernel-mode driver (win32k.sys) variant 23 privilege escalation
5795| [66416] Microsoft Windows kernel-mode driver (win32k.sys) variant 22 privilege escalation
5796| [66415] Microsoft Windows kernel-mode driver (win32k.sys) variant 21 privilege escalation
5797| [66414] Microsoft Windows kernel-mode driver (win32k.sys) variant 20 privilege escalation
5798| [66396] Microsoft Windows kernel-mode driver (win32k.sys) variant 2 privilege escalation
5799| [66394] Microsoft Windows Knowledge Base Article 2485663 update is not installed
5800| [65588] Microsoft Windows Knowledge Base Article 2489279 update is not installed
5801| [65581] Microsoft Windows Knowledge Base Article 2510030 update is not installed
5802| [65580] Microsoft Windows Knowledge Base Article 2489283 update is not installed
5803| [65575] Microsoft Windows Knowledge Base Article 2489293 update is not installed
5804| [65573] Microsoft Windows Knowledge Base Article 2494047 update is not installed
5805| [64973] Microsoft Windows Knowledge Base Article 2478960 update is not installed
5806| [64971] Microsoft Windows Knowledge Base Article 2479628 update is not installed
5807| [64927] Microsoft Windows Knowledge Base Article 2393802 update is not installed
5808| [64925] Microsoft Windows Knowledge Base Article 2451879 update is not installed
5809| [64920] Microsoft Windows Knowledge Base Article 2475792 update is not installed
5810| [64918] Microsoft Windows Knowledge Base Article 2476687 update is not installed
5811| [64916] Microsoft Windows Knowledge Base Article 2478953 update is not installed
5812| [64914] Microsoft Windows Knowledge Base Article 2482017 update is not installed
5813| [64910] Microsoft Windows Knowledge Base Article 2483185 update is not installed
5814| [64909] Microsoft Windows Knowledge Base Article 2484015 update is not installed
5815| [64907] Microsoft Windows Knowledge Base Article 2485376 update is not installed
5816| [64905] Microsoft Windows Knowledge Base Article 2489256 update is not installed
5817| [64902] Microsoft Windows Knowledge Base Article 2496930 update is not installed
5818| [64342] Microsoft Windows Knowledge Base Article 2451910 update is not installed
5819| [64339] Microsoft Windows Knowledge Base Article 2478935 update is not installed
5820| [63584] Microsoft Windows Knowledge Base Article 2424434 update is not installed
5821| [63582] Microsoft Windows Knowledge Base Article 2423089 update is not installed
5822| [63580] Microsoft Windows Knowledge Base Article 2436673 update is not installed
5823| [63571] Microsoft Windows Knowledge Base Article 2440591 update is not installed
5824| [63569] Microsoft Windows Knowledge Base Article 2385678 update is not installed
5825| [63566] Microsoft Windows Knowledge Base Article 2442962 update is not installed
5826| [63564] Microsoft Windows Knowledge Base Article 2345316 update is not installed
5827| [63562] Microsoft Windows Knowledge Base Article 2296199 update is not installed
5828| [63558] Microsoft Windows Knowledge Base Article 2416400 update is not installed
5829| [63550] Microsoft Windows Knowledge Base Article 2447961 update is not installed
5830| [63548] Microsoft Windows Knowledge Base Article 2443105 update is not installed
5831| [63546] Microsoft Windows Knowledge Base Article 2455005 update is not installed
5832| [63544] Microsoft Windows Knowledge Base Article 2292970 update is not installed
5833| [62805] Microsoft Windows Knowledge Base Article 2316074 update is not installed
5834| [62793] Microsoft Windows Knowledge Base Article 2293386 update is not installed
5835| [62789] Microsoft Windows Knowledge Base Article 2423930 update is not installed
5836| [62170] Microsoft Windows Knowledge Base Article 2296011 update is not installed
5837| [62166] Microsoft Windows Knowledge Base Article 2294255 update is not installed
5838| [62163] Microsoft Windows Knowledge Base Article 2281679 update is not installed
5839| [62154] Microsoft Windows Knowledge Base Article 2279986 update is not installed
5840| [62147] Microsoft Windows Knowledge Base Article 2160841 update is not installed
5841| [62134] Microsoft Windows Knowledge Base Article 2412048 update is not installed
5842| [62129] Microsoft Windows Knowledge Base Article 2387149 update is not installed
5843| [62126] Microsoft Windows Knowledge Base Article 2378111 update is not installed
5844| [62123] Microsoft Windows Knowledge Base Article 2360937 update is not installed
5845| [62118] Microsoft Windows Knowledge Base Article 2293211 update is not installed
5846| [62104] Microsoft Windows Knowledge Base Article 2360131 update is not installed
5847| [62098] Microsoft Windows Knowledge Base Article 2293194 update is not installed
5848| [62069] Microsoft Windows Knowledge Base Article 2418042 update is not installed
5849| [61519] Microsoft Windows Knowledge Base Article 2121546 update is not installed
5850| [61517] Microsoft Windows Knowledge Base Article 2259922 update is not installed
5851| [61514] Microsoft Windows Knowledge Base Article 2267960 update is not installed
5852| [61510] Microsoft Windows Knowledge Base Article 2315011 update is not installed
5853| [61507] Microsoft Windows Knowledge Base Article 2320113 update is not installed
5854| [61504] Microsoft Windows Knowledge Base Article 2347290 update is not installed
5855| [60736] Microsoft Windows Knowledge Base Article 2265906 update is not installed
5856| [60734] Microsoft Windows Knowledge Base Article 2269638 update is not installed
5857| [60728] Microsoft Windows Knowledge Base Article 2269707 update is not installed
5858| [60724] Microsoft Windows Knowledge Base Article 2286198 update is not installed
5859| [60713] Microsoft Windows Knowledge Base Article 2183461 update is not installed
5860| [60698] Microsoft Windows Knowledge Base Article 2160329 update is not installed
5861| [60686] Microsoft Windows Knowledge Base Article 2115168 update is not installed
5862| [60684] Microsoft Windows Knowledge Base Article 2079403 update is not installed
5863| [60680] Microsoft Windows Knowledge Base Article 2264072 update is not installed
5864| [59901] Microsoft Windows Knowledge Base Article 2229593 update is not installed
5865| [59898] Microsoft Windows Knowledge Base Article 2229593 update is not installed
5866| [58913] Microsoft Windows Knowledge Base Article 2027452 update is not installed
5867| [58891] Microsoft Windows Knowledge Base Article 2028554 update is not installed
5868| [17004] Microsoft Windows XP Service Pack 2 is not installed on the system
5869| [9187] Microsoft Passport SDK 2.1 Component Configuration Document (CCD) permission
5870| [9146] Microsoft Passport SDK 2.1 events reporting disabled
5871| [9068] Microsoft Passport SDK 2.1 registry default permission exposure
5872| [9067] Microsoft Passport SDK 2.1 default test site exposure
5873| [9066] Microsoft Passport SDK 2.1 Adventure Works Sample Site exposure
5874| [9065] Microsoft Passport SDK 2.1 Adventure Works Sample Site global.asa file default permission exposure
5875| [9064] Microsoft Passport SDK 2.1 default time window exposure
5876| [1271] Microsoft IIS version 2 installed
5877| [621] Microsoft IIS 3.0 script source revealed by appending 2E to requests
5878|
5879| Exploit-DB - https://www.exploit-db.com:
5880| [30756] Microsoft Forms 2.0 ActiveX Control 2.0 Memory Access Violation Denial of Service Vulnerabilities
5881| [30749] Microsoft Office 2003 Web Component Memory Access Violation Denial of Service Vulnerability
5882| [30636] Microsoft Windows 2000/2003 Recursive DNS Spoofing Vulnerability (2)
5883| [30635] Microsoft Windows 2000/2003 Recursive DNS Spoofing Vulnerability (1)
5884| [30281] Microsoft .Net Framework <= 2.0 - Multiple Null Byte Injection Vulnerabilities
5885| [29664] Microsoft Office Publisher 2007 - Remote Denial of Service (DoS) Vulnerability
5886| [29660] Microsoft Office 2003 - Denial of Service (DoS) Vulnerability
5887| [29630] Microsoft Windows 2003/XP ReadDirectoryChangesW Information Disclosure Vulnerability
5888| [29524] Microsoft Word 2000 - Malformed Function Code Execution Vulnerability
5889| [28420] Microsoft Windows 2000 Multiple COM Object Instantiation Code Execution Vulnerabilities
5890| [28357] Microsoft Windows Explorer 2000/2003/XP Drag and Drop Remote Code Execution Vulnerability
5891| [28227] Microsoft Windows 2000/XP Registry Access Local Denial of Service Vulnerability
5892| [28226] Microsoft PowerPoint 2003 PPT File Closure Memory Corruption
5893| [28225] Microsoft PowerPoint 2003 powerpnt.exe Unspecified Issue
5894| [28224] Microsoft PowerPoint 2003 mso.dll PPT Processing Unspecified Code Execution
5895| [28198] Microsoft Office 2000/2002 Property Code Execution Vulnerability
5896| [28189] Microsoft Excel 2000-2004 Style Handling and Repair Remote Code Execution Vulnerability
5897| [28087] Microsoft Office 2003 Embedded Shockwave Flash Object Security Bypass Weakness
5898| [28005] Microsoft Exchange Server 2000/2003 Outlook Web Access Script Injection Vulnerability
5899| [26690] Microsoft Windows 2000/2003/XP CreateRemoteThread Local Denial of Service Vulnerability
5900| [26517] Microsoft Office PowerPoint 2007 - Crash PoC
5901| [26341] Microsoft Windows 2000/2003/XP MSDTC TIP Denial of Service Vulnerability
5902| [26222] Microsoft Windows 2000/2003/XP Keyboard Event Privilege Escalation Weakness
5903| [25384] Microsoft Windows 2000/XP Internet Protocol Validation Remote Code Execution Vulnerability (2)
5904| [25383] Microsoft Windows 2000/XP Internet Protocol Validation Remote Code Execution Vulnerability (1)
5905| [25231] Microsoft Windows 2000/2003/XP Graphical Device Interface Library Denial of Service Vulnerability
5906| [25085] Microsoft Office XP 2000/2002 HTML Link Processing Remote Buffer Overflow Vulnerability
5907| [25084] Microsoft Outlook 2003 Web Access Login Form Remote URI Redirection Vulnerability
5908| [25050] Microsoft Windows 2000/2003/XP winhlp32 Phrase Heap Overflow Vulnerability
5909| [25049] Microsoft Windows 2000/2003/XP winhlp32 Phrase Integer Overflow Vulnerability
5910| [24686] Microsoft Outlook 2003 Security Policy Bypass Vulnerability
5911| [24277] Microsoft Windows 2000/NT 4 POSIX Subsystem Buffer Overflow Local Privilege Escalation Vulnerability
5912| [24114] Microsoft Outlook 2003Mail Client E-mail Address Verification Weakness
5913| [24101] Microsoft Outlook 2003 Predictable File Location Weakness
5914| [23989] Microsoft Windows 2000/NT 4 Local Descriptor Table Local Privilege Escalation Vulnerability
5915| [23796] Microsoft Outlook 2002 Mailto Parameter Quoting Zone Bypass Vulnerability
5916| [23019] Microsoft Windows 2000 Subnet Bandwidth Manager RSVP Server Authority Hijacking Vulnerability
5917| [22919] Microsoft ISA Server 2000 Cross-Site Scripting Vulnerabilities
5918| [22883] Microsoft Windows 2000 CreateFile API Named Pipe Privilege Escalation Vulnerability (2)
5919| [22882] Microsoft Windows 2000 CreateFile API Named Pipe Privilege Escalation Vulnerability (1)
5920| [22837] Microsoft Windows 2000/NT 4 Media Services NSIISlog.DLL Remote Buffer Overflow
5921| [22782] Microsoft Windows 2000 Active Directory Remote Stack Overflow Vulnerability
5922| [22591] Microsoft Office Excel 2007 - WriteAV Crash PoC
5923| [22555] Microsoft BizTalk Server 2000/2002 DTA RawCustomSearchField.asp SQL Injection
5924| [22554] Microsoft BizTalk Server 2000/2002 DTA rawdocdata.asp SQL Injection Vulnerability
5925| [22553] Microsoft BizTalk Server 2002 HTTP Receiver Buffer Overflow Vulnerability
5926| [22528] Microsoft Windows 2000 RegEdit.EXE Registry Key Value Buffer Overflow Vulnerability
5927| [22354] Microsoft Windows 2000 Help Facility .CNT File :Link Buffer Overflow Vulnerability
5928| [21920] Microsoft Content Management Server 2001 Cross-Site Scripting Vulnerability
5929| [21718] Microsoft SQL 2000/7.0 Agent Jobs Privilege Elevation Vulnerability
5930| [21693] Microsoft SQL Server 2000 User Authentication Remote Buffer Overflow Vulnerability
5931| [21652] Microsoft SQL Server 2000 Resolution Service Heap Overflow Vulnerability
5932| [21651] Microsoft SQL Server 2000 sp_MScopyscript SQL Injection Vulnerability
5933| [21650] Microsoft SQL Server 2000 Database Consistency Checkers Buffer Overflow Vulnerability
5934| [21549] Microsoft SQL Server 2000 Password Encrypt Procedure Buffer Overflow Vulnerability
5935| [21541] Microsoft SQL Server 2000 SQLXML Script Injection Vulnerability
5936| [21540] Microsoft SQL Server 2000 SQLXML Buffer Overflow Vulnerability
5937| [21389] Microsoft Windows 2000 Lanman Denial of Service Vulnerability (2)
5938| [21388] Microsoft Windows 2000 Lanman Denial of Service Vulnerability (1)
5939| [21344] Microsoft Windows 2000 / NT 4.0 Process Handle Local Privilege Elevation Vulnerability
5940| [21258] Microsoft Windows 2000/NT 4 NTFS File Hiding Vulnerability
5941| [21246] Microsoft Windows 2000/NT 4 TCP Stack DoS Vulnerability (2)
5942| [21245] Microsoft Windows 2000/NT 4 TCP Stack DoS Vulnerability (1)
5943| [21172] Microsoft Windows 2000 Internet Key Exchange DoS Vulnerability (2)
5944| [21171] Microsoft Windows 2000 Internet Key Exchange DoS Vulnerability (1)
5945| [21131] Microsoft Windows 2000/XP GDI Denial of Service Vulnerability
5946| [21123] Microsoft Windows 2000/NT Terminal Server Service RDP DoS Vulnerability
5947| [21113] Microsoft Index Server 2.0 File Information and Path Disclosure Vulnerability
5948| [21099] Microsoft Windows 2000 RunAs Service Denial of Services Vulnerability
5949| [21069] Microsoft Windows 2000 RunAs Service Named Pipe Hijacking Vulnerability
5950| [20907] Microsoft Windows 2000 Telnet Username DoS Vulnerability
5951| [20802] Microsoft IIS 2.0/3.0 Long URL Denial of Service Vulnerability
5952| [20763] Microsoft ISA Server 2000 Web Proxy DoS Vulnerability
5953| [20571] Microsoft Outlook 2000 0/98 0/Express 5.5 Concealed Attachment Vulnerability
5954| [20481] Microsoft IIS 2.0/3.0 Appended Dot Script Source Disclosure Vulnerability
5955| [20399] Microsoft Indexing Services for Windows 2000 File Verification Vulnerability
5956| [20335] Microsoft Indexing Services for Windows 2000/NT 4.0 .htw Cross-Site Scripting Vulnerability
5957| [20305] Microsoft Site Server 2.0 with IIS 4.0 - File Upload Vulnerability
5958| [20265] Microsoft Windows NT 4.0 / 2000 Spoofed LPC Request Vulnerability
5959| [20257] Microsoft Windows NT 4.0 / 2000 Predictable LPC Message Identifier Multiple Vulnerabilities
5960| [20255] Microsoft Windows NT 4.0 / 2000 LPC Zone Memory Depletion DoS Vulnerability
5961| [20222] Microsoft Windows 2000 telnet.exe NTLM Authentication Vulnerability
5962| [20209] Microsoft Windows 2000 Still Image Service Privilege Escalation Vulnerability
5963| [20133] Microsoft Windows 2000 Named Pipes Predictability Vulnerability
5964| [20122] Microsoft Office SharePoint Server 2007 Remote Code Execution
5965| [20096] Microsoft IIS 2.0/3.0/4.0/5.0/5.1 Internal IP Address Disclosure Vulnerability
5966| [20048] Microsoft Windows 2000 Remote CPU-overload Vulnerability
5967| [20047] Microsoft Windows 2000 Telnet Server DoS Vulnerability
5968| [19830] Microsoft Index Server 2.0 '%20' ASP Source Disclosure Vulnerability
5969| [19742] microsoft iis 3.0/4.0,microsoft index server 2.0 - Directory Traversal
5970| [19734] Microsoft Virtual Machine 2000 Series/3000 Series getSystemResource Vulnerability
5971| [19731] microsoft index server 2.0/indexing services for windows 2000 - Directory Traversal
5972| [19728] Microsoft Systems Management Server 2.0 Default Permissions Vulnerability
5973| [19425] Microsoft Data Access Components (MDAC) <= 2.1,Microsoft IIS 3.0/4.0,Microsoft Index Server 2.0,Microsoft Site Server Commerce Edition 3.0 i386 MDAC RDS Vulnerability (2)
5974| [19424] Microsoft Data Access Components (MDAC) <= 2.1,Microsoft IIS 3.0/4.0,Microsoft Index Server 2.0,Microsoft Site Server Commerce Edition 3.0 i386 MDAC RDS Vulnerability (1)
5975| [19376] Microsoft IIS 2.0/3.0/4.0 ISAPI GetExtensionVersion() Vulnerability
5976| [19143] "Microsoft Windows ""April Fools 2001"" Vulnerability"
5977| [19118] Microsoft IIS 3.0/4.0,Microsoft Personal Web Server 2.0/3.0/4.0 ASP Alternate Data Streams Vulnerability
5978| [18334] Microsoft Office 2003 Home/Pro 0day
5979| [18087] MS11-021 Microsoft Office 2007 Excel .xlb Buffer Overflow
5980| [18078] Microsoft Excel 2003 11.8335.8333 Use After Free
5981| [18067] Microsoft Excel 2007 SP2 Buffer Overwrite Exploit
5982| [17305] "Microsoft Windows Vista/Server 2008 ""nsiproxy.sys"" Local Kernel DoS Exploit"
5983| [14971] MOAUB #11 - Microsoft Office Word 2007 sprmCMajority Buffer Overflow
5984| [14782] Microsoft Office PowerPoint 2007 DLL Hijacking Exploit (rpawinet.dll)
5985| [14746] Microsoft Office Groove 2007 DLL Hijacking Exploit (mso.dll)
5986| [14744] Microsoft Visio 2003 DLL Hijacking Exploit (mfc71enu.dll)
5987| [12450] Microsoft SharePoint Server 2007 XSS Vulnerability
5988| [10068] Microsoft Windows 2000-2008 Embedded OpenType Font Engine Remote Code Execution
5989| [4121] Microsoft Excel 2000/2003 Sheet Name Vulnerability PoC
5990| [3973] Microsoft Office 2000 (OUACTRL.OCX 1.0.1.9) - Remote DoS Exploit
5991| [3690] microsoft office word 2007 - Multiple Vulnerabilities
5992| [3260] Microsoft Word 2000 Unspecified Code Execution Exploit (0day)
5993| [2523] Microsoft Office 2003 PPT Local Buffer Overflow PoC
5994| [2091] Microsoft PowerPoint 2003 SP2 Local Code Execution Exploit (french)
5995| [2001] Microsoft Word 2000/2003 Unchecked Boundary Condition Vulnerability
5996| [1999] Microsoft Word 2000/2003 Hlink Local Buffer Overflow Exploit PoC
5997| [1988] Microsoft Excel 2003 Hlink Local Buffer Overflow Exploit (italian)
5998| [1986] Microsoft Excel 2000/2003 Hlink Local Buffer Overflow Exploit (french)
5999| [1958] Microsoft Excel 2003 Hlink Stack/SEH Buffer Overflow Exploit
6000| [28238] Microsoft SharePoint 2013 (Cloud) - Persistent Exception Handling Vulnerability MS13-067
6001| [23034] Microsoft URLScan 2.5/ RSA Security SecurID 5.0 Configuration Enumeration Weakness
6002| [22850] Microsoft Office OneNote 2010 Crash PoC
6003| [22679] Microsoft Visio 2010 Crash PoC
6004| [22655] Microsoft Publisher 2013 Crash PoC
6005| [22621] Microsoft Netmeeting 2.1/3.0.1 4.4.3385 CALLTO URL Buffer Overflow Vulnerability
6006| [22330] Microsoft Office Excel 2010 Crash PoC
6007| [22310] Microsoft Office Publisher 2010 Crash PoC
6008| [22237] Microsoft Office Picture Manager 2010 Crash PoC
6009| [22215] Microsoft Office Word 2010 Crash PoC
6010| [19451] Microsoft Windows 98 a/98 b/98SE,Solaris 2.6 IRDP Vulnerability
6011| [19440] Microsoft Windows NT 4.0/SP 1/SP 2/Sp 3/SP 4/SP 5 Malformed Dialer Entry Vulnerability
6012| [19372] Microsoft Windows NT 4.0/SP 1/SP 2/SP 3/SP 4/SP 5 Null Session Admin Name Vulnerability
6013| [17164] Microsoft Reader <= 2.1.1.3143 NULL Byte Write
6014| [17163] Microsoft Reader <= 2.1.1.3143 Array Overflow
6015| [17162] Microsoft Reader <= 2.1.1.3143 Integer Overflow
6016| [17161] Microsoft Reader <= 2.1.1.3143 Heap Overflow
6017| [17160] Microsoft Reader <= 2.1.1.3143 Integer Overflow
6018| [14731] Microsoft Windows Movie Maker <= 2.6.4038.0 DLL Hijacking Exploit (hhctrl.ocx)
6019| [14723] Microsoft Power Point 2010 DLL Hijacking Exploit (pptimpconv.dll)
6020|
6021| OpenVAS (Nessus) - http://www.openvas.org:
6022| [902250] Microsoft Word 2003 'MSO.dll' Null Pointer Dereference Vulnerability
6023| [900125] Microsoft SQL Server 2000 sqlvdir.dll ActiveX Buffer Overflow Vulnerability
6024| [801597] Microsoft Office Excel 2003 Invalid Object Type Remote Code Execution Vulnerability
6025| [801596] Microsoft Excel 2007 Office Drawing Layer Remote Code Execution Vulnerability
6026| [801594] Microsoft PowerPoint 2007 OfficeArt Atom Remote Code Execution Vulnerability
6027| [800687] Microsoft Windows Server 2003 OpenType Font Engine DoS Vulnerability
6028| [800577] Microsoft Windows Server 2003 win32k.sys DoS Vulnerability
6029| [800343] Microsoft Word 2007 Sensitive Information Disclosure Vulnerability
6030| [103254] Microsoft SharePoint Server 2007 '_layouts/help.aspx' Cross Site Scripting Vulnerability
6031| [11992] Vulnerability in Microsoft ISA Server 2000 H.323 Filter(816458)
6032| [902931] Microsoft Office Remote Code Execution Vulnerabilities - 2720184 (Mac OS X)
6033| [902678] Microsoft Silverlight Code Execution Vulnerabilities - 2681578 (Mac OS X)
6034| [901210] Microsoft Office Privilege Elevation Vulnerability - 2721015 (Mac OS X)
6035|
6036| SecurityTracker - https://www.securitytracker.com:
6037| [1015347] Microsoft Windows 2000 Kernel APC Queue Bug Lets Local Users Gain Elevated Privileges
6038| [1013454] Microsoft Office InfoPath 2003 May Disclose System and Authentication Information to Remote Users
6039| [1013284] Microsoft Windows 2000 and XP Group Policy Can Be Bypassed By Microsoft Office Applications and By Flash Drives
6040| [1010687] Microsoft Windows 2000/NT POSIX Subsystem Buffer Overflow Lets Local Users Gain Elevated Privileges
6041| [1010352] Microsoft Windows 2000 Domains With Eight Characters May Let Remote Users With Expired Passwords Login
6042| [1010189] Microsoft Outlook 2003 Scripting Restrictions Can Be Bypassed By Remote Users
6043| [1010125] Microsoft Outlook 2003 Lets Remote Users Send E-mail to Cause the Recipient's Client to Contact a Remote Server
6044| [1009767] Microsoft Windows 2000 Domain Controller LDAP Flaw May Let Remote Users Restart the Authentication Service
6045| [1008324] Microsoft Exchange 2003 With Outlook Web Access and Windows SharePoint Services May Grant Incorrect E-mail Account Access to Remote Authenticated Users
6046| [1007905] Microsoft Windows Server 2003 Shell Folders Can Be Referenced Using Directory Traversal Characters
6047| [1007238] Microsoft Outlook Web Access Can Be Crashed By Remote Authenticated Users With an Outlook 2003 Client
6048| [1007152] Microsoft Windows 2000 Accessibility Utility Manager Lets Local Users Gain Elevated Privileges
6049| [1007099] Microsoft Windows 2000 ShellExecute() Buffer Overflow May Let Users Execute Arbitrary Code
6050| [1007093] Microsoft Active Directory Stack Overflow in 'Lsaas.exe' Lets Remote Users Crash the Windows 2000 Server
6051| [1006959] Microsoft Windows Server 2003 Drivers May Leak Information From Memory Via Ethernet Packets Containing TCP Streams
6052| [1006580] Microsoft Windows 2003 'win2k.sys' Printing Bug Lets Users Crash the System
6053| [1006534] Microsoft Proxy Service in Proxy Server 2.0 Has Unspecified Flaw That Lets Remote Users Stop Traffic
6054| [1006286] Microsoft Windows 2000/XP PostMessage() API Flaw May Let Local Users Grab Passwords from Local Dialog Boxes
6055| [1006280] Protegrity Secure.Data for Microsoft SQL Server 2000 Contains Buffer Oveflows That Let Remote Users Execute Arbitrary Code
6056| [1005254] Microsoft NT, 2000, and XP Operating Systems May Execute a 16-bit Application Even When The File Has No Execute Permissions
6057| [1005068] Microsoft NTFS Filesystem in Windows NT and Windows 2000 Has Auditing Hole That Lets Local Users Access Files Without the File Access Being Audited
6058| [1004587] Microsoft SQL Server 2000 Buffer Overflow in OpenDataSource() Function May Let Remote Users Gain SYSTEM Privileges on the Server
6059| [1004528] Microsoft SQLXML Component of Microsoft SQL Server 2000 Contains an Input Validation Flaw in an XML SQL Tag That Allows Cross-Site Scripting Attacks
6060| [1004527] Microsoft SQLXML Component of Microsoft SQL Server 2000 Contains a Buffer Overflow That Lets Remote Users Take Full Control of the System
6061| [1004407] Microsoft Exchange 2000 Flaw in Processing a Certain Malformed SMTP Command Allows Remote Users to Deny Service to the Server
6062| [1004357] Microsoft Windows Debugging Facility for Windows NT4 and 2000 Has Authentication Hole That Lets Local Users Execute Arbitrary Code with SYSTEM Privileges
6063| [1004083] Microsoft Windows 2000 'microsoft-ds' Service Flaw Allows Remote Users to Create Denial of Service Conditions By Sending Malformed Packets
6064| [1004022] Microsoft Windows 2000 Group Policy Object Enforcement Can Be Circumvented if User License Limits are Exceeded
6065| [1003975] Microsoft Windows NT, 2000, and XP Kernel Buffer Overflow in Processing Multiple UNC Provider (MUP) Requests May Let Local Users Obtain System Level Privileges
6066| [1003949] Microsoft Windows 2000 DCOM Implementation Flaw May Disclose Memory Contents to Remote Users
6067| [1003816] Microsoft Windows 2000 Automatic Log Off Policy Fails to Expire Sessions in Progress
6068| [1003688] Microsoft Exchange Server 2000 Command Processing Bug Lets Remote Users Cause the SMTP Service to Crash
6069| [1003687] Microsoft Windows 2000 and Windows XP SMTP Service Command Processing Bug Lets Remote Users Cause the SMTP Service to Crash
6070| [1003634] Microsoft XML Core Services in SQL Server 2000 Lets Remote Scripts Access and Send Local Files
6071| [1003629] Microsoft Commerce Server 2000 AuthFilter Buffer Overflow Lets Remote Users Execute Arbitrary Code on the Server With LocalSystem Privileges to Gain Full Control of the Server
6072| [1003472] Microsoft Telnet Server for Windows 2000 and for Interix Has a Buffer Overflow That May Let Remote Users Execute Code on the Server with System Level Privileges
6073| [1003469] Microsoft Exchange 2000 Server Allows Remote Users to View and Possibly Modify Registry Settings
6074| [1003402] Microsoft Windows NT 4.0 and Windows 2000 Domain Controllers May Give Elevated Privileges to Remote Users Who Are Valid Administrators on Other Trusted Domains
6075| [1002922] Microsoft Windows 2000 Internet Key Exchange (IKE) Service Can Be Crashed By Remote Users
6076| [1002754] Terminal Services on Microsoft Windows 2000 and XP Allow Remote Users to Log Bogus IP Addresses Instead of the User's Genuine Address
6077| [1002731] Microsoft Windows 2000 RunAs Service May Disclose Authentication Credentials to Local Users
6078| [1002730] Microsoft Windows 2000 RunAs Utility May Disclose Sensitive Information to Local Users
6079| [1002729] Microsoft Windows 2000 RunAs Service Allows Local Users to Disable the Service
6080| [1002356] Microsoft Outlook 2000 Animated Assistant Prevents the Screen Saver from Activating, Allowing Physically Local Users to Access the System
6081| [1002206] Microsoft Internet Security and Acceleration (ISA) Server 2000 Can Be Disrupted By Remote Users Due to Memory Leaks and Also Allows Cross-Site Scripting Attacks
6082| [1002106] Microsoft Windows 2000 and Windows NT 4.0 RPC Input Validation Failure Lets Remote Users Destabilize the Operating System
6083| [1002099] Microsoft Windows 2000 Telnet Service Can Be Crashed By Remote Users
6084| [1002098] Windows Terminal Services in Microsoft Windows 2000 and NT 4.0 Can Be Crashed By Remote Users Due to a Memory Leak
6085| [1001993] Microsoft Windows 2000, Linux 2.4, NetBSD, FreeBSD, and OpenBSD May Let Remote Users Affect TCP Performance
6086| [1001931] Microsoft Windows 2000 SMTP Service May Allow Unauthorized Remote Users to Relay E-mail via the Service
6087| [1001832] Microsoft Windows 2000 LDAP Server Lets Remote Users Gain Administrator Access to the Domain Controller When Configured to Support LDAP over SSL
6088| [1001701] Microsoft Windows 2000 Telnet Server Allows Local Users to Gain System-Level Privileges and Lets Remote Users Crash the Server
6089| [1001605] Microsoft Windows 2000 Allows Local Users to Elevate Privileges
6090| [1001565] Microsoft IIS Web Server on Windows 2000 Allows Remote Users to Cause the Server to Consume All Available Memory Due to Memory Leak in WebDAV Lock Method
6091| [1001513] Microsoft Windows 2000 Indexing Service Allows Remote Users to View Include Programming Files
6092| [1001501] Microsoft Windows 2000 Domain Controllers Can Be Effectively Halted By Remote Users
6093| [1001464] Microsoft Internet Information Server IIS 5.0 for Windows 2000 Lets Remote Users Execute Arbitrary Code on the Server and Gain Control of the Server
6094| [1001240] Microsoft FTP Client for Windows 2000 Still Vulnerable to Executing Arbitrary Code in Limited Situations
6095| [1001088] Microsoft Internet Explorer with Services for Unix 2.0 Can Create Malicious Files on the User's Host
6096|
6097| OSVDB - http://www.osvdb.org:
6098| [90257] Microsoft Windows Server 2003 ICACLS.EXE Permission Inheritance Weakness
6099| [86790] Microsoft Virtual PC 2007 Crafted x86 Instruction Sequence Handling Local DoS
6100| [86061] Microsoft Windows Server 2008 R1 CSRSS ReadConsole / CloseHandle Local DoS
6101| [79442] Microsoft Windows Server 2008 DNS Server Service Cache Update Policy Deleted Domain Name Resolving Weakness
6102| [72670] Microsoft Windows Server 2003 ActiveDirectory BROWSER ELECTION Remote Overflow
6103| [68554] Microsoft Windows Server 2008 Shared Cluster Disks Addition Default Permission Weakness
6104| [62251] Microsoft Windows Server 2008 Hyper-V Crafted Instruction Sequence DoS
6105| [60329] Microsoft Windows 2000 NetBIOS Continuation Packet Remote DoS
6106| [59733] Microsoft Windows 2000 Terminal Services Screensaver Screen Minimization Locking Weakness
6107| [59731] Microsoft Windows 2000 DCOM Client Alter Context Request Remote Information Disclosure
6108| [59730] Microsoft Windows 2000 Terminal Services Disconnect Feature Local Privilege Escalation
6109| [59514] Microsoft Windows 2000 Task Manager Uppercase Process Name Termination Weakness
6110| [59509] Microsoft Windows 2000 Encrypted File System Cleartext Backup File Local Disclosure
6111| [59346] Microsoft Windows 2000 Crafted TCP/UDP Traffic CPU Consumption Remote DoS
6112| [55836] Microsoft ISA Server 2006 Radius OTP Security Bypass
6113| [53663] Microsoft Office Word 2000 WordPerfect 6.x Converter Document Handling Stack Corruption
6114| [50589] Microsoft SQL Server 2000 sp_replwritetovarbin() Stored Procedure Overflow
6115| [37629] Microsoft Windows 2000 RPC Authentication Unspecified Information Disclosure
6116| [37628] Microsoft Windows 2000 RPC Authentication Crafted Request Remote DoS
6117| [36034] Microsoft Office 2000 Controllo ActiveX (OUACTRL.OCX) HelpPopup Method Overflow
6118| [34489] Microsoft Office 2003 Malformed WMF File Handling DoS
6119| [34488] Microsoft Excel 2003 XLS Handling Corrupt Format DoS
6120| [31251] Microsoft Office 2003 Brazilian Portuguese Grammar Checker Arbitrary Code Execution
6121| [29529] Microsoft Windows 2000 creator.dll ActiveX COM Object Memory Corruption
6122| [29528] Microsoft Windows 2000 msdxm.ocx ActiveX COM Object Memory Corruption
6123| [29527] Microsoft Windows 2000 myinfo.dll ActiveX COM Object Memory Corruption
6124| [29526] Microsoft Windows 2000 ciodm.dll ActiveX COM Object Memory Corruption
6125| [28539] Microsoft Word 2000 Unspecified Code Execution
6126| [24121] Microsoft Commerce Server 2002 authfiles/login.asp Authentication Bypass
6127| [24081] Microsoft Outlook 2003 Unspecified Malformed Word Attachment DoS
6128| [23484] Microsoft SQLServer 2000 sp_addalias Procedure Privileged Alias Creation
6129| [23234] Microsoft SQLServer 2000 Unspecified Invalid Client Buffer DoS
6130| [23231] Microsoft SQL Server 2000 SQL Profiler Multiple Method DoS
6131| [23205] Microsoft SQLServer 2000 Crafted Sort Command User Mode Scheduler (UMS) Bypass DoS
6132| [23203] Microsoft SQL Server 2000 Database Name Transact-SQL Statement Privilege Escalation
6133| [23202] Microsoft SQLServer 2000 sysmembers Virtual Table Query Overflow
6134| [23201] Microsoft SQL Server 2000 Dynamic Transact-SQL Statement Disclosure
6135| [23200] Microsoft SQLServer 2000 Encrypted Stored Procedure Dynamic Query Disclosure
6136| [21907] Microsoft Office InfoPath 2003 Mshtml.dll Form Handling DoS
6137| [21598] Microsoft Windows 2000 NetBIOS Port Malformed TCP Packet Parsing Remote DoS
6138| [20256] Microsoft Windows 2000 NTFS Volume Macintosh Client Directory Permission Modification
6139| [20222] Microsoft Windows 2000 runas.exe Named Pipe Spoofing Information Disclosure
6140| [20221] Microsoft Windows 2000 runas.exe Named Pipe Single Thread DoS
6141| [20220] Microsoft Windows 2000 runas.exe Cleartext Authentication Information Disclosure
6142| [20002] Microsoft Windows 2000 CHKDSK Fix Mode File ACL Failure
6143| [20001] Microsoft Windows 2000 Terminal Service Client Connection IP Logging Failure
6144| [20000] Microsoft Windows 2000 Domain Administrator Computer Lock Bypass
6145| [19999] Microsoft Windows 2000 FQDN Domain Login Password Expiry Bypass
6146| [19998] Microsoft Windows 2000 UPN Credentialed Login Group Policy Failure
6147| [19997] Microsoft Windows 2000 WideCharToMultiByte Function String Termination Issue
6148| [19996] Microsoft Windows 2000 Event ID 1704 Group Policy Failure
6149| [19995] Microsoft Windows 2000 SECEDIT Long Folder ACL Set Issue
6150| [19994] Microsoft Windows 2000 audit directory service access 565 Event Logging Failure
6151| [19993] Microsoft Windows 2000 LDAPS CA Trust Issue
6152| [19264] Microsoft Exchange Server 2003 Crafted IMAP4 Folder Listing Request DoS
6153| [17031] Microsoft ISA Server 2000 SecureNAT Traffic Saturation DoS
6154| [15343] Microsoft Windows Server 2003 Malformed HTTP Cookie Header CGI DoS
6155| [15341] Microsoft Windows Server 2003 SMB Redirector Processing DoS
6156| [15340] Microsoft Windows Server 2003 Terminal Service Client Print DoS
6157| [15338] Microsoft Windows Server 2003 Terminal Session Close DoS
6158| [15337] Microsoft Windows Server 2003 CreateProcessWithLogonW() Function Process Disclosure
6159| [15336] Microsoft Windows Server 2003 Shutdown.exe Shut Down Failure
6160| [15335] Microsoft Windows Server 2003 MIT Kerberos Realm Authentication Group Policy Failure
6161| [15334] Microsoft Windows Server 2003 Shared Folder Permission Weakness
6162| [15333] Microsoft Windows Server 2003 EFS File Copy LDAP Connection DoS
6163| [15332] Microsoft Windows Server 2003 Citrix Metaframe Encryption Policy Failure
6164| [15331] Microsoft Windows Server 2003 Home Folder Path Permission Inheritance Failure
6165| [14617] Microsoft Exchange Server 2003 Folder Handling DoS
6166| [14430] Microsoft Commerce Server 2000 Profile Service Affected API Overflow
6167| [13996] Microsoft Windows 2000 IKE Malformed Packet Saturation Remote DoS
6168| [13762] Microsoft 2000 Domain Controller Directory Service Restore Mode Blank Password
6169| [13761] Microsoft Exchange 2000 Malformed URL Request DoS
6170| [13475] Microsoft Windows 2000 Telnet Service Predictable Named Pipe Arbitrary Command Execution Variant
6171| [13474] Microsoft Windows 2000 Telnet Service Predictable Named Pipe Arbitrary Command Execution
6172| [13441] Microsoft Windows 2000 Security Interface Change Password Option Account Enumeration
6173| [13437] Microsoft Windows 2000 Debug Register Local Privilege Escalation
6174| [13424] Microsoft Windows 2000 Current Password Change Policy Bypass
6175| [13423] Microsoft Windows 2000 Terminal Server SYSVOL Share Connection Saturation Restriction Bypass
6176| [13415] Microsoft Windows 2000 System Root Folder Search Path Permission Weakness
6177| [13410] Microsoft Windows 2000 Accessibility Utility Manager Arbitrary Code Execution
6178| [11958] Microsoft Outlook 2003 Image Rendering Security Policy Bypass
6179| [11945] Microsoft Outlook 2002 IFRAME Tag Embedded URL
6180| [11944] Microsoft Outlook 2002 HREF Tag Embedded JavaScript Execution
6181| [11750] Microsoft Windows 2000 Message Queue Manager Queue Registration Request Overflow DoS
6182| [11712] Microsoft ISA Server 2000 H.323 Filter Overflow
6183| [10633] Microsoft Windows 2000 Protected Store Weak Encryption Default
6184| [9386] Microsoft Windows 2000 msinfo32.exe msinfo_file Variable Overflow
6185| [8243] Microsoft SMS Port 2702 DoS
6186| [7202] Microsoft PowerPoint 2000 File Loader Overflow
6187| [7179] Microsoft Windows 2000 Event Viewer Snap-in Overflow
6188| [6971] Microsoft ISA Server 2000 ICMP Rule Bypass During Startup
6189| [6970] Microsoft ISA Server 2000 Web Publishing Unencrypted Credentials Disclosure
6190| [6969] Microsoft ISA Server 2000 Invalid DNS Request DoS
6191| [6968] Microsoft ISA Server 2000 FTP Port Scan Bounce Weakness
6192| [6967] Microsoft ISA Server 2000 UDP Packet Winsock DoS
6193| [6965] Microsoft ISA Server 2000 SSL Packet DoS
6194| [6964] Microsoft ISA Server 2000 DNS Intrusion Detection Filter DoS
6195| [6515] Microsoft Windows 2000 Domain Expired Account Authentication
6196| [5179] Microsoft Windows 2000 microsoft-ds DoS
6197| [5171] Microsoft Word 2002 Mail Merge Tool Execute Arbitrary Script
6198| [4779] Microsoft Desktop Engine (MSDE) 2000 Stored Procedure SQL Injection
6199| [4778] Microsoft SQL Server 2000 Stored Procedure SQL Injection
6200| [4777] Microsoft Desktop Engine (MSDE) 2000 Database Consistency Checkers (DBCCs) Overflow
6201| [4776] Microsoft SQL Server 2000 Database Consistency Checkers (DBCCs) 2000 Overflow
6202| [4170] Microsoft Windows 2000 Server Media Services TCP Packet Handling Remote DoS
6203| [4168] Microsoft Outlook 2002 mailto URI Script Injection
6204| [3490] Microsoft Exchange 2003 OWA Mailbox Access Information Disclosure
6205| [2705] Microsoft Windows 2000 Windows Troubleshooter ActiveX Overflow
6206| [2655] Microsoft Windows Server 2003 Shell Folders Arbitrary File Access
6207| [2540] Microsoft Windows 2003 Server Buffer Overflow Protection Mechanism Bypass
6208| [2244] Microsoft Windows 2000 ShellExecute() API Let
6209| [2237] Microsoft Windows 2000 Active Directory Lsass.exe Overflow
6210| [1949] Symantec Norton Anti-Virus for Microsoft Exchange 2000 INBOX Path Information Disclosure
6211| [1764] Microsoft Windows 2000 Domain Controller DoS
6212| [1758] Microsoft Windows 2000 Network DDE Escalated Privileges
6213| [1755] Microsoft Windows 2000 RDP Malformed Packet Handling Remote DoS
6214| [1672] Microsoft Windows 2000 Telnet Session Timeout DoS
6215| [1633] Microsoft Windows 2000 System Monitor ActiveX LogFileName Parameter Validation Overflow
6216| [1621] Microsoft Indexing Services for Windows 2000 .htw XSS
6217| [1591] Microsoft Windows 2000 OEMPreinstall Installation Permission Weakness
6218| [1578] Microsoft Windows 2000 Simplified Chinese IME Local Privilege Escalation
6219| [1500] Microsoft Word / Excel / Powerpoint 2000 Object Tag Buffer Overflow
6220| [1437] Microsoft Windows 2000 Telnet Server Binary Zero Parsing Remote DoS
6221| [1399] Microsoft Windows 2000 Windows Station Access
6222| [1328] Microsoft Office 2000 UA Control ActiveX (Ouactrl.ocx) Show Me Function Remote Code Execution
6223| [1297] Microsoft Windows 2000 Active Directory Object Attribute
6224| [1292] Microsoft Windows NT 4.0 / 2000 cmd.exe Buffer Overflow
6225| [773] Microsoft Windows 2000 Group Policy File Lock DoS
6226| [515] Microsoft Windows 2000 LDAP Server Arbitrary User Password Modification
6227| [454] Microsoft Windows 2000 NTLM Domain Account Lockout Policy Bypass
6228| [403] Microsoft Windows 2000 Still Image Service WM_USER Message Local Overflow
6229| [398] Microsoft Windows 2000 Malformed RPC Traffic Local Security Policy Corruption DoS
6230| [307] Microsoft FrontPage 2000 Server Extensions shtml.exe Path Disclosure
6231| [69085] Microsoft Office 2010 RTF File Handling pFragments Buffer Overflow Arbitrary Code Execution
6232|_
6233Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
6234Device type: general purpose
6235Running (JUST GUESSING): Microsoft Windows 2012 (89%)
6236OS CPE: cpe:/o:microsoft:windows_server_2012
6237Aggressive OS guesses: Microsoft Windows Server 2012 (89%), Microsoft Windows Server 2012 or Windows Server 2012 R2 (89%), Microsoft Windows Server 2012 R2 (89%)
6238No exact OS matches for host (test conditions non-ideal).
6239Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows
6240
6241TRACEROUTE (using port 80/tcp)
6242HOP RTT ADDRESS
62431 171.41 ms 10.250.200.1
62442 172.53 ms 213.184.122.97
62453 173.37 ms bzq-82-80-246-9.cablep.bezeqint.net (82.80.246.9)
62464 171.84 ms bzq-179-124-185.cust.bezeqint.net (212.179.124.185)
62475 166.28 ms bzq-114-65-2.cust.bezeqint.net (192.114.65.2)
62486 222.08 ms bzq-179-72-241.cust.bezeqint.net (212.179.72.241)
62497 226.06 ms ae9.cr1-lon2.ip4.gtt.net (46.33.89.185)
62508 226.05 ms ae9.cr1-lon2.ip4.gtt.net (46.33.89.185)
62519 289.39 ms a100-gw.ip4.gtt.net (173.205.58.70)
625210 294.10 ms 52.93.1.89
625311 289.91 ms 52.93.1.26
625412 297.57 ms 52.93.1.93
625513 293.76 ms 52.93.1.4
625614 ... 18
625719 301.87 ms 52.93.132.142
625820 ... 26
625927 298.35 ms 52.93.28.192
626028 295.33 ms 52.93.28.190
626129 299.58 ms 52.93.28.158
626230 ...
6263#######################################################################################################################################
6264
6265wig - WebApp Information Gatherer
6266
6267
6268Scanning http://52.44.246.60...
6269____________________________________________ SITE INFO _____________________________________________
6270IP Title
627152.44.246.60
6272
6273_____________________________________________ VERSION ______________________________________________
6274Name Versions Type
6275microsoft-httpapi 2.0 Platform
6276Microsoft Windows 7 OS
6277Microsoft Windows Server 2003 SP2 | 2003 SP3 | 2008 | 2008 R2 | 2012 | 2012 R2 OS
6278
6279____________________________________________________________________________________________________
6280Time: 40.6 sec Urls: 599 Fingerprints: 40401
6281######################################################################################################################################
6282HTTP/1.1 404 Not Found
6283Content-Length: 315
6284Content-Type: text/html; charset=us-ascii
6285Server: Microsoft-HTTPAPI/2.0
6286Date: Fri, 26 Jul 2019 04:50:07 GMT
6287Connection: close
6288
6289HTTP/1.1 404 Not Fou
6290Content-Type: text/html; charset=us-ascii
6291Server: Microsoft-HTTPAPI/2.0
6292Date: Fri, 26 Jul 2019 04:50:08 GMT
6293Connection: close
6294######################################################################################################################################
6295Starting Nmap 7.70 ( https://nmap.org ) at 2019-07-26 00:50 EDT
6296Nmap scan report for ec2-52-44-246-60.compute-1.amazonaws.com (52.44.246.60)
6297Host is up.
6298
6299PORT STATE SERVICE VERSION
6300123/udp open|filtered ntp
6301Too many fingerprints match this host to give specific OS details
6302
6303TRACEROUTE (using proto 1/icmp)
6304HOP RTT ADDRESS
63051 170.08 ms 10.250.200.1
63062 171.14 ms 213.184.122.97
63073 171.13 ms bzq-82-80-246-9.cablep.bezeqint.net (82.80.246.9)
63084 231.76 ms bzq-219-189-185.cablep.bezeqint.net (62.219.189.185)
63095 165.00 ms bzq-114-65-2.cust.bezeqint.net (192.114.65.2)
63106 165.21 ms bzq-179-124-82.cust.bezeqint.net (212.179.124.82)
63117 226.36 ms bzq-179-124-118.cust.bezeqint.net (212.179.124.118)
63128 220.40 ms ae9.cr1-lon2.ip4.gtt.net (46.33.89.185)
63139 288.64 ms et-10-3-0.cr4-nyc2.ip4.gtt.net (213.254.214.10)
631410 288.53 ms a100-gw.ip4.gtt.net (173.205.58.70)
631511 288.56 ms 52.93.1.89
631612 288.33 ms 52.93.1.56
631713 ... 17
631818 295.38 ms 72.21.222.229
631919 ... 28
632029 302.01 ms 52.93.28.184
632130 ...
6322#######################################################################################################################################
6323Starting Nmap 7.70 ( https://nmap.org ) at 2019-07-26 00:52 EDT
6324Nmap scan report for ec2-52-44-246-60.compute-1.amazonaws.com (52.44.246.60)
6325Host is up (0.26s latency).
6326
6327PORT STATE SERVICE VERSION
6328443/tcp open ssl/http Microsoft IIS httpd 8.5
6329|_http-vuln-cve2014-3704: ERROR: Script execution failed (use -d to debug)
6330| vulscan: VulDB - https://vuldb.com:
6331| [68193] Microsoft IIS 8.0/8.5 IP and Domain Restriction privilege escalation
6332| [48519] Microsoft Works 8.5/9.0 memory corruption
6333| [45763] Microsoft Windows Live Messenger up to 8.5.1 unknown vulnerability
6334| [134730] Microsoft Skype 8.35 on Android Bluetooth Listening information disclosure
6335| [129845] Microsoft Skype for Business 2015 CU 8 Request cross site scripting
6336| [126799] Microsoft Dynamics 365 8 Web Request Code Execution
6337| [126798] Microsoft Dynamics 365 8 Web Request cross site scripting
6338| [126797] Microsoft Dynamics 365 8 Web Request cross site scripting
6339| [126796] Microsoft Dynamics 365 8 Web Request cross site scripting
6340| [126795] Microsoft Dynamics 365 8 Web Request cross site scripting
6341| [123872] Microsoft Windows 8.1/RT 8.1/10/Server 2012/Server 2012 R2 SMB information disclosure
6342| [121108] Microsoft Mail Client 8.1 information disclosure
6343| [115260] EMC RSA Authentication Agent for Web up to 8.0.1 on IIS/Apache cross site scripting
6344| [115259] EMC RSA Authentication Agent for Web up to 8.0.1 on IIS/Apache Cookie Stack-based memory corruption
6345| [113264] Microsoft Windows 8.1/RT 8.1/Server 2012 R2 SMBv2/SMBv3 denial of service
6346| [100989] Microsoft Internet Explorer 8/9/10/11 memory corruption
6347| [100918] Microsoft Windows 8/8.1/10/Server 2012/Server 2016 Malware Protection Service Type Confusion privilege escalation
6348| [96521] Microsoft Windows 8.1/10/Server 2012/Server 2016 SMB Response mrxsmb20.sys denial of service
6349| [93988] Microsoft Desktop Client for Mac up to 8.0.36 privilege escalation
6350| [93755] Microsoft Internet Explorer 8 Ls\xC2\xADFind\xC2\xADSpan\xC2\xADVisual\xC2\xADBoundaries memory corruption
6351| [93535] Microsoft Internet Explorer 8/9/10/11 Regex vbscript.dll RegExpComp::PnodeParse memory corruption
6352| [93386] Microsoft Windows Vista SP2/7 SP1/8.1/RT 8.1/10 Video Control memory corruption
6353| [92587] Microsoft Windows 8.1/RT 8.1/10/Server 2012/Server 2012 R2 Transaction Manager privilege escalation
6354| [92585] Microsoft Windows Vista SP2/7 SP1/8.1/RT 8.1/10 Video Control privilege escalation
6355| [91571] Microsoft Windows 8.1/RT 8.1/10/Server 2012/Server 2012 R2 PDF Library information disclosure
6356| [91570] Microsoft Windows 8.1/RT 8.1/10/Server 2012/Server 2012 R2 PDF Library information disclosure
6357| [91559] Microsoft Windows 8.1/RT 8.1/10 NTLM SSO information disclosure
6358| [90711] Microsoft Windows 8.1/RT 8.1/10/Server 2012/Server 2012 R2 PDF privilege escalation
6359| [90710] Microsoft Windows 8.1/RT 8.1/Server 2012/Server 2012 R2 Netlogon privilege escalation
6360| [87959] Microsoft Windows 8.1/10/Server 2012/Server 2012 R2 PDF information disclosure
6361| [87958] Microsoft Windows 8.1/10/Server 2012/Server 2012 R2 PDF memory corruption
6362| [87957] Microsoft Windows 8.1/10/Server 2012/Server 2012 R2 PDF information disclosure
6363| [87156] Microsoft Windows 8.1/RT 8.1/10/Server 2012 R2 Shell memory corruption
6364| [87155] Microsoft Windows Vista SP2/7/8.1/RT 8.1/10 Journal memory corruption
6365| [82223] Microsoft Windows 8.1/10/Server 2012 R2 Hyper-V Memory information disclosure
6366| [82222] Microsoft Windows 8.1/10/Server 2012/Server 2012 R2 Memory information disclosure
6367| [82221] Microsoft Windows 8.1/10/Server 2012/Server 2012 R2 Hyper-V privilege escalation
6368| [81270] Microsoft Windows 8.1/RT 8.1/10/Server 2012/Server 2012 R2 PDF Library memory corruption
6369| [80865] Microsoft Windows 8.1/RT 8.1/Server 2012/Server 2012 R2 DLL Loader memory corruption
6370| [80860] Microsoft Windows 8.1/10/Server 2012/Server 2012 R2 Reader memory corruption
6371| [80859] Microsoft Windows 8.1/10/Server 2012/Server 2012 R2 PDF Library memory corruption
6372| [80844] Microsoft Internet Explorer 8/9/10/11 MSHTML MSHTML!Method_VARIANTBOOLp_BSTR_o0oVARIANT memory corruption
6373| [80209] Microsoft Internet Explorer 8/9/10/11 VBScript/JScript memory corruption
6374| [79462] Microsoft Internet Explorer 8/9/10/11 memory corruption
6375| [79460] Microsoft Internet Explorer 8/9 memory corruption
6376| [79458] Microsoft Internet Explorer 8/9 memory corruption
6377| [79457] Microsoft Internet Explorer 8/9 memory corruption
6378| [79455] Microsoft Internet Explorer 8/9/10/11 XSS Filter privilege escalation
6379| [79449] Microsoft Internet Explorer 8/9/10/11 XSS Filter privilege escalation
6380| [79448] Microsoft Internet Explorer 8/9/10/11 Scripting Engine memory corruption
6381| [79447] Microsoft Internet Explorer 8/9/10/11 Scripting Engine information disclosure
6382| [79445] Microsoft Internet Explorer 8/9/10/11 memory corruption
6383| [79162] Microsoft Internet Explorer 8/9/10/11 Scripting Engine memory corruption
6384| [79155] Microsoft Internet Explorer 8/9/10/11 memory corruption
6385| [79143] Microsoft Internet Explorer 8/9/10/11 memory corruption
6386| [78390] Microsoft Internet Explorer 8/9/10/11 VBScript/JScript Engine information disclosure
6387| [78386] Microsoft Internet Explorer 8/9/10/11 VBScript/JScript Engine memory corruption
6388| [78384] Microsoft Internet Explorer 8/9/10/11 VBScript/JScript Engine ASLR privilege escalation
6389| [78379] Microsoft Internet Explorer 8/9/10/11 EditWith Broker privilege escalation
6390| [78377] Microsoft Internet Explorer 8 privilege escalation
6391| [78362] Microsoft Internet Explorer 8/9/10/11 VBScript/JScript Engine RegExpBase::FBadHeader memory corruption
6392| [77605] Microsoft Internet Explorer 8 VBScript/JScript Engine memory corruption
6393| [77006] Microsoft Internet Explorer 8/9/10/11 memory corruption
6394| [77004] Microsoft Internet Explorer 8/9/10/11 memory corruption
6395| [76490] Microsoft Internet Explorer 8/9/10/11 Image Caching History information disclosure
6396| [76482] Microsoft Internet Explorer 8 memory corruption
6397| [76479] Microsoft Internet Explorer 8/9/10/11 XSS Filter cross site scripting
6398| [76474] Microsoft Internet Explorer 8/9 memory corruption
6399| [76449] Microsoft Windows 8/8.1/Server 2008/Server 2012/Server 2012 R2 Hyper-V memory corruption
6400| [76448] Microsoft Windows 8.1/Server 2012 R2 Hyper-V memory corruption
6401| [76437] Microsoft Internet Explorer 8/9 memory corruption
6402| [75780] Microsoft Internet Explorer 8 memory corruption
6403| [75707] Cisco Unified MeetingPlace for Microsoft Outlook 8.6(1.2)/ 8.6(1.9) cross site scripting
6404| [75322] Microsoft Internet Explorer 8/9 memory corruption
6405| [75319] Microsoft Internet Explorer 8/9/10/11 memory corruption
6406| [75311] Microsoft Internet Explorer 8/9 memory corruption
6407| [75308] Microsoft Internet Explorer 8/9/10/11 VBscript and JScript Engine privilege escalation
6408| [75306] Microsoft Internet Explorer 8/9/10/11 VBScript Engine privilege escalation
6409| [74856] Microsoft Internet Explorer 8/9/10/11 memory corruption
6410| [74842] Microsoft Windows 8.1/Server 2012 R2 Hyper-V denial of service
6411| [73946] Microsoft Internet Explorer 8/9/10/11 memory corruption
6412| [73943] Microsoft Internet Explorer 8 memory corruption
6413| [73939] Microsoft Internet Explorer 8/9/10/11 VBScript Engine memory corruption
6414| [69137] Microsoft Internet Explorer 8 ASLR privilege escalation
6415| [69136] Microsoft Internet Explorer 8/9 MSHTML SpanQualifier memory corruption
6416| [69135] Microsoft Internet Explorer 8/10 memory corruption
6417| [69131] Microsoft Internet Explorer 8/9 memory corruption
6418| [69130] Microsoft Internet Explorer 8/9/10/11 memory corruption
6419| [68400] Microsoft Internet Explorer 8 memory corruption
6420| [68393] Microsoft Internet Explorer 8/9/10/11 XSS Filter cross site scripting
6421| [68389] Microsoft Internet Explorer 8/9/10/11 XSS Filter cross site scripting
6422| [68181] Microsoft Internet Explorer 8/9/10/11 memory corruption
6423| [68176] Microsoft Internet Explorer 8/9/10/11 information disclosure
6424| [68174] Microsoft Internet Explorer 8/9 memory corruption
6425| [68169] Microsoft Internet Explorer 8/9 ASLR privilege escalation
6426| [68211] Microsoft Internet Explorer 8/9/10/11 denial of service
6427| [67821] Microsoft Internet Explorer 8/9/10/11 CAttrArray memory corruption
6428| [67813] Microsoft Internet Explorer 8 memory corruption
6429| [67500] Microsoft Internet Explorer 8/9/10/11 memory corruption
6430| [67494] Microsoft Internet Explorer 8/9/10/11 memory corruption
6431| [67345] Microsoft Internet Explorer 8/9/10/11 memory corruption
6432| [67340] Microsoft Internet Explorer 8 memory corruption
6433| [67337] Microsoft Internet Explorer 8/9 memory corruption
6434| [67007] Microsoft Internet Explorer 8/9/10/11 memory corruption
6435| [67006] Microsoft Internet Explorer 8/9/10 memory corruption
6436| [67002] Microsoft Internet Explorer 8/9/10/11 memory corruption
6437| [67000] Microsoft Internet Explorer 8/9/10/11 memory corruption
6438| [66995] Microsoft Internet Explorer 8/9/10/11 memory corruption
6439| [13542] Microsoft Internet Explorer 8/9/10/11 privilege escalation
6440| [13536] Microsoft Internet Explorer 8 memory corruption
6441| [13518] Microsoft Internet Explorer 8 memory corruption
6442| [13515] Microsoft Internet Explorer 8/9/10/11 memory corruption
6443| [13509] Microsoft Internet Explorer 8 memory corruption
6444| [13499] Microsoft Internet Explorer 8 memory corruption
6445| [13496] Microsoft Internet Explorer 8/9/10/11 privilege escalation
6446| [13027] Microsoft Internet Explorer 8/9 information disclosure
6447| [66605] Microsoft Internet Explorer 8/9/10/11 memory corruption
6448| [12543] Microsoft Internet Explorer 8/9/10/11 memory corruption
6449| [12541] Microsoft Internet Explorer 8/9/10 memory corruption
6450| [12540] Microsoft Internet Explorer 8/9/10/11 memory corruption
6451| [12538] Microsoft Internet Explorer 8/9 memory corruption
6452| [12531] Microsoft Internet Explorer 8/9/10/11 memory corruption
6453| [66445] Microsoft Windows 8.0/8.1 XMLDOM ActiveX Control information disclosure
6454| [12252] Microsoft Internet Explorer 8 memory corruption
6455| [12245] Microsoft Internet Explorer 8/9/10/11 memory corruption
6456| [12239] Microsoft Internet Explorer 8/9/10/11 privilege escalation
6457| [12238] Microsoft Windows 8/Server 2012/RT IPv6 denial of service
6458| [11150] Microsoft Windows 8/Server 2012 Hyper-V Data Structure Value Crash privilege escalation
6459| [11141] Microsoft Internet Explorer 8/9/10/11 CCaret Object Use-After-Free memory corruption
6460| [11138] Microsoft Internet Explorer 8/9/10/11 CTreePos Object memory corruption
6461| [11127] Microsoft Internet Explorer 8/9 information disclosure
6462| [10623] Microsoft Internet Explorer 8/9 memory corruption
6463| [10215] Microsoft Internet Explorer 8/9 memory corruption
6464| [10214] Microsoft Internet Explorer 8/9/10 memory corruption
6465| [9935] Microsoft Internet Explorer 8/9 memory corruption
6466| [9934] Microsoft Internet Explorer 8/9/10 memory corruption
6467| [9933] Microsoft Internet Explorer 8/9 memory corruption
6468| [9932] Microsoft Internet Explorer 8/9 memory corruption
6469| [10246] Microsoft Internet Explorer 8 Table Tree Use-After-Free memory corruption
6470| [9419] Microsoft Internet Explorer up to 8 memory corruption
6471| [9418] Microsoft Internet Explorer 8/9/10 Use-After-Free memory corruption
6472| [9413] Microsoft Internet Explorer 8/9/10 Use-After-Free memory corruption
6473| [9406] Microsoft Internet Explorer 8/9/10 memory corruption
6474| [9099] Microsoft Internet Explorer 8/9 Use-After-Free memory corruption
6475| [9098] Microsoft Internet Explorer 8 memory corruption
6476| [9095] Microsoft Internet Explorer 8/9/10 Use-After-Free memory corruption
6477| [9084] Microsoft Internet Explorer 8/9/10 _UpdateButtonLocation memory corruption
6478| [9083] Microsoft Internet Explorer 8/9 memory corruption
6479| [8722] Microsoft Windows 8/Server 2012/RT HTTP.sys denial of service
6480| [8718] Microsoft Internet Explorer 8 memory corruption
6481| [8714] Microsoft Internet Explorer 8/9 memory corruption
6482| [8712] Microsoft Internet Explorer 8/9 memory corruption
6483| [8601] Microsoft Internet Explorer 8 'vtable' memory corruption
6484| [8423] Microsoft Internet Explorer up to 8.00.6001.18702 CSS iexplorer.exe denial of service
6485| [7962] Microsoft Internet Explorer up to 8 CTreeNode memory corruption
6486| [7958] Microsoft Internet Explorer up to 8 Celement memory corruption
6487| [7996] Microsoft Windows 8 TrueType Font denial of service
6488| [63558] Microsoft Internet Explorer 8 Use-After-Free memory corruption
6489| [63557] Microsoft Internet Explorer 8/9 Use-After-Free memory corruption
6490| [7511] Microsoft Internet Explorer 8/9 TCP Session information disclosure
6491| [7510] Microsoft Internet Explorer 8/9 HTTP/HTTPS Request spoofing
6492| [7258] Microsoft Windows up to 8/Server 2012 SSL/TLS race condition
6493| [7199] Microsoft Internet Explorer 8/9 mshtml.dll Unclosed Tags Sequence denial of service
6494| [6513] Microsoft Internet Explorer 8/9 OnMove Engine Use-After-Free memory corruption
6495| [5937] Microsoft Internet Explorer 8/9 JavaScript Parser memory corruption
6496| [5538] Microsoft Internet Explorer 8 Same ID Property Deleted Object memory corruption
6497| [5532] Microsoft Internet Explorer 8/9 HTML Sanitization toStaticHTML String information disclosure
6498| [5530] Microsoft Internet Explorer 8/9 OnRowsInserted Elements memory corruption
6499| [5516] Microsoft Internet Explorer 8/9 memory corruption
6500| [4467] Microsoft Internet Explorer 8 cross site scripting
6501| [4454] Microsoft Internet Explorer 8/9 unknown vulnerability
6502| [59618] Microsoft Internet Explorer 8 unknown vulnerability
6503| [57681] Microsoft Internet Explorer 8/9 memory corruption
6504| [57675] Microsoft Internet Explorer 8 memory corruption
6505| [4372] Microsoft Internet Explorer 8/9 information disclosure
6506| [57130] Microsoft Internet Explorer 8 on Win7 msxml.dll unknown vulnerability
6507| [4340] Microsoft Internet Explorer up to 8 unknown vulnerability
6508| [56786] Microsoft Internet Explorer 8 on Win7 unknown vulnerability
6509| [56785] Microsoft Internet Explorer 8 on Win7 memory corruption
6510| [56412] Microsoft Internet Explorer 8 IEShims.dll unknown vulnerability
6511| [55755] Microsoft Internet Explorer 8 memory corruption
6512| [54961] Microsoft Internet Explorer 8 mshtml.dll InsertIntoTimeoutList information disclosure
6513| [4172] Microsoft Internet Explorer up to 8 CSS cross site scripting
6514| [54339] Microsoft Internet Explorer 8 Uninitialized Memory memory corruption
6515| [53805] Microsoft Internet Explorer 8 unknown vulnerability
6516| [53514] Microsoft Internet Explorer 8 Uninitialized Memory memory corruption
6517| [53513] Microsoft Internet Explorer 8 memory corruption
6518| [4137] Microsoft Internet Explorer up to 8.0 memory corruption
6519| [4121] Microsoft Internet Explorer 8 XSS Filter cross site scripting
6520| [52505] Microsoft Internet Explorer 8 mstime.dll memory corruption
6521| [52373] Microsoft Internet Explorer 8 on Win7 Use-After-Free memory corruption
6522| [52372] Microsoft Internet Explorer 8 on Win7 Heap-based memory corruption
6523| [51652] Microsoft Internet Explorer 8 Uninitialized Memory memory corruption
6524| [51651] Microsoft Internet Explorer 8 Uninitialized Memory memory corruption
6525| [50914] Microsoft Internet Explorer 8 cross site scripting
6526| [50910] Microsoft Internet Explorer 8 unknown vulnerability
6527| [4048] Microsoft Internet Explorer up to 8 CSS Declaration memory corruption
6528| [4047] Microsoft Internet Explorer up to 8 DOM Object memory corruption
6529| [4046] Microsoft Internet Explorer up to 8 HTML memory corruption
6530| [3987] Microsoft Internet Explorer up to 8 Row Reference memory corruption
6531| [3982] Microsoft Internet Explorer up to 8 DHTML Call memory corruption
6532| [47244] Microsoft Internet Explorer 8 on Win 7 memory corruption
6533| [45681] Microsoft Internet Explorer 8 Beta 2 privilege escalation
6534| [45451] Microsoft Internet Explorer 8 XSS Filter cross site scripting
6535| [45450] Microsoft Internet Explorer 8 XSS Filter Protection cross site scripting
6536| [45449] Microsoft Internet Explorer 8 Beta 2 XSS Filter cross site scripting
6537| [45448] Microsoft Internet Explorer 8 Beta 2 XSS Filter cross site scripting
6538| [45447] Microsoft Internet Explorer 8 XSS Filter cross site scripting
6539| [45446] Microsoft Internet Explorer 8 Beta 2 XSS Filter cross site scripting
6540| [39012] Microsoft Windows Live Messenger up to 8.1 doc memory corruption
6541| [34991] Microsoft Visual Studio 8.0 msvcr80.dll denial of service
6542| [33589] Microsoft Windows Live Messenger up to 8.0 denial of service
6543| [31353] Microsoft Works 8.0 Spreadsheet wksss.exe memory corruption
6544| [31352] Microsoft Works 8.0 Spreadsheet wksss.exe denial of service
6545| [31024] Microsoft Windows Live Messenger 8.0 Heap-based memory corruption
6546|
6547| MITRE CVE - https://cve.mitre.org:
6548| [CVE-2013-0941] EMC RSA Authentication API before 8.1 SP1, RSA Web Agent before 5.3.5 for Apache Web Server, RSA Web Agent before 5.3.5 for IIS, RSA PAM Agent before 7.0, and RSA Agent before 6.1.4 for Microsoft Windows use an improper encryption algorithm and a weak key for maintaining the stored data of the node secret for the SecurID Authentication API, which allows local users to obtain sensitive information via cryptographic attacks on this data.
6549| [CVE-2011-1215] Stack-based buffer overflow in mw8sr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a crafted link in a Microsoft Office document attachment, aka SPR PRAD8823ND.
6550| [CVE-2010-3496] McAfee VirusScan Enterprise 8.5i and 8.7i does not properly interact with the processing of hcp:// URLs by the Microsoft Help and Support Center, which makes it easier for remote attackers to execute arbitrary code via malware that is correctly detected by this product, but with a detection approach that occurs too late to stop the code execution.
6551| [CVE-2009-3126] Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a crafted PNG image file, aka "GDI+ PNG Integer Overflow Vulnerability."
6552| [CVE-2009-3032] Integer overflow in kvolefio.dll 8.5.0.8339 and 10.5.0.0 in the Autonomy KeyView Filter SDK, as used in IBM Lotus Notes 8.5, Symantec Mail Security for Microsoft Exchange 5.0.10 through 5.0.13, and other products, allows context-dependent attackers to execute arbitrary code via a crafted OLE document that triggers a heap-based buffer overflow.
6553| [CVE-2009-2504] Multiple integer overflows in unspecified APIs in GDI+ in Microsoft .NET Framework 1.1 SP1, .NET Framework 2.0 SP1 and SP2, Windows XP SP2 and SP3, Windows Server 2003 SP2, Vista Gold and SP1, Server 2008 Gold, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allow remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "GDI+ .NET API Vulnerability."
6554| [CVE-2009-2503] GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Windows Server 2003 SP2, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 does not properly allocate an unspecified buffer, which allows remote attackers to execute arbitrary code via a crafted TIFF image file that triggers memory corruption, aka "GDI+ TIFF Memory Corruption Vulnerability."
6555| [CVE-2009-2502] Buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a crafted TIFF image file, aka "GDI+ TIFF Buffer Overflow Vulnerability."
6556| [CVE-2009-2501] Heap-based buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a crafted PNG image file, aka "GDI+ PNG Heap Overflow Vulnerability."
6557| [CVE-2009-2500] Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a crafted WMF image file, aka "GDI+ WMF Integer Overflow Vulnerability."
6558| [CVE-2009-1533] Buffer overflow in the Works for Windows document converters in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, Office 2007 SP1, and Works 8.5 and 9 allows remote attackers to execute arbitrary code via a crafted Works .wps file that triggers memory corruption, aka "File Converter Buffer Overflow Vulnerability."
6559| [CVE-2008-5828] Microsoft Windows Live Messenger Client 8.5.1 and earlier, when MSN Protocol Version 15 (MSNP15) is used over a NAT session, allows remote attackers to discover intranet IP addresses and port numbers by reading the (1) IPv4InternalAddrsAndPorts, (2) IPv4Internal-Addrs, and (3) IPv4Internal-Port header fields.
6560| [CVE-2007-0045] Multiple cross-site scripting (XSS) vulnerabilities in Adobe Acrobat Reader Plugin before 8.0.0, and possibly the plugin distributed with Adobe Reader 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2, for Mozilla Firefox, Microsoft Internet Explorer 6 SP1, Google Chrome, Opera 8.5.4 build 770, and Opera 9.10.8679 on Windows allow remote attackers to inject arbitrary JavaScript and conduct other attacks via a .pdf URL with a javascript: or res: URI with (1) FDF, (2) XML, and (3) XFDF AJAX parameters, or (4) an arbitrarily named name=URI anchor identifier, aka "Universal XSS (UXSS)."
6561| [CVE-2004-1312] A bug in the HTML parser in a certain Microsoft HTML library, as used in various third party products, may allow remote attackers to cause a denial of service via certain strings, as reported in GFI MailEssentials for Exchange 9 and 10, and GFI MailSecurity for Exchange 8, which causes emails to remain in IIS or Exchange mail queues.
6562| [CVE-2002-1117] Veritas Backup Exec 8.5 and earlier requires that the "RestrictAnonymous" registry key for Microsoft Exchange 2000 must be set to 0, which enables anonymous listing of the SAM database and shares.
6563| [CVE-2001-1088] Microsoft Outlook 8.5 and earlier, and Outlook Express 5 and earlier, with the "Automatically put people I reply to in my address book" option enabled, do not notify the user when the "Reply-To" address is different than the "From" address, which could allow an untrusted remote attacker to spoof legitimate addresses and intercept email from the client that is intended for another user.
6564| [CVE-2013-3661] The EPATHOBJ::bFlatten function in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not check whether linked-list traversal is continually accessing the same list member, which allows local users to cause a denial of service (infinite traversal) via vectors that trigger a crafted PATHRECORD chain.
6565| [CVE-2013-3660] The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, and Windows Server 2012 does not properly initialize a pointer for the next object in a certain list, which allows local users to obtain write access to the PATHRECORD chain, and consequently gain privileges, by triggering excessive consumption of paged memory and then making many FlattenPath function calls, aka "Win32k Read AV Vulnerability."
6566| [CVE-2013-3174] DirectShow in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, and Windows Server 2012 allows remote attackers to execute arbitrary code via a crafted GIF file, aka "DirectShow Arbitrary Memory Overwrite Vulnerability."
6567| [CVE-2013-3173] Buffer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages improper handling of objects in memory, aka "Win32k Buffer Overwrite Vulnerability."
6568| [CVE-2013-3164] Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
6569| [CVE-2013-3163] Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3144 and CVE-2013-3151.
6570| [CVE-2013-3151] Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3144 and CVE-2013-3163.
6571| [CVE-2013-3149] Microsoft Internet Explorer 7 and 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
6572| [CVE-2013-3144] Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3151 and CVE-2013-3163.
6573| [CVE-2013-3141] Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3110.
6574| [CVE-2013-3138] Integer overflow in the TCP/IP kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allows remote attackers to cause a denial of service (system hang) via crafted TCP packets, aka "TCP/IP Integer Overflow Vulnerability."
6575| [CVE-2013-3136] The kernel in Microsoft Windows XP SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, and Windows 8 on 32-bit platforms does not properly handle unspecified page-fault system calls, which allows local users to obtain sensitive information from kernel memory via a crafted application, aka "Kernel Information Disclosure Vulnerability."
6576| [CVE-2013-3123] Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3111.
6577| [CVE-2013-3111] Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3123.
6578| [CVE-2013-3110] Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3141.
6579| [CVE-2013-2558] Unspecified vulnerability in Microsoft Windows 8 allows remote attackers to cause a denial of service (reboot) or possibly have unknown other impact via a crafted TrueType Font (TTF) file, as demonstrated by the 120612-69701-01.dmp error report.
6580| [CVE-2013-2552] Unspecified vulnerability in Microsoft Internet Explorer 10 on Windows 8 allows remote attackers to bypass the sandbox protection mechanism by leveraging access to a Medium integrity process, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2013.
6581| [CVE-2013-1451] Microsoft Internet Explorer 8 and 9, when the Proxy Settings configuration has the same Proxy address and Port values in the HTTP and Secure rows, does not ensure that the SSL lock icon is consistent with the Address bar, which makes it easier for remote attackers to spoof web sites via a crafted HTML document that triggers many HTTPS requests to an arbitrary host, followed by an HTTPS request to a trusted host and then an HTTP request to an untrusted host, a related issue to CVE-2013-1450.
6582| [CVE-2013-1450] Microsoft Internet Explorer 8 and 9, when the Proxy Settings configuration has the same Proxy address and Port values in the HTTP and Secure rows, does not properly reuse TCP sessions to the proxy server, which allows remote attackers to obtain sensitive information intended for a specific host via a crafted HTML document that triggers many HTTPS requests and then triggers an HTTP request to that host, as demonstrated by reading a Cookie header, aka MSRC 12096gd.
6583| [CVE-2013-1347] Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly allocated or (2) is deleted, as exploited in the wild in May 2013.
6584| [CVE-2013-1345] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Win32k Vulnerability."
6585| [CVE-2013-1340] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Win32k Dereference Vulnerability."
6586| [CVE-2013-1339] The Print Spooler in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly manage memory during deletion of printer connections, which allows remote authenticated users to execute arbitrary code via a crafted request, aka "Print Spooler Vulnerability."
6587| [CVE-2013-1334] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Win32k Window Handle Vulnerability."
6588| [CVE-2013-1332] dxgkrnl.sys (aka the DirectX graphics kernel subsystem) in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "DirectX Graphics Kernel Subsystem Double Fetch Vulnerability."
6589| [CVE-2013-1311] Use-after-free vulnerability in Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer Use After Free Vulnerability."
6590| [CVE-2013-1307] Use-after-free vulnerability in Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer Use After Free Vulnerability," a different vulnerability than CVE-2013-0811.
6591| [CVE-2013-1305] HTTP.sys in Microsoft Windows 8, Windows Server 2012, and Windows RT allows remote attackers to cause a denial of service (infinite loop) via a crafted HTTP header, aka "HTTP.sys Denial of Service Vulnerability."
6592| [CVE-2013-1300] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Win32k Memory Allocation Vulnerability."
6593| [CVE-2013-1297] Microsoft Internet Explorer 6 through 8 does not properly restrict data access by VBScript, which allows remote attackers to perform cross-domain reading of JSON files via a crafted web site, aka "JSON Array Information Disclosure Vulnerability."
6594| [CVE-2013-1294] Race condition in the kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages improper handling of objects in memory, aka "Kernel Race Condition Vulnerability."
6595| [CVE-2013-1292] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages improper handling of objects in memory, aka "Win32k Race Condition Vulnerability."
6596| [CVE-2013-1291] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, Windows 7 Gold and SP1, and Windows 8 allows local users to cause a denial of service (reboot) via a crafted OpenType font, aka "OpenType Font Parsing Vulnerability" or "Win32k Font Parsing Vulnerability."
6597| [CVE-2013-1288] Use-after-free vulnerability in Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer CTreeNode Use After Free Vulnerability."
6598| [CVE-2013-1287] The USB kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 do not properly handle objects in memory, which allows physically proximate attackers to execute arbitrary code by connecting a crafted USB device, aka "Windows USB Descriptor Vulnerability," a different vulnerability than CVE-2013-1285 and CVE-2013-1286.
6599| [CVE-2013-1286] The USB kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 do not properly handle objects in memory, which allows physically proximate attackers to execute arbitrary code by connecting a crafted USB device, aka "Windows USB Descriptor Vulnerability," a different vulnerability than CVE-2013-1285 and CVE-2013-1287.
6600| [CVE-2013-1285] The USB kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 do not properly handle objects in memory, which allows physically proximate attackers to execute arbitrary code by connecting a crafted USB device, aka "Windows USB Descriptor Vulnerability," a different vulnerability than CVE-2013-1286 and CVE-2013-1287.
6601| [CVE-2013-1284] Race condition in the kernel in Microsoft Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages improper handling of objects in memory, aka "Kernel Race Condition Vulnerability."
6602| [CVE-2013-1283] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages improper handling of objects in memory, aka "Win32k Race Condition Vulnerability."
6603| [CVE-2013-1280] The kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Reference Count Vulnerability."
6604| [CVE-2013-1279] Race condition in the kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages incorrect handling of objects in memory, aka "Kernel Race Condition Vulnerability," a different vulnerability than CVE-2013-1278.
6605| [CVE-2013-1278] Race condition in the kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages incorrect handling of objects in memory, aka "Kernel Race Condition Vulnerability," a different vulnerability than CVE-2013-1279.
6606| [CVE-2013-1249] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
6607| [CVE-2013-1248] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
6608| [CVE-2013-0811] Use-after-free vulnerability in Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer Use After Free Vulnerability," a different vulnerability than CVE-2013-1307.
6609| [CVE-2013-0091] Use-after-free vulnerability in Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer CElement Use After Free Vulnerability."
6610| [CVE-2013-0078] The Microsoft Antimalware Client in Windows Defender on Windows 8 and Windows RT uses an incorrect pathname for MsMpEng.exe, which allows local users to gain privileges via a crafted application, aka "Microsoft Antimalware Improper Pathname Vulnerability."
6611| [CVE-2013-0075] The TCP/IP implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows remote attackers to cause a denial of service (reboot) via a crafted packet that terminates a TCP connection, aka "TCP FIN WAIT Vulnerability."
6612| [CVE-2013-0025] Use-after-free vulnerability in Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer SLayoutRun Use After Free Vulnerability."
6613| [CVE-2013-0024] Use-after-free vulnerability in Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer pasteHTML Use After Free Vulnerability."
6614| [CVE-2013-0013] The SSL provider component in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle encrypted packets, which allows man-in-the-middle attackers to conduct SSLv2 downgrade attacks against (1) SSLv3 sessions or (2) TLS sessions by intercepting handshakes and injecting content, aka "Microsoft SSL Version 3 and TLS Protocol Security Feature Bypass Vulnerability."
6615| [CVE-2013-0008] win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle window broadcast messages, which allows local users to gain privileges via a crafted application, aka "Win32k Improper Message Handling Vulnerability."
6616| [CVE-2012-4792] Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not properly allocated or (2) is deleted, as demonstrated by a CDwnBindInfo object, and exploited in the wild in December 2012.
6617| [CVE-2012-4786] The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allow remote attackers to execute arbitrary code via a crafted TrueType Font (TTF) file, aka "TrueType Font Parsing Vulnerability."
6618| [CVE-2012-2897] The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT, as used by Google Chrome before 22.0.1229.79 and other programs, do not properly handle objects in memory, which allows remote attackers to execute arbitrary code via a crafted TrueType font file, aka "Windows Font Parsing Vulnerability" or "TrueType Font Parsing Vulnerability."
6619| [CVE-2012-2557] Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "cloneNode Use After Free Vulnerability."
6620| [CVE-2012-2556] The OpenType Font (OTF) driver in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows remote attackers to execute arbitrary code via a crafted OpenType font file, aka "OpenType Font Parsing Vulnerability."
6621| [CVE-2012-2523] Integer overflow in Microsoft Internet Explorer 8 and 9, JScript 5.8, and VBScript 5.8 on 64-bit platforms allows remote attackers to execute arbitrary code by leveraging an incorrect size calculation during object copying, aka "JavaScript Integer Overflow Remote Code Execution Vulnerability."
6622| [CVE-2012-1881] Microsoft Internet Explorer 8 and 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "OnRowsInserted Event Remote Code Execution Vulnerability."
6623| [CVE-2012-1875] Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "Same ID Property Remote Code Execution Vulnerability."
6624| [CVE-2012-1874] Microsoft Internet Explorer 8 and 9 does not properly handle objects in memory, which allows user-assisted remote attackers to execute arbitrary code by accessing a deleted object, aka "Developer Toolbar Remote Code Execution Vulnerability."
6625| [CVE-2012-1858] The toStaticHTML API (aka the SafeHTML component) in Microsoft Internet Explorer 8 and 9, Communicator 2007 R2, and Lync 2010 and 2010 Attendee does not properly handle event attributes and script, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted HTML document, aka "HTML Sanitization Vulnerability."
6626| [CVE-2012-1856] The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office 2003 SP3, Office 2003 Web Components SP3, Office 2007 SP2 and SP3, Office 2010 SP1, SQL Server 2000 SP4, SQL Server 2005 SP4, SQL Server 2008 SP2, SP3, R2, R2 SP1, and R2 SP2, Commerce Server 2002 SP4, Commerce Server 2007 SP2, Commerce Server 2009 Gold and R2, Host Integration Server 2004 SP1, Visual FoxPro 8.0 SP1, Visual FoxPro 9.0 SP2, and Visual Basic 6.0 Runtime allows remote attackers to execute arbitrary code via a crafted (1) document or (2) web page that triggers system-state corruption, aka "MSCOMCTL.OCX RCE Vulnerability."
6627| [CVE-2012-1848] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview does not properly handle user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application, aka "Scrollbar Calculation Vulnerability."
6628| [CVE-2012-1537] Heap-based buffer overflow in DirectPlay in DirectX 9.0 through 11.1 in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 allows remote attackers to execute arbitrary code via a crafted Office document, aka "DirectPlay Heap Overflow Vulnerability."
6629| [CVE-2012-1529] Use-after-free vulnerability in Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not properly initialized or (2) is deleted, aka "OnMove Use After Free Vulnerability."
6630| [CVE-2012-1528] Integer overflow in Windows Shell in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 allows local users to gain privileges via a crafted briefcase, aka "Windows Briefcase Integer Overflow Vulnerability."
6631| [CVE-2012-1527] Integer underflow in Windows Shell in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 allows local users to gain privileges via a crafted briefcase, aka "Windows Briefcase Integer Underflow Vulnerability."
6632| [CVE-2012-1523] Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "Center Element Remote Code Execution Vulnerability."
6633| [CVE-2012-0181] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview does not properly manage Keyboard Layout files, which allows local users to gain privileges via a crafted application, aka "Keyboard Layout File Vulnerability."
6634| [CVE-2012-0180] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview does not properly handle user-mode input passed to kernel mode for (1) windows and (2) messages, which allows local users to gain privileges via a crafted application, aka "Windows and Messages Vulnerability."
6635| [CVE-2012-0172] Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "VML Style Remote Code Execution Vulnerability."
6636| [CVE-2012-0159] Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview
6637| [CVE-2012-0151] The Authenticode Signature Verification function in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview does not properly validate the digest of a signed portable executable (PE) file, which allows user-assisted remote attackers to execute arbitrary code via a modified file with additional content, aka "WinVerifyTrust Signature Validation Vulnerability."
6638| [CVE-2011-2382] Microsoft Internet Explorer 8 and earlier, and Internet Explorer 9 beta, does not properly restrict cross-zone drag-and-drop actions, which allows user-assisted remote attackers to read cookie files via vectors involving an IFRAME element with a SRC attribute containing a file: URL, as demonstrated by a Facebook game, related to a "cookiejacking" issue.
6639| [CVE-2011-1999] Microsoft Internet Explorer 8 does not properly allocate and access memory, which allows remote attackers to execute arbitrary code via vectors involving a "dereferenced memory address," aka "Select Element Remote Code Execution Vulnerability."
6640| [CVE-2011-1996] Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "Option Element Remote Code Execution Vulnerability."
6641| [CVE-2011-1992] The XSS Filter in Microsoft Internet Explorer 8 allows remote attackers to read content from a different (1) domain or (2) zone via a "trial and error" attack, aka "XSS Filter Information Disclosure Vulnerability."
6642| [CVE-2011-1713] Microsoft msxml.dll, as used in Internet Explorer 8 on Windows 7, allows remote attackers to obtain potentially sensitive information about heap memory addresses via an XML document containing a call to the XSLT generate-id XPath function. NOTE: this might overlap CVE-2011-1202.
6643| [CVE-2011-1347] Unspecified vulnerability in Microsoft Internet Explorer 8 on Windows 7 allows remote attackers to bypass Protected Mode and create arbitrary files by leveraging access to a Low integrity process, as demonstrated by Stephen Fewer as the third of three chained vulnerabilities during a Pwn2Own competition at CanSecWest 2011.
6644| [CVE-2011-1346] Unspecified vulnerability in Microsoft Internet Explorer 8 on Windows 7 allows remote attackers to execute arbitrary code via unknown vectors, as demonstrated by Stephen Fewer as the second of three chained vulnerabilities during a Pwn2Own competition at CanSecWest 2011.
6645| [CVE-2011-1345] Microsoft Internet Explorer 6, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, as demonstrated by Stephen Fewer as the first of three chained vulnerabilities during a Pwn2Own competition at CanSecWest 2011, aka "Object Management Memory Corruption Vulnerability."
6646| [CVE-2011-1266] The Vector Markup Language (VML) implementation in vgx.dll in Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, aka "VML Memory Corruption Vulnerability."
6647| [CVE-2011-1260] Microsoft Internet Explorer 8 and 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, aka "Layout Memory Corruption Vulnerability."
6648| [CVE-2011-1258] Microsoft Internet Explorer 6 through 8 does not properly restrict web script, which allows user-assisted remote attackers to obtain sensitive information from a different (1) domain or (2) zone via vectors involving a drag-and-drop operation, aka "Drag and Drop Information Disclosure Vulnerability."
6649| [CVE-2011-1257] Race condition in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors involving access to an object, aka "Window Open Race Condition Vulnerability."
6650| [CVE-2011-1256] Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, aka "DOM Modification Memory Corruption Vulnerability."
6651| [CVE-2011-1255] The Timed Interactive Multimedia Extensions (aka HTML+TIME) implementation in Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, aka "Time Element Memory Corruption Vulnerability."
6652| [CVE-2011-1254] Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, aka "Drag and Drop Memory Corruption Vulnerability."
6653| [CVE-2011-1252] Cross-site scripting (XSS) vulnerability in the SafeHTML function in the toStaticHTML API in Microsoft Internet Explorer 7 and 8, Office SharePoint Server 2007 SP2, Office SharePoint Server 2010 Gold and SP1, Groove Server 2010 Gold and SP1, Windows SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via unspecified strings, aka "toStaticHTML Information Disclosure Vulnerability" or "HTML Sanitization Vulnerability."
6654| [CVE-2011-1251] Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, aka "DOM Manipulation Memory Corruption Vulnerability."
6655| [CVE-2011-1246] Microsoft Internet Explorer 8 does not properly handle content settings in HTTP responses, which allows remote web servers to obtain sensitive information from a different (1) domain or (2) zone via a crafted response, aka "MIME Sniffing Information Disclosure Vulnerability."
6656| [CVE-2011-1244] Microsoft Internet Explorer 6, 7, and 8 does not enforce intended domain restrictions on content access, which allows remote attackers to obtain sensitive information or conduct clickjacking attacks via a crafted web site, aka "Frame Tag Information Disclosure Vulnerability."
6657| [CVE-2011-0346] Use-after-free vulnerability in the ReleaseInterface function in MSHTML.DLL in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to the DOM implementation and the BreakAASpecial and BreakCircularMemoryReferences functions, as demonstrated by cross_fuzz, aka "MSHTML Memory Corruption Vulnerability."
6658| [CVE-2011-0038] Untrusted search path vulnerability in Microsoft Internet Explorer 8 might allow local users to gain privileges via a Trojan horse IEShims.dll in the current working directory, as demonstrated by a Desktop directory that contains an HTML file, aka "Internet Explorer Insecure Library Loading Vulnerability."
6659| [CVE-2011-0036] Microsoft Internet Explorer 6, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, relagted to a "dangling pointer," aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2010-2556 and CVE-2011-0035.
6660| [CVE-2011-0035] Microsoft Internet Explorer 6, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2010-2556 and CVE-2011-0036.
6661| [CVE-2010-5071] The JavaScript implementation in Microsoft Internet Explorer 8.0 and earlier does not properly restrict the set of values contained in the object returned by the getComputedStyle method, which allows remote attackers to obtain sensitive information about visited web pages by calling this method.
6662| [CVE-2010-3971] Use-after-free vulnerability in the CSharedStyleSheet::Notify function in the Cascading Style Sheets (CSS) parser in mshtml.dll, as used in Microsoft Internet Explorer 6 through 8 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a self-referential @import rule in a stylesheet, aka "CSS Memory Corruption Vulnerability."
6663| [CVE-2010-3964] Unrestricted file upload vulnerability in the Document Conversions Launcher Service in Microsoft Office SharePoint Server 2007 SP2, when the Document Conversions Load Balancer Service is enabled, allows remote attackers to execute arbitrary code via a crafted SOAP request to TCP port 8082, aka "Malformed Request Code Execution Vulnerability."
6664| [CVE-2010-3962] Use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code via vectors related to Cascading Style Sheets (CSS) token sequences and the clip attribute, aka an "invalid flag reference" issue or "Uninitialized Memory Corruption Vulnerability," as exploited in the wild in November 2010.
6665| [CVE-2010-3886] The CTimeoutEventList::InsertIntoTimeoutList function in Microsoft mshtml.dll uses a certain pointer value as part of producing Timer ID values for the setTimeout and setInterval methods in VBScript and JScript, which allows remote attackers to obtain sensitive information about the heap memory addresses used by an application, as demonstrated by the Internet Explorer 8 application.
6666| [CVE-2010-3348] Microsoft Internet Explorer 6, 7, and 8 does not prevent rendering of cached content as HTML, which allows remote attackers to access content from a different (1) domain or (2) zone via unspecified script code, aka "Cross-Domain Information Disclosure Vulnerability," a different vulnerability than CVE-2010-3342.
6667| [CVE-2010-3346] Microsoft Internet Explorer 6, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "HTML Element Memory Corruption Vulnerability."
6668| [CVE-2010-3345] Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "HTML Element Memory Corruption Vulnerability."
6669| [CVE-2010-3342] Microsoft Internet Explorer 6, 7, and 8 does not prevent rendering of cached content as HTML, which allows remote attackers to access content from a different (1) domain or (2) zone via unspecified script code, aka "Cross-Domain Information Disclosure Vulnerability," a different vulnerability than CVE-2010-3348.
6670| [CVE-2010-3331] Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory in certain circumstances involving use of Microsoft Word to read Word documents, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability."
6671| [CVE-2010-3330] Microsoft Internet Explorer 6 through 8 does not properly restrict script access to content from a different (1) domain or (2) zone, which allows remote attackers to obtain sensitive information via a crafted web site, aka "Cross-Domain Information Disclosure Vulnerability."
6672| [CVE-2010-3329] mshtmled.dll in Microsoft Internet Explorer 7 and 8 allows remote attackers to execute arbitrary code via a crafted Microsoft Office document that causes the HtmlDlgHelper class destructor to access uninitialized memory, aka "Uninitialized Memory Corruption Vulnerability."
6673| [CVE-2010-3328] Use-after-free vulnerability in the CAttrArray::PrivateFind function in mshtml.dll in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code by setting an unspecified property of a stylesheet object, aka "Uninitialized Memory Corruption Vulnerability."
6674| [CVE-2010-3327] The implementation of HTML content creation in Microsoft Internet Explorer 6 through 8 does not remove the Anchor element during pasting and editing, which might allow remote attackers to obtain sensitive deleted information by visiting a web page, aka "Anchor Element Information Disclosure Vulnerability."
6675| [CVE-2010-3325] Microsoft Internet Explorer 6 through 8 does not properly handle unspecified special characters in Cascading Style Sheets (CSS) documents, which allows remote attackers to obtain sensitive information from a different (1) domain or (2) zone via a crafted web site, aka "CSS Special Character Information Disclosure Vulnerability."
6676| [CVE-2010-3324] The toStaticHTML function in Microsoft Internet Explorer 8, and the SafeHTML function in Microsoft Windows SharePoint Services 3.0 SP2, SharePoint Foundation 2010, Office SharePoint Server 2007 SP2, Groove Server 2010, and Office Web Apps, allows remote attackers to bypass the cross-site scripting (XSS) protection mechanism and conduct XSS attacks via a crafted use of the Cascading Style Sheets (CSS) @import rule, aka "HTML Sanitization Vulnerability," a different vulnerability than CVE-2010-1257.
6677| [CVE-2010-3243] Cross-site scripting (XSS) vulnerability in the toStaticHTML function in Microsoft Internet Explorer 8, and the SafeHTML function in Microsoft Windows SharePoint Services 3.0 SP2 and Office SharePoint Server 2007 SP2, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "HTML Sanitization Vulnerability."
6678| [CVE-2010-2560] Microsoft Internet Explorer 6, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "HTML Layout Memory Corruption Vulnerability."
6679| [CVE-2010-2559] Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-3671, CVE-2009-3674, CVE-2010-0245, and CVE-2010-0246.
6680| [CVE-2010-2558] Race condition in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors related to an object in memory, aka "Race Condition Memory Corruption Vulnerability."
6681| [CVE-2010-2556] Microsoft Internet Explorer 6, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability."
6682| [CVE-2010-2442] Microsoft Internet Explorer, possibly 8, does not properly restrict focus changes, which allows remote attackers to read keystrokes via "cross-domain IFRAME gadgets."
6683| [CVE-2010-2375] Package/Privilege: Plugins for Apache, Sun and IIS web servers Unspecified vulnerability in the WebLogic Server component in Oracle Fusion Middleware 7.0 SP7, 8.1 SP6, 9.0, 9.1, 9.2 MP3, 10.0 MP2, 10.3.2, and 10.3.3 allows remote attackers to affect confidentiality and integrity, related to IIS.
6684| [CVE-2010-2118] Microsoft Internet Explorer 6.0.2900.2180 and 8.0.7600.16385 allows remote attackers to cause a denial of service (resource consumption) via JavaScript code containing an infinite loop that creates IFRAME elements for invalid news:// URIs.
6685| [CVE-2010-2091] Microsoft Outlook Web Access (OWA) 8.2.254.0, when Internet Explorer 7 on Windows Server 2003 is used, does not properly handle the id parameter in a Folder IPF.Note action to the default URI, which might allow remote attackers to obtain sensitive information or conduct cross-site scripting (XSS) attacks via an invalid value.
6686| [CVE-2010-1991] Microsoft Internet Explorer 6.0.2900.2180, 7, and 8.0.7600.16385 executes a mail application in situations where an IFRAME element has a mailto: URL in its SRC attribute, which allows remote attackers to cause a denial of service (excessive application launches) via an HTML document with many IFRAME elements.
6687| [CVE-2010-1489] The XSS Filter in Microsoft Internet Explorer 8 does not properly perform neutering for the SCRIPT tag, which allows remote attackers to conduct cross-site scripting (XSS) attacks against web sites that have no inherent XSS vulnerabilities, a different issue than CVE-2009-4074.
6688| [CVE-2010-1262] Microsoft Internet Explorer 6 SP1 and SP2, 7, and 8 allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, related to the CStyleSheet object and a free of the root container, aka "Memory Corruption Vulnerability."
6689| [CVE-2010-1261] The IE8 Developer Toolbar in Microsoft Internet Explorer 8 SP1, SP2, and SP3 allows user-assisted remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability."
6690| [CVE-2010-1260] The IE8 Developer Toolbar in Microsoft Internet Explorer 8 SP1, SP2, and SP3 allows user-assisted remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "HTML Element Memory Corruption Vulnerability."
6691| [CVE-2010-1259] Microsoft Internet Explorer 6 SP1 and SP2, 7, and 8 allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability."
6692| [CVE-2010-1258] Microsoft Internet Explorer 6, 7, and 8 does not properly determine the origin of script code, which allows remote attackers to execute script in an unintended domain or security zone, and obtain sensitive information, via unspecified vectors, aka "Event Handler Cross-Domain Vulnerability."
6693| [CVE-2010-1118] Unspecified vulnerability in Internet Explorer 8 on Microsoft Windows 7 allows remote attackers to execute arbitrary code via unknown vectors, possibly related to a use-after-free issue, as demonstrated by Peter Vreugdenhil during a Pwn2Own competition at CanSecWest 2010.
6694| [CVE-2010-1117] Heap-based buffer overflow in Internet Explorer 8 on Microsoft Windows 7 allows remote attackers to discover the base address of a Windows .dll file, and possibly have unspecified other impact, via unknown vectors, as demonstrated by Peter Vreugdenhil during a Pwn2Own competition at CanSecWest 2010.
6695| [CVE-2010-0811] Multiple unspecified vulnerabilities in the Microsoft Internet Explorer 8 Developer Tools ActiveX control in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allow remote attackers to execute arbitrary code via unknown vectors that "corrupt the system state," aka "Microsoft Internet Explorer 8 Developer Tools Vulnerability."
6696| [CVE-2010-0555] Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, 7, and 8 does not prevent rendering of non-HTML local files as HTML documents, which allows remote attackers to bypass intended access restrictions and read arbitrary files via vectors involving the product's use of text/html as the default content type for files that are encountered after a redirection, aka the URLMON sniffing vulnerability, a variant of CVE-2009-1140 and related to CVE-2008-1448.
6697| [CVE-2010-0494] Cross-domain vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 allows user-assisted remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted HTML document in a situation where the client user drags one browser window across another browser window, aka "HTML Element Cross-Domain Vulnerability."
6698| [CVE-2010-0492] Use-after-free vulnerability in mstime.dll in Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code via vectors related to the TIME2 behavior, the CTimeAction object, and destruction of markup, leading to memory corruption, aka "HTML Object Memory Corruption Vulnerability."
6699| [CVE-2010-0490] Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability."
6700| [CVE-2010-0255] Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, 7, and 8 does not prevent rendering of non-HTML local files as HTML documents, which allows remote attackers to bypass intended access restrictions and read arbitrary files via vectors involving JavaScript exploit code that constructs a reference to a file://127.0.0.1 URL, aka the dynamic OBJECT tag vulnerability, as demonstrated by obtaining the data from an index.dat file, a variant of CVE-2009-1140 and related to CVE-2008-1448.
6701| [CVE-2010-0249] Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4
6702| [CVE-2010-0248] Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "HTML Object Memory Corruption Vulnerability."
6703| [CVE-2010-0246] Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-3671, CVE-2009-3674, and CVE-2010-0245.
6704| [CVE-2010-0245] Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-3671, CVE-2009-3674, and CVE-2010-0246.
6705| [CVE-2010-0244] Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-2530 and CVE-2009-2531.
6706| [CVE-2010-0112] Multiple SQL injection vulnerabilities in the Administrative Interface in the IIS extension in Symantec IM Manager before 8.4.16 allow remote attackers to execute arbitrary SQL commands via (1) the rdReport parameter to rdpageimlogic.aspx, related to the sGetDefinition function in rdServer.dll, and SQL statements contained within a certain report file
6707| [CVE-2010-0027] The URL validation functionality in Microsoft Internet Explorer 5.01, 6, 6 SP1, 7 and 8, and the ShellExecute API function in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, does not properly process input parameters, which allows remote attackers to execute arbitrary local programs via a crafted URL, aka "URL Validation Vulnerability."
6708| [CVE-2009-4074] The XSS Filter in Microsoft Internet Explorer 8 allows remote attackers to leverage the "response-changing mechanism" to conduct cross-site scripting (XSS) attacks against web sites that have no inherent XSS vulnerabilities, related to the details of output encoding and improper modification of an HTML attribute, aka "XSS Filter Script Handling Vulnerability."
6709| [CVE-2009-4073] The printing functionality in Microsoft Internet Explorer 8 allows remote attackers to discover a local pathname, and possibly a local username, by reading the dc:title element of a PDF document that was generated from a local web page.
6710| [CVE-2009-3674] Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-3671.
6711| [CVE-2009-3673] Microsoft Internet Explorer 7 and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability."
6712| [CVE-2009-3671] Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-3674.
6713| [CVE-2009-3003] Microsoft Internet Explorer 6 through 8 allows remote attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary URL on the web site visited by the victim, as demonstrated by a visit to an attacker-controlled web page, which triggers a spoofed login form for the site containing that page.
6714| [CVE-2009-2764] Microsoft Internet Explorer 8.0.7100.0 on Windows 7 RC on the x64 platform allows remote attackers to cause a denial of service (application crash) via a certain DIV element in conjunction with SCRIPT elements that have empty contents and no reference to a valid external script location.
6715| [CVE-2009-2655] mshtml.dll in Microsoft Internet Explorer 7 and 8 on Windows XP SP3 allows remote attackers to cause a denial of service (application crash) by calling the JavaScript findText method with a crafted Unicode string in the first argument, and only one additional argument, as demonstrated by a second argument of -1.
6716| [CVE-2009-2536] Microsoft Internet Explorer 5 through 8 allows remote attackers to cause a denial of service (memory consumption and application crash) via a large integer value for the length property of a Select object, a related issue to CVE-2009-1692.
6717| [CVE-2009-2531] Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-2530.
6718| [CVE-2009-2530] Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-2531.
6719| [CVE-2009-2529] Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, 7, and 8 does not properly handle argument validation for unspecified variables, which allows remote attackers to execute arbitrary code via a crafted HTML document, aka "HTML Component Handling Vulnerability."
6720| [CVE-2009-2069] Microsoft Internet Explorer before 8 displays a cached certificate for a (1) 4xx or (2) 5xx CONNECT response page returned by a proxy server, which allows man-in-the-middle attackers to spoof an arbitrary https site by letting a browser obtain a valid certificate from this site during one request, and then sending the browser a crafted 502 response page upon a subsequent request.
6721| [CVE-2009-2064] Microsoft Internet Explorer 8, and possibly other versions, detects http content in https web pages only when the top-level frame uses https, which allows man-in-the-middle attackers to execute arbitrary web script, in an https site's context, by modifying an http page to include an https iframe that references a script file on an http site, related to "HTTP-Intended-but-HTTPS-Loadable (HPIHSL) pages."
6722| [CVE-2009-2057] Microsoft Internet Explorer before 8 uses the HTTP Host header to determine the context of a document provided in a (1) 4xx or (2) 5xx CONNECT response from a proxy server, which allows man-in-the-middle attackers to execute arbitrary web script by modifying this CONNECT response, aka an "SSL tampering" attack.
6723| [CVE-2009-1532] Microsoft Internet Explorer 8 for Windows XP SP2 and SP3
6724| [CVE-2009-1335] Microsoft Internet Explorer 7 and 8 on Windows XP and Vista allows remote attackers to cause a denial of service (application hang) via a large document composed of unprintable characters, aka MSRC 9011jr.
6725| [CVE-2009-1043] Unspecified vulnerability in Microsoft Internet Explorer 8 on Windows 7 allows remote attackers to execute arbitrary code via unknown vectors triggered by clicking on a link, as demonstrated by Nils during a PWN2OWN competition at CanSecWest 2009.
6726| [CVE-2009-1016] Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, and 7.0 SP7 allows remote authenticated users to affect confidentiality, integrity, and availability, related to IIS. NOTE: the previous information was obtained from the April 2009 CPU. Oracle has not commented on claims from a reliable researcher that this is a stack-based buffer overflow involving an unspecified Server Plug-in and a crafted SSL certificate.
6727| [CVE-2009-1012] Unspecified vulnerability in the plug-ins for Apache and IIS web servers in Oracle BEA WebLogic Server 7.0 Gold through SP7, 8.1 Gold through SP6, 9.0, 9.1, 9.2 Gold through MP3, 10.0 Gold through MP1, and 10.3 allows remote attackers to affect confidentiality, integrity, and availability. NOTE: the previous information was obtained from the April 2009 CPU. Oracle has not commented on claims from a reliable researcher that this is an integer overflow in an unspecified plug-in that parses HTTP requests, which leads to a heap-based buffer overflow.
6728| [CVE-2009-1011] Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.2.2 and 8.3.0 allows local users to affect confidentiality, integrity, and availability, related to HTML. NOTE: the previous information was obtained from the April 2009 CPU. Oracle has not commented on reliable researcher claims that this issue is for multiple integer overflows in a function that parses an optional data stream within a Microsoft Office file, leading to a heap-based buffer overflow.
6729| [CVE-2009-0084] Use-after-free vulnerability in DirectShow in Microsoft DirectX 8.1 and 9.0 allows remote attackers to execute arbitrary code via an MJPEG file or video stream with a malformed Huffman table, which triggers an exception that frees heap memory that is later accessed, aka "MJPEG Decompression Vulnerability."
6730| [CVE-2009-0072] Microsoft Internet Explorer 6.0 through 8.0 beta2 allows remote attackers to cause a denial of service (application crash) via an onload=screen[""] attribute value in a BODY element.
6731| [CVE-2008-5750] Argument injection vulnerability in Microsoft Internet Explorer 8 beta 2 on Windows XP SP3 allows remote attackers to execute arbitrary commands via the --renderer-path option in a chromehtml: URI.
6732| [CVE-2008-5556] ** DISPUTED ** The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 does not recognize attack patterns designed to operate against web pages that are encoded with utf-7, which allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks by injecting crafted utf-7 content. NOTE: the vendor reportedly disputes this issue, stating "Behaviour is by design."
6733| [CVE-2008-5555] Microsoft Internet Explorer 8.0 Beta 2 relies on the XDomainRequestAllowed HTTP header to authorize data exchange between domains, which allows remote attackers to bypass the product's XSS Filter protection mechanism, and conduct XSS and cross-domain attacks, by injecting this header after a CRLF sequence, related to "XDomainRequest Allowed Injection (XAI)." NOTE: the vendor has reportedly stated that the XSS Filter intentionally does not attempt to "address every conceivable XSS attack scenario."
6734| [CVE-2008-5554] The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 does not properly handle some HTTP headers that appear after a CRLF sequence in a URI, which allows remote attackers to bypass the XSS protection mechanism and conduct XSS or redirection attacks, as demonstrated by the (1) Location and (2) Set-Cookie HTTP headers. NOTE: the vendor has reportedly stated that the XSS Filter intentionally does not attempt to "address every conceivable XSS attack scenario."
6735| [CVE-2008-5553] The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 disables itself upon encountering a certain X-XSS-Protection HTTP header, which allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks by injecting this header after a CRLF sequence. NOTE: the vendor has reportedly stated that the XSS Filter intentionally does not attempt to "address every conceivable XSS attack scenario."
6736| [CVE-2008-5552] The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks via a CRLF sequence in conjunction with a crafted Content-Type header, as demonstrated by a header with a utf-7 charset value. NOTE: the vendor has reportedly stated that the XSS Filter intentionally does not attempt to "address every conceivable XSS attack scenario."
6737| [CVE-2008-5551] The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks by injecting data at two different positions within an HTML document, related to STYLE elements and the CSS expression property, aka a "double injection."
6738| [CVE-2008-5457] Unspecified vulnerability in the Oracle BEA WebLogic Server Plugins for Apache, Sun and IIS web servers component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, and 7.0 SP7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
6739| [CVE-2008-5416] Heap-based buffer overflow in Microsoft SQL Server 2000 SP4, 8.00.2050, 8.00.2039, and earlier
6740| [CVE-2008-4295] Microsoft Windows Mobile 6.0 on HTC Wiza 200 and HTC MDA 8125 devices does not properly handle the first attempt to establish a Bluetooth connection to a peer with a long name, which allows remote attackers to cause a denial of service (device reboot) by configuring a Bluetooth device with a long hci name and (1) connecting directly to the Windows Mobile system or (2) waiting for the Windows Mobile system to scan for nearby devices.
6741| [CVE-2008-4256] The Charts ActiveX control in Microsoft Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2 does not properly handle errors during access to incorrectly initialized objects, which allows remote attackers to execute arbitrary code via a crafted HTML document, related to corruption of the "system state," aka "Charts Control Memory Corruption Vulnerability."
6742| [CVE-2008-4255] Heap-based buffer overflow in mscomct2.ocx (aka Windows Common ActiveX control or Microsoft Animation ActiveX control) in Microsoft Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2, and Office Project 2003 SP3 and 2007 Gold and SP1 allows remote attackers to execute arbitrary code via an AVI file with a crafted stream length, which triggers an "allocation error" and memory corruption, aka "Windows Common AVI Parsing Overflow Vulnerability."
6743| [CVE-2008-4254] Multiple integer overflows in the Hierarchical FlexGrid ActiveX control (mshflxgd.ocx) in Microsoft Visual Basic 6.0 and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2 allow remote attackers to execute arbitrary code via crafted (1) Rows and (2) Cols properties to the (a) ExpandAll and (b) CollapseAll methods, related to access of incorrectly initialized objects and corruption of the "system state," aka "Hierarchical FlexGrid Control Memory Corruption Vulnerability."
6744| [CVE-2008-4253] The FlexGrid ActiveX control in Microsoft Visual Basic 6.0, Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2, Office FrontPage 2002 SP3, and Office Project 2003 SP3 does not properly handle errors during access to incorrectly initialized objects, which allows remote attackers to execute arbitrary code via a crafted HTML document, related to corruption of the "system state," aka "FlexGrid Control Memory Corruption Vulnerability."
6745| [CVE-2008-4252] The DataGrid ActiveX control in Microsoft Visual Basic 6.0 and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2 does not properly handle errors during access to incorrectly initialized objects, which allows remote attackers to execute arbitrary code via a crafted HTML document, related to corruption of the "system state," aka "DataGrid Control Memory Corruption Vulnerability."
6746| [CVE-2008-4127] Mshtml.dll in Microsoft Internet Explorer 7 Gold 7.0.5730 and 8 Beta 8.0.6001 on Windows XP SP2 allows remote attackers to cause a denial of service (failure of subsequent image rendering) via a crafted PNG file, related to an infinite loop in the CDwnTaskExec::ThreadExec function.
6747| [CVE-2008-4110] Buffer overflow in the SQLVDIRLib.SQLVDirControl ActiveX control in Tools\Binn\sqlvdir.dll in Microsoft SQL Server 2000 (aka SQL Server 8.0) allows remote attackers to cause a denial of service (browser crash) or possibly execute arbitrary code via a long URL in the second argument to the Connect method. NOTE: this issue is not a vulnerability in many environments, since the control is not marked as safe for scripting and would not execute with default Internet Explorer settings.
6748| [CVE-2008-3815] Unspecified vulnerability in Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 7.0 before 7.0(8)3, 7.1 before 7.1(2)78, 7.2 before 7.2(4)16, 8.0 before 8.0(4)6, and 8.1 before 8.1(1)13, when configured as a VPN using Microsoft Windows NT Domain authentication, allows remote attackers to bypass VPN authentication via unknown vectors.
6749| [CVE-2008-3704] Heap-based buffer overflow in the MaskedEdit ActiveX control in Msmask32.ocx 6.0.81.69, and possibly other versions before 6.0.84.18, in Microsoft Visual Studio 6.0, Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2 allows remote attackers to execute arbitrary code via a long Mask parameter, related to not "validating property values with boundary checks," as exploited in the wild in August 2008, aka "Masked Edit Control Memory Corruption Vulnerability."
6750| [CVE-2008-3015] Integer overflow in gdiplus.dll in GDI+ in Microsoft Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a BMP image file with a malformed BitMapInfoHeader that triggers a buffer overflow, aka "GDI+ BMP Integer Overflow Vulnerability."
6751| [CVE-2008-3014] Buffer overflow in gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a malformed WMF image file that triggers improper memory allocation, aka "GDI+ WMF Buffer Overrun Vulnerability."
6752| [CVE-2008-3013] gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a malformed GIF image file containing many extension markers for graphic control extensions and subsequent unknown labels, aka "GDI+ GIF Parsing Vulnerability."
6753| [CVE-2008-3012] gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 does not properly perform memory allocation, which allows remote attackers to execute arbitrary code via a malformed EMF image file, aka "GDI+ EMF Memory Corruption Vulnerability."
6754| [CVE-2008-2948] Cross-domain vulnerability in Microsoft Internet Explorer 7 and 8 allows remote attackers to change the location property of a frame via the Object data type, and use a frame from a different domain to observe domain-independent events, as demonstrated by observing onkeydown events with caballero-listener. NOTE: according to Microsoft, this is a duplicate of CVE-2008-2947, possibly a different attack vector.
6755| [CVE-2008-2579] Unspecified vulnerability in the WebLogic Server Plugins for Apache, Sun and IIS web servers component in Oracle BEA Product Suite 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, 7.0 SP7, and 6.1 SP7 has unknown impact and remote attack vectors.
6756| [CVE-2008-1544] The setRequestHeader method of the XMLHttpRequest object in Microsoft Internet Explorer 5.01, 6, and 7 does not block dangerous HTTP request headers when certain 8-bit character sequences are appended to a header name, which allows remote attackers to (1) conduct HTTP request splitting and HTTP request smuggling attacks via an incorrect Content-Length header, (2) access arbitrary virtual hosts via a modified Host header, (3) bypass referrer restrictions via an incorrect Referer header, and (4) bypass the same-origin policy and obtain sensitive information via a crafted request header.
6757| [CVE-2008-1444] Stack-based buffer overflow in Microsoft DirectX 7.0 and 8.1 on Windows 2000 SP4 allows remote attackers to execute arbitrary code via a Synchronized Accessible Media Interchange (SAMI) file with crafted parameters for a Class Name variable, aka the "SAMI Format Parsing Vulnerability."
6758| [CVE-2008-0108] Stack-based buffer overflow in wkcvqd01.dll in Microsoft Works 6 File Converter, as used in Office 2003 SP2 and SP3, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted field lengths, aka "Microsoft Works File Converter Field Length Vulnerability."
6759| [CVE-2008-0105] Microsoft Works 6 File Converter, as used in Office 2003 SP2 and SP3, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted section header index table information, aka "Microsoft Works File Converter Index Table Vulnerability."
6760| [CVE-2008-0011] Microsoft DirectX 8.1 through 9.0c, and DirectX on Microsoft XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008, does not properly perform MJPEG error checking, which allows remote attackers to execute arbitrary code via a crafted MJPEG stream in a (1) AVI or (2) ASF file, aka the "MJPEG Decoder Vulnerability."
6761| [CVE-2007-5348] Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via an image file with crafted gradient sizes in gradient fill input, which triggers a heap-based buffer overflow related to GdiPlus.dll and VGX.DLL, aka "GDI+ VML Buffer Overrun Vulnerability."
6762| [CVE-2007-5277] Microsoft Internet Explorer 6 drops DNS pins based on failed connections to irrelevant TCP ports, which makes it easier for remote attackers to conduct DNS rebinding attacks, as demonstrated by a port 81 URL in an IMG SRC, when the DNS pin had been established for a session on port 80, a different issue than CVE-2006-4560.
6763| [CVE-2007-4916] Heap-based buffer overflow in the FileFind::FindFile method in (1) MFC42.dll, (2) MFC42u.dll, (3) MFC71.dll, and (4) MFC71u.dll in Microsoft Foundation Class (MFC) Library 8.0, as used by the ListFiles method in hpqutil.dll 2.0.0.138 in Hewlett-Packard (HP) All-in-One and Photo & Imaging Gallery 1.1 and probably other products, allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long first argument.
6764| [CVE-2007-4814] Buffer overflow in the SQLServer ActiveX control in the Distributed Management Objects OLE DLL (sqldmo.dll) 2000.085.2004.00 in Microsoft SQL Server Enterprise Manager 8.05.2004 allows remote attackers to execute arbitrary code via a long second argument to the Start method.
6765| [CVE-2007-2931] Heap-based buffer overflow in Microsoft MSN Messenger 6.2, 7.0, and 7.5, and Live Messenger 8.0 allows user-assisted remote attackers to execute arbitrary code via unspecified vectors involving video conversation handling in Web Cam and video chat sessions.
6766| [CVE-2007-0842] The 64-bit versions of Microsoft Visual C++ 8.0 standard library (MSVCR80.DLL) time functions, including (1) localtime, (2) localtime_s, (3) gmtime, (4) gmtime_s, (5) ctime, (6) ctime_s, (7) wctime, (8) wctime_s, and (9) fstat, trigger an assertion error instead of a NULL pointer or EINVAL when processing a time argument later than Jan 1, 3000, which might allow context-dependent attackers to cause a denial of service (application exit) via large time values. NOTE: it could be argued that this is a design limitation of the functions, and the vulnerability lies with any application that does not validate arguments to these functions. However, this behavior is inconsistent with documentation, which does not list assertions as a possible result of an error condition.
6767| [CVE-2007-0216] wkcvqd01.dll in Microsoft Works 6 File Converter, as used in Office 2003 SP2, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted section length headers, aka "Microsoft Works File Converter Input Validation Vulnerability."
6768| [CVE-2007-0047] CRLF injection vulnerability in Adobe Acrobat Reader Plugin before 8.0.0, when used with the Microsoft.XMLHTTP ActiveX object in Internet Explorer, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the javascript: URI in the (1) FDF, (2) XML, or (3) XFDF AJAX request parameters.
6769| [CVE-2006-6252] Microsoft Windows Live Messenger 8.0 and earlier, when gestual emoticons are enabled, allows remote attackers to cause a denial of service (CPU consumption) via a long string composed of ":D" sequences, which are interpreted as emoticons.
6770| [CVE-2006-3654] Buffer overflow in wksss.exe 8.4.702.0 in Microsoft Works Spreadsheet 8.0 allows remote attackers to cause a denial of service (CPU consumption or crash) via crafted Excel files.
6771| [CVE-2006-3653] wksss.exe 8.4.702.0 in Microsoft Works Spreadsheet 8.0 allows remote attackers to cause a denial of service (CPU consumption or crash) via crafted (1) Works, (2) Excel, and (3) Lotus 1-2-3 files.
6772| [CVE-2005-3568] db2fmp process in IBM DB2 Content Manager before 8.2 Fix Pack 10 allows local users to cause a denial of service (CPU consumption) by importing a corrupted Microsoft Excel file, aka "CORRUPTED EXEL FILE WILL CAUSE TEXT SEARCH PROCESS LOOPING."
6773| [CVE-2005-3182] Buffer overflow in the HTTP management interface for GFI MailSecurity 8.1 allows remote attackers to execute arbitrary code via long headers such as (1) Host and (2) Accept in HTTP requests. NOTE: the vendor suggests that this issues is "in an underlying Microsoft technology" which, if true, could mean that the overflow affects other products as well.
6774| [CVE-2005-3174] Microsoft Windows 2000 before Update Rollup 1 for SP4 allows users to log on to the domain, even when their password has expired, if the fully qualified domain name (FQDN) is 8 characters long.
6775| [CVE-2004-0540] Microsoft Windows 2000, when running in a domain whose Fully Qualified Domain Name (FQDN) is exactly 8 characters long, does not prevent users with expired passwords from logging on to the domain.
6776| [CVE-2003-0604] Windows Media Player (WMP) 7 and 8, as running on Internet Explorer and possibly other Microsoft products that process HTML, allows remote attackers to bypass zone restrictions and access or execute arbitrary files via an IFRAME tag pointing to an ASF file whose Content-location contains a File:// URL.
6777| [CVE-2002-2435] The Cascading Style Sheets (CSS) implementation in Microsoft Internet Explorer 8.0 and earlier does not properly handle the :visited pseudo-class, which allows remote attackers to obtain sensitive information about visited web pages via a crafted HTML document, a related issue to CVE-2010-2264.
6778| [CVE-2002-2380] NetDSL ADSL Modem 800 with Microsoft Network firmware 5.5.11 allows remote attackers to gain access to configuration menus by sniffing undocumented usernames and passwords from network traffic.
6779| [CVE-2002-0797] Buffer overflow in the MIB parsing component of mibiisa for Solaris 5.6 through 8 allows remote attackers to gain root privileges.
6780| [CVE-2001-0238] Microsoft Data Access Component Internet Publishing Provider 8.103.2519.0 and earlier allows remote attackers to bypass Security Zone restrictions via WebDAV requests.
6781|
6782| SecurityFocus - https://www.securityfocus.com/bid/:
6783| [582] Microsoft IIS And PWS 8.3 Directory Name Vulnerability
6784| [58847] Microsoft Windows Defender for Windows 8 and Windows RT Local Privilege Escalation Vulnerability
6785| [42467] Microsoft Internet Explorer 8 'toStaticHTML()' HTML Sanitization Bypass Weakness
6786| [40490] Microsoft Internet Explorer 8 Developer Tools Remote Code Execution Vulnerability
6787| [37135] Microsoft Internet Explorer 8 Cross-Site Scripting Filter Cross-Site Scripting Vulnerability
6788| [35941] Microsoft Internet Explorer 8 Denial of Service Vulnerability
6789|
6790| IBM X-Force - https://exchange.xforce.ibmcloud.com:
6791| [40937] Microsoft Windows Knowledge Base Article 815495 update not installed
6792| [37226] Microsoft Windows Knowledge Base Article 815495 update not installed
6793| [19102] Microsoft Knowledge Base Article 885834 is not installed
6794| [19090] Microsoft Knowledge Base Article 885250 is not installed
6795| [18392] Microsoft Windows Knowledge Base Article 885249 update is not installed
6796| [18391] Microsoft Windows Knowledge Base Article 885835 update is not installed
6797| [18390] Microsoft Windows Knowledge Base Article 885836 update is not installed
6798| [82776] Microsoft Internet Explorer 10 on Windows 8 sandbox security bypass
6799| [66402] Microsoft Windows kernel-mode driver (win32k.sys) variant 8 privilege escalation
6800| [57338] Microsoft Internet Explorer 8 Developer Tools code execution
6801| [24509] Microsoft Windows Knowledge Base Article 889167 update is not installed
6802| [22882] Microsoft Windows Knowledge Base Article 896424 update is not installed
6803| [22156] Microsoft Windows Knowledge Base Article 899589 update is not installed
6804| [22155] Microsoft Knowledge Base Article 896688 is not installed
6805| [22072] Microsoft Knowledge Base Article 899587 is not installed
6806| [22071] Microsoft Knowledge Base Article 896428 is not installed
6807| [22069] Microsoft Knowledge Base Article 890859 is not installed
6808| [22068] Microsoft Knowledge Base Article 890046 is not installed
6809| [21704] Microsoft Windows Knowledge Base Article 896727 update is not installed
6810| [21605] Microsoft Windows Knowledge Base Article 896423 update is not installed
6811| [21603] Microsoft Windows Knowledge Base Article 899588 update is not installed
6812| [21601] Microsoft Windows Knowledge Base Article 899591 update is not installed
6813| [21600] Microsoft Windows Knowledge Base Article 893756 update is not installed
6814| [20826] Microsoft Windows Knowledge Base Article 896422 update is not installed
6815| [20825] Microsoft Windows Knowledge Base Article 896358 update is not installed
6816| [20823] Microsoft Windows Knowledge Base Article 890169 update is not installed
6817| [20822] Microsoft Windows Knowledge Base Article 883939 update is not installed
6818| [20820] Microsoft Windows Knowledge Base Article 896426 update is not installed
6819| [20382] Microsoft Windows Knowledge Base Article 894320 update is not installed
6820| [20318] Microsoft Windows Knowledge Base Article 893086 update is not installed
6821| [20317] Microsoft Windows Knowledge Base Article 890923 update is not installed
6822| [20000] Microsoft Windows Knowledge Base Article 892944 update is not installed
6823| [19875] Microsoft Knowledge Base Article 893066 is not installed
6824| [19843] Microsoft Windows Knowledge Base Article 894549 update is not installed
6825| [19252] Microsoft Knowledge Base Article 890261 is not installed
6826| [19141] Microsoft Knowledge Base Article 867282 is not installed
6827| [19118] Microsoft Knowledge Base Article 890047 is not installed
6828| [19116] Microsoft Knowledge Base Article 891781 is not installed
6829| [19112] Microsoft Knowledge Base Article 873352 is not installed
6830| [19111] Microsoft Knowledge Base Article 888113 is not installed
6831| [19106] Microsoft Knowledge Base Article 873333 is not installed
6832| [19095] Microsoft Knowledge Base Article 888302 is not installed
6833| [19092] Microsoft Knowledge Base Article 887981 is not installed
6834| [18944] Microsoft Knowledge Base Article 886185 is not installed
6835| [18770] Microsoft Knowledge Base Article 890175 is not installed
6836| [18769] Microsoft Knowledge Base Article 887219 is not installed
6837| [18768] Microsoft Windows Knowledge Base Article 891711 update is not installed
6838| [18766] Microsoft Windows Knowledge Base Article 871250 update is not installed
6839| [18394] Microsoft Windows Knowledge Base Article 870763 update is not installed
6840| [18393] Microsoft Windows Knowledge Base Article 873339 update is not installed
6841| [18314] Microsoft Windows Knowledge Base Article 889293 update is not installed
6842|
6843| Exploit-DB - https://www.exploit-db.com:
6844| [17159] Microsoft Host Integration Server <= 8.5.4224.0 DoS Vulnerabilities
6845| [31118] Microsoft Works 8.0 File Converter Field Length Remote Code Execution Vulnerability
6846| [30537] Microsoft MSN Messenger <= 8.0 - Video Conversation Buffer Overflow Vulnerability
6847| [28222] microsoft works 8.0 spreadsheet Multiple Vulnerabilities
6848| [12728] Microsoft Outlook Web Access (OWA) 8.2.254.0 - Information Disclosure vulnerability
6849|
6850| OpenVAS (Nessus) - http://www.openvas.org:
6851| [902914] Microsoft IIS GET Request Denial of Service Vulnerability
6852| [902796] Microsoft IIS IP Address/Internal Network Name Disclosure Vulnerability
6853| [902694] Microsoft Windows IIS FTP Service Information Disclosure Vulnerability (2761226)
6854| [901120] Microsoft IIS Authentication Remote Code Execution Vulnerability (982666)
6855| [900944] Microsoft IIS FTP Server 'ls' Command DOS Vulnerability
6856| [900874] Microsoft IIS FTP Service Remote Code Execution Vulnerabilities (975254)
6857| [900711] Microsoft IIS WebDAV Remote Authentication Bypass Vulnerability
6858| [900567] Microsoft IIS Security Bypass Vulnerability (970483)
6859| [802806] Microsoft IIS Default Welcome Page Information Disclosure Vulnerability
6860| [801669] Microsoft Windows IIS FTP Server DOS Vulnerability
6861| [801520] Microsoft IIS ASP Stack Based Buffer Overflow Vulnerability
6862| [100952] Microsoft IIS FTPd NLST stack overflow
6863| [11443] Microsoft IIS UNC Mapped Virtual Host Vulnerability
6864| [10680] Test Microsoft IIS Source Fragment Disclosure
6865| [903041] Microsoft Windows Kernel Privilege Elevation Vulnerability (2724197)
6866| [903037] Microsoft JScript and VBScript Engines Remote Code Execution Vulnerability (2706045)
6867| [903036] Microsoft Windows Networking Components Remote Code Execution Vulnerabilities (2733594)
6868| [903035] Microsoft Windows Kernel-Mode Drivers Privilege Elevation Vulnerability (2731847)
6869| [903033] Microsoft Windows Kernel-Mode Drivers Privilege Elevation Vulnerabilities (2718523)
6870| [903026] Microsoft Office Remote Code Execution Vulnerabilities (2663830)
6871| [903017] Microsoft Office Remote Code Execution Vulnerability (2639185)
6872| [903000] Microsoft Expression Design Remote Code Execution Vulnerability (2651018)
6873| [902936] Microsoft Windows Kernel-Mode Drivers Remote Code Execution Vulnerabilities (2783534)
6874| [902934] Microsoft .NET Framework Remote Code Execution Vulnerability (2745030)
6875| [902933] Microsoft Windows Shell Remote Code Execution Vulnerabilities (2727528)
6876| [902932] Microsoft Internet Explorer Multiple Use-After-Free Vulnerabilities (2761451)
6877| [902931] Microsoft Office Remote Code Execution Vulnerabilities - 2720184 (Mac OS X)
6878| [902930] Microsoft Office Remote Code Execution Vulnerabilities (2720184)
6879| [902923] Microsoft Internet Explorer Multiple Vulnerabilities (2722913)
6880| [902922] Microsoft Remote Desktop Protocol Remote Code Execution Vulnerability (2723135)
6881| [902921] Microsoft Office Visio/Viewer Remote Code Execution Vulnerability (2733918)
6882| [902920] Microsoft Office Remote Code Execution Vulnerability (2731879)
6883| [902919] Microsoft SharePoint Privilege Elevation Vulnerabilities (2663841)
6884| [902916] Microsoft Windows Kernel Privilege Elevation Vulnerabilities (2711167)
6885| [902913] Microsoft Office Remote Code Execution Vulnerabilities-2663830 (Mac OS X)
6886| [902912] Microsoft Office Word Remote Code Execution Vulnerability-2680352 (Mac OS X)
6887| [902911] Microsoft Office Word Remote Code Execution Vulnerability (2680352)
6888| [902910] Microsoft Office Visio Viewer Remote Code Execution Vulnerability (2597981)
6889| [902909] Microsoft Windows Service Pack Missing Multiple Vulnerabilities
6890| [902908] Microsoft Windows DirectWrite Denial of Service Vulnerability (2665364)
6891| [902906] Microsoft Windows DNS Server Denial of Service Vulnerability (2647170)
6892| [902900] Microsoft Windows SSL/TLS Information Disclosure Vulnerability (2643584)
6893| [902846] Microsoft Windows TLS Protocol Information Disclosure Vulnerability (2655992)
6894| [902845] Microsoft Windows Shell Remote Code Execution Vulnerability (2691442)
6895| [902842] Microsoft Lync Remote Code Execution Vulnerabilities (2707956)
6896| [902841] Microsoft .NET Framework Remote Code Execution Vulnerability (2706726)
6897| [902839] Microsoft FrontPage Server Extensions MS-DOS Device Name DoS Vulnerability
6898| [902833] Microsoft .NET Framework Remote Code Execution Vulnerability (2693777)
6899| [902832] MS Security Update For Microsoft Office, .NET Framework, and Silverlight (2681578)
6900| [902829] Microsoft Windows Common Controls Remote Code Execution Vulnerability (2664258)
6901| [902828] Microsoft .NET Framework Remote Code Execution Vulnerability (2671605)
6902| [902818] Microsoft Remote Desktop Protocol Remote Code Execution Vulnerabilities (2671387)
6903| [902817] Microsoft Visual Studio Privilege Elevation Vulnerability (2651019)
6904| [902811] Microsoft .NET Framework and Microsoft Silverlight Remote Code Execution Vulnerabilities (2651026)
6905| [902807] Microsoft Windows Media Could Allow Remote Code Execution Vulnerabilities (2636391)
6906| [902798] Microsoft SMB Signing Enabled and Not Required At Server
6907| [902797] Microsoft SMB Signing Information Disclosure Vulnerability
6908| [902785] Microsoft AntiXSS Library Information Disclosure Vulnerability (2607664)
6909| [902784] Microsoft Windows Object Packager Remote Code Execution Vulnerability (2603381)
6910| [902783] Microsoft Windows Kernel Security Feature Bypass Vulnerability (2644615)
6911| [902782] MicroSoft Windows Server Service Remote Code Execution Vulnerability (921883)
6912| [902766] Microsoft Windows Kernel Privilege Elevation Vulnerability (2633171)
6913| [902746] Microsoft Active Accessibility Remote Code Execution Vulnerability (2623699)
6914| [902727] Microsoft Office Excel Remote Code Execution Vulnerabilities (2587505)
6915| [902708] Microsoft Remote Desktop Protocol Denial of Service Vulnerability (2570222)
6916| [902696] Microsoft Internet Explorer Multiple Vulnerabilities (2761465)
6917| [902693] Microsoft Windows Kernel-Mode Drivers Remote Code Execution Vulnerabilities (2761226)
6918| [902692] Microsoft Office Excel ReadAV Arbitrary Code Execution Vulnerability
6919| [902689] Microsoft SQL Server Report Manager Cross Site Scripting Vulnerability (2754849)
6920| [902688] Microsoft System Center Configuration Manager XSS Vulnerability (2741528)
6921| [902687] Microsoft Windows Data Access Components Remote Code Execution Vulnerability (2698365)
6922| [902686] Microsoft Internet Explorer Multiple Vulnerabilities (2719177)
6923| [902683] Microsoft Remote Desktop Protocol Remote Code Execution Vulnerability (2685939)
6924| [902682] Microsoft Internet Explorer Multiple Vulnerabilities (2699988)
6925| [902678] Microsoft Silverlight Code Execution Vulnerabilities - 2681578 (Mac OS X)
6926| [902677] Microsoft Windows Prtition Manager Privilege Elevation Vulnerability (2690533)
6927| [902676] Microsoft Windows TCP/IP Privilege Elevation Vulnerabilities (2688338)
6928| [902670] Microsoft Internet Explorer Multiple Vulnerabilities (2675157)
6929| [902663] Microsoft Remote Desktop Protocol Remote Code Execution Vulnerabilities (2671387)
6930| [902662] MicroSoft SMB Server Trans2 Request Remote Code Execution Vulnerability
6931| [902660] Microsoft SMB Transaction Parsing Remote Code Execution Vulnerability
6932| [902658] Microsoft RDP Server Private Key Information Disclosure Vulnerability
6933| [902649] Microsoft Internet Explorer Multiple Vulnerabilities (2647516)
6934| [902642] Microsoft Internet Explorer Multiple Vulnerabilities (2618444)
6935| [902626] Microsoft SharePoint SafeHTML Information Disclosure Vulnerabilities (2412048)
6936| [902625] Microsoft SharePoint Multiple Privilege Escalation Vulnerabilities (2451858)
6937| [902613] Microsoft Internet Explorer Multiple Vulnerabilities (2559049)
6938| [902609] Microsoft Windows CSRSS Privilege Escalation Vulnerabilities (2507938)
6939| [902598] Microsoft Windows Time Component Remote Code Execution Vulnerability (2618451)
6940| [902597] Microsoft Windows Media Remote Code Execution Vulnerability (2648048)
6941| [902596] Microsoft Windows OLE Remote Code Execution Vulnerability (2624667)
6942| [902588] Microsoft Windows Internet Protocol Validation Remote Code Execution Vulnerability
6943| [902581] Microsoft .NET Framework and Silverlight Remote Code Execution Vulnerability (2604930)
6944| [902580] Microsoft Host Integration Server Denial of Service Vulnerabilities (2607670)
6945| [902567] Microsoft Office Remote Code Execution Vulnerabilites (2587634)
6946| [902566] Microsoft Windows WINS Local Privilege Escalation Vulnerability (2571621)
6947| [902552] Microsoft .NET Framework Chart Control Information Disclosure Vulnerability (2567943)
6948| [902551] Microsoft .NET Framework Information Disclosure Vulnerability (2567951)
6949| [902523] Microsoft .NET Framework and Silverlight Remote Code Execution Vulnerability (2514842)
6950| [902522] Microsoft .NET Framework Remote Code Execution Vulnerability (2538814)
6951| [902518] Microsoft .NET Framework Security Bypass Vulnerability
6952| [902516] Microsoft Windows WINS Remote Code Execution Vulnerability (2524426)
6953| [902502] Microsoft .NET Framework Remote Code Execution Vulnerability (2484015)
6954| [902501] Microsoft JScript and VBScript Scripting Engines Remote Code Execution Vulnerability (2514666)
6955| [902496] Microsoft Office IME (Chinese) Privilege Elevation Vulnerability (2652016)
6956| [902495] Microsoft Office Remote Code Execution Vulnerability (2590602)
6957| [902494] Microsoft Office Excel Remote Code Execution Vulnerability (2640241)
6958| [902493] Microsoft Publisher Remote Code Execution Vulnerabilities (2607702)
6959| [902492] Microsoft Office PowerPoint Remote Code Execution Vulnerabilities (2639142)
6960| [902487] Microsoft Windows Active Directory LDAPS Authentication Bypass Vulnerability (2630837)
6961| [902484] Microsoft Windows TCP/IP Remote Code Execution Vulnerability (2588516)
6962| [902464] Microsoft Visio Remote Code Execution Vulnerabilities (2560978)
6963| [902463] Microsoft Windows Client/Server Run-time Subsystem Privilege Escalation Vulnerability (2567680)
6964| [902455] Microsoft Visio Remote Code Execution Vulnerability (2560847)
6965| [902445] Microsoft XML Editor Information Disclosure Vulnerability (2543893)
6966| [902443] Microsoft Internet Explorer Multiple Vulnerabilities (2530548)
6967| [902440] Microsoft Windows SMB Server Remote Code Execution Vulnerability (2536275)
6968| [902430] Microsoft Office PowerPoint Remote Code Execution Vulnerabilities (2545814)
6969| [902425] Microsoft Windows SMB Accessible Shares
6970| [902423] Microsoft Office Visio Viewer Remote Code Execution Vulnerabilities (2663510)
6971| [902411] Microsoft Office PowerPoint Remote Code Execution Vulnerabilities (2489283)
6972| [902410] Microsoft Office Excel Remote Code Execution Vulnerabilities (2489279)
6973| [902403] Microsoft Windows Fraudulent Digital Certificates Spoofing Vulnerability
6974| [902395] Microsoft Bluetooth Stack Remote Code Execution Vulnerability (2566220)
6975| [902378] Microsoft Office Excel Remote Code Execution Vulnerabilities (2537146)
6976| [902377] Microsoft Windows OLE Automation Remote Code Execution Vulnerability (2476490)
6977| [902365] Microsoft GDI+ Remote Code Execution Vulnerability (2489979)
6978| [902364] Microsoft Office Remote Code Execution Vulnerabilites (2489293)
6979| [902351] Microsoft Groove Remote Code Execution Vulnerability (2494047)
6980| [902337] Microsoft Windows Kernel Elevation of Privilege Vulnerability (2393802)
6981| [902336] Microsoft JScript and VBScript Scripting Engines Information Disclosure Vulnerability (2475792)
6982| [902325] Microsoft Internet Explorer 'CSS Import Rule' Use-after-free Vulnerability
6983| [902324] Microsoft SharePoint Could Allow Remote Code Execution Vulnerability (2455005)
6984| [902319] Microsoft Foundation Classes Could Allow Remote Code Execution Vulnerability (2387149)
6985| [902290] Microsoft Windows Active Directory SPN Denial of Service (2478953)
6986| [902289] Microsoft Windows LSASS Privilege Escalation Vulnerability (2478960)
6987| [902288] Microsoft Kerberos Privilege Escalation Vulnerabilities (2496930)
6988| [902287] Microsoft Visio Remote Code Execution Vulnerabilities (2451879)
6989| [902285] Microsoft Internet Explorer Information Disclosure Vulnerability (2501696)
6990| [902281] Microsoft Windows Data Access Components Remote Code Execution Vulnerabilities (2451910)
6991| [902280] Microsoft Windows BranchCache Remote Code Execution Vulnerability (2385678)
6992| [902277] Microsoft Windows Netlogon Service Denial of Service Vulnerability (2207559)
6993| [902276] Microsoft Windows Task Scheduler Elevation of Privilege Vulnerability (2305420)
6994| [902274] Microsoft Publisher Remote Code Execution Vulnerability (2292970)
6995| [902269] Microsoft Windows SMB Server NTLM Multiple Vulnerabilities (971468)
6996| [902265] Microsoft Office Word Remote Code Execution Vulnerabilities (2293194)
6997| [902264] Microsoft Office Excel Remote Code Execution Vulnerabilities (2293211)
6998| [902263] Microsoft Windows Media Player Network Sharing Remote Code Execution Vulnerability (2281679)
6999| [902262] Microsoft Windows Shell and WordPad COM Validation Vulnerability (2405882)
7000| [902256] Microsoft Windows win32k.sys Driver 'CreateDIBPalette()' BOF Vulnerability
7001| [902255] Microsoft Visual Studio Insecure Library Loading Vulnerability
7002| [902254] Microsoft Office Products Insecure Library Loading Vulnerability
7003| [902250] Microsoft Word 2003 'MSO.dll' Null Pointer Dereference Vulnerability
7004| [902246] Microsoft Internet Explorer 'toStaticHTML()' Cross Site Scripting Vulnerability
7005| [902243] Microsoft Outlook TNEF Remote Code Execution Vulnerability (2315011)
7006| [902232] Microsoft Windows TCP/IP Privilege Elevation Vulnerabilities (978886)
7007| [902231] Microsoft Windows Tracing Feature Privilege Elevation Vulnerabilities (982799)
7008| [902230] Microsoft .NET Common Language Runtime Remote Code Execution Vulnerability (2265906)
7009| [902229] Microsoft Window MPEG Layer-3 Remote Code Execution Vulnerability (2115168)
7010| [902228] Microsoft Office Word Remote Code Execution Vulnerabilities (2269638)
7011| [902227] Microsoft Windows LSASS Denial of Service Vulnerability (975467)
7012| [902226] Microsoft Windows Shell Remote Code Execution Vulnerability (2286198)
7013| [902217] Microsoft Outlook SMB Attachment Remote Code Execution Vulnerability (978212)
7014| [902210] Microsoft IE cross-domain IFRAME gadgets keystrokes steal Vulnerability
7015| [902193] Microsoft .NET Framework XML HMAC Truncation Vulnerability (981343)
7016| [902192] Microsoft Office COM Validation Remote Code Execution Vulnerability (983235)
7017| [902191] Microsoft Internet Explorer Multiple Vulnerabilities (982381)
7018| [902183] Microsoft Internet Explorer 'IFRAME' Denial Of Service Vulnerability
7019| [902178] Microsoft Visual Basic Remote Code Execution Vulnerability (978213)
7020| [902176] Microsoft SharePoint '_layouts/help.aspx' Cross Site Scripting Vulnerability
7021| [902166] Microsoft Internet Explorer 'neutering' Mechanism XSS Vulnerability
7022| [902159] Microsoft VBScript Scripting Engine Remote Code Execution Vulnerability (980232)
7023| [902158] Microsoft Office Publisher Remote Code Execution Vulnerability (981160)
7024| [902157] Microsoft 'ISATAP' Component Spoofing Vulnerability (978338)
7025| [902156] Microsoft SMB Client Remote Code Execution Vulnerabilities (980232)
7026| [902155] Microsoft Internet Explorer Multiple Vulnerabilities (980182)
7027| [902151] Microsoft Internet Explorer Denial of Service Vulnerability - Mar10
7028| [902133] Microsoft Office Excel Multiple Vulnerabilities (980150)
7029| [902117] Microsoft DirectShow Remote Code Execution Vulnerability (977935)
7030| [902116] Microsoft Client/Server Run-time Subsystem Privilege Elevation Vulnerability (978037)
7031| [902115] Microsoft Kerberos Denial of Service Vulnerability (977290)
7032| [902114] Microsoft Office PowerPoint Remote Code Execution Vulnerabilities (975416)
7033| [902112] Microsoft SMB Client Remote Code Execution Vulnerabilities (978251)
7034| [902095] Microsoft Office Excel Remote Code Execution Vulnerability (2269707)
7035| [902094] Microsoft Windows Kernel Mode Drivers Privilege Elevation Vulnerabilities (2160329)
7036| [902093] Microsoft Windows Kernel Privilege Elevation Vulnerabilities (981852)
7037| [902080] Microsoft Help and Support Center Remote Code Execution Vulnerability (2229593)
7038| [902069] Microsoft SharePoint Privilege Elevation Vulnerabilities (2028554)
7039| [902068] Microsoft Office Excel Remote Code Execution Vulnerabilities (2027452)
7040| [902067] Microsoft Windows Kernel Mode Drivers Privilege Escalation Vulnerabilities (979559)
7041| [902039] Microsoft Visio Remote Code Execution Vulnerabilities (980094)
7042| [902038] Microsoft MPEG Layer-3 Codecs Remote Code Execution Vulnerability (977816)
7043| [902033] Microsoft Windows '.ani' file Denial of Service vulnerability
7044| [902015] Microsoft Paint Remote Code Execution Vulnerability (978706)
7045| [901305] Microsoft Windows IP-HTTPS Component Security Feature Bypass Vulnerability (2765809)
7046| [901304] Microsoft Windows File Handling Component Remote Code Execution Vulnerability (2758857)
7047| [901301] Microsoft Windows Kerberos Denial of Service Vulnerability (2743555)
7048| [901212] Microsoft Windows DirectPlay Remote Code Execution Vulnerability (2770660)
7049| [901211] Microsoft Windows Common Controls Remote Code Execution Vulnerability (2720573)
7050| [901210] Microsoft Office Privilege Elevation Vulnerability - 2721015 (Mac OS X)
7051| [901209] Microsoft Windows Media Center Remote Code Execution Vulnerabilities (2604926)
7052| [901208] Microsoft Internet Explorer Multiple Vulnerabilities (2586448)
7053| [901205] Microsoft Windows Components Remote Code Execution Vulnerabilities (2570947)
7054| [901193] Microsoft Windows Media Remote Code Execution Vulnerabilities (2510030)
7055| [901183] Internet Information Services (IIS) FTP Service Remote Code Execution Vulnerability (2489256)
7056| [901180] Microsoft Internet Explorer Multiple Vulnerabilities (2482017)
7057| [901169] Microsoft Windows Address Book Remote Code Execution Vulnerability (2423089)
7058| [901166] Microsoft Office Remote Code Execution Vulnerabilites (2423930)
7059| [901164] Microsoft Windows SChannel Denial of Service Vulnerability (2207566)
7060| [901163] Microsoft Windows Media Player Remote Code Execution Vulnerability (2378111))
7061| [901162] Microsoft Internet Explorer Multiple Vulnerabilities (2360131)
7062| [901161] Microsoft ASP.NET Information Disclosure Vulnerability (2418042)
7063| [901151] Microsoft Internet Information Services Remote Code Execution Vulnerabilities (2267960)
7064| [901150] Microsoft Windows Print Spooler Service Remote Code Execution Vulnerability(2347290)
7065| [901140] Microsoft Windows SMB Code Execution and DoS Vulnerabilities (982214)
7066| [901139] Microsoft Internet Explorer Multiple Vulnerabilities (2183461)
7067| [901119] Microsoft Windows OpenType Compact Font Format Driver Privilege Escalation Vulnerability (980218)
7068| [901102] Microsoft Windows Media Services Remote Code Execution Vulnerability (980858)
7069| [901097] Microsoft Internet Explorer Multiple Vulnerabilities (978207)
7070| [901095] Microsoft Embedded OpenType Font Engine Remote Code Execution Vulnerabilities (972270)
7071| [901069] Microsoft Office Project Remote Code Execution Vulnerability (967183)
7072| [901065] Microsoft Windows IAS Remote Code Execution Vulnerability (974318)
7073| [901064] Microsoft Windows ADFS Remote Code Execution Vulnerability (971726)
7074| [901063] Microsoft Windows LSASS Denial of Service Vulnerability (975467)
7075| [901048] Microsoft Windows Active Directory Denial of Service Vulnerability (973309)
7076| [901041] Microsoft Internet Explorer Multiple Code Execution Vulnerabilities (974455)
7077| [901012] Microsoft Windows Media Format Remote Code Execution Vulnerability (973812)
7078| [900973] Microsoft Office Word Remote Code Execution Vulnerability (976307)
7079| [900965] Microsoft Windows SMB2 Negotiation Protocol Remote Code Execution Vulnerability
7080| [900964] Microsoft .NET Common Language Runtime Code Execution Vulnerability (974378)
7081| [900963] Microsoft Windows Kernel Privilege Escalation Vulnerability (971486)
7082| [900957] Microsoft Windows Patterns & Practices EntLib DOS Vulnerability
7083| [900956] Microsoft Windows Patterns & Practices EntLib Version Detection
7084| [900929] Microsoft JScript Scripting Engine Remote Code Execution Vulnerability (971961)
7085| [900908] Microsoft Windows Message Queuing Privilege Escalation Vulnerability (971032)
7086| [900907] Microsoft Windows AVI Media File Parsing Vulnerabilities (971557)
7087| [900898] Microsoft Internet Explorer 'XSS Filter' XSS Vulnerabilities - Nov09
7088| [900897] Microsoft Internet Explorer PDF Information Disclosure Vulnerability - Nov09
7089| [900891] Microsoft Internet Denial Of Service Vulnerability - Nov09
7090| [900887] Microsoft Office Excel Multiple Vulnerabilities (972652)
7091| [900886] Microsoft Windows Kernel-Mode Drivers Multiple Vulnerabilities (969947)
7092| [900881] Microsoft Windows Indexing Service ActiveX Vulnerability (969059)
7093| [900880] Microsoft Windows ATL COM Initialization Code Execution Vulnerability (973525)
7094| [900879] Microsoft Windows Media Player ASF Heap Overflow Vulnerability (974112)
7095| [900878] Microsoft Products GDI Plus Code Execution Vulnerabilities (957488)
7096| [900877] Microsoft Windows LSASS Denial of Service Vulnerability (975467)
7097| [900876] Microsoft Windows CryptoAPI X.509 Spoofing Vulnerabilities (974571)
7098| [900873] Microsoft Windows DNS Devolution Third-Level Domain Name Resolving Weakness (971888)
7099| [900863] Microsoft Internet Explorer 'window.print()' DOS Vulnerability
7100| [900838] Microsoft Windows TCP/IP Remote Code Execution Vulnerability (967723)
7101| [900837] Microsoft DHTML Editing Component ActiveX Remote Code Execution Vulnerability (956844)
7102| [900836] Microsoft Internet Explorer Address Bar Spoofing Vulnerability
7103| [900826] Microsoft Internet Explorer 'location.hash' DOS Vulnerability
7104| [900814] Microsoft Windows WINS Remote Code Execution Vulnerability (969883)
7105| [900813] Microsoft Remote Desktop Connection Remote Code Execution Vulnerability (969706)
7106| [900809] Microsoft Visual Studio ATL Remote Code Execution Vulnerability (969706)
7107| [900808] Microsoft Visual Products Version Detection
7108| [900757] Microsoft Windows Media Player '.AVI' File DOS Vulnerability
7109| [900741] Microsoft Internet Explorer Information Disclosure Vulnerability Feb10
7110| [900740] Microsoft Windows Kernel Could Allow Elevation of Privilege (977165)
7111| [900690] Microsoft Virtual PC/Server Privilege Escalation Vulnerability (969856)
7112| [900689] Microsoft Embedded OpenType Font Engine Remote Code Execution Vulnerabilities (961371))
7113| [900670] Microsoft Office Excel Remote Code Execution Vulnerabilities (969462)
7114| [900589] Microsoft ISA Server Privilege Escalation Vulnerability (970953)
7115| [900588] Microsoft DirectShow Remote Code Execution Vulnerability (961373)
7116| [900568] Microsoft Windows Search Script Execution Vulnerability (963093)
7117| [900566] Microsoft Active Directory LDAP Remote Code Execution Vulnerability (969805)
7118| [900476] Microsoft Excel Remote Code Execution Vulnerabilities (968557)
7119| [900465] Microsoft Windows DNS Memory Corruption Vulnerability - Mar09
7120| [900461] Microsoft MSN Live Messneger Denial of Service Vulnerability
7121| [900445] Microsoft Autorun Arbitrary Code Execution Vulnerability (08-038)
7122| [900404] Microsoft Windows RTCP Unspecified Remote DoS Vulnerability
7123| [900400] Microsoft Internet Explorer Unicode String DoS Vulnerability
7124| [900391] Microsoft Office Publisher Remote Code Execution Vulnerability (969516)
7125| [900366] Microsoft Internet Explorer Web Script Execution Vulnerabilites
7126| [900365] Microsoft Office Word Remote Code Execution Vulnerabilities (969514)
7127| [900337] Microsoft Internet Explorer Denial of Service Vulnerability - Apr09
7128| [900336] Microsoft Windows Media Player MID File Integer Overflow Vulnerability
7129| [900328] Microsoft Internet Explorer Remote Code Execution Vulnerability (963027)
7130| [900314] Microsoft XML Core Service Information Disclosure Vulnerability
7131| [900303] Microsoft Internet Explorer HTML Form Value DoS Vulnerability
7132| [900299] Microsoft Report Viewer Information Disclosure Vulnerability (2578230)
7133| [900297] Microsoft Windows Kernel Denial of Service Vulnerability (2556532)
7134| [900296] Microsoft Windows TCP/IP Stack Denial of Service Vulnerability (2563894)
7135| [900295] Microsoft Windows DNS Server Remote Code Execution Vulnerability (2562485)
7136| [900294] Microsoft Data Access Components Remote Code Execution Vulnerabilities (2560656)
7137| [900288] Microsoft Distributed File System Remote Code Execution Vulnerabilities (2535512)
7138| [900287] Microsoft SMB Client Remote Code Execution Vulnerabilities (2536276)
7139| [900285] Microsoft Foundation Class (MFC) Library Remote Code Execution Vulnerability (2500212)
7140| [900282] Microsoft DNS Resolution Remote Code Execution Vulnerability (2509553)
7141| [900281] Microsoft IE Developer Tools WMITools and Windows Messenger ActiveX Control Vulnerability (2508272)
7142| [900280] Microsoft Windows SMB Server Remote Code Execution Vulnerability (2508429)
7143| [900279] Microsoft SMB Client Remote Code Execution Vulnerabilities (2511455)
7144| [900278] Microsoft Internet Explorer Multiple Vulnerabilities (2497640)
7145| [900273] Microsoft Remote Desktop Client Remote Code Execution Vulnerability (2508062)
7146| [900267] Microsoft Media Decompression Remote Code Execution Vulnerability (2447961)
7147| [900266] Microsoft Windows Movie Maker Could Allow Remote Code Execution Vulnerability (2424434)
7148| [900263] Microsoft Windows OpenType Compact Font Format Driver Privilege Escalation Vulnerability (2296199)
7149| [900262] Microsoft Internet Explorer Multiple Vulnerabilities (2416400)
7150| [900261] Microsoft Office PowerPoint Remote Code Execution Vulnerabilities (2293386)
7151| [900248] Microsoft Windows Movie Maker Could Allow Remote Code Execution Vulnerability (981997)
7152| [900246] Microsoft Media Decompression Remote Code Execution Vulnerability (979902)
7153| [900245] Microsoft Data Analyzer and IE Developer Tools ActiveX Control Vulnerability (980195)
7154| [900241] Microsoft Outlook Express and Windows Mail Remote Code Execution Vulnerability (978542)
7155| [900240] Microsoft Exchange and Windows SMTP Service Denial of Service Vulnerability (981832)
7156| [900237] Microsoft Windows Authentication Verification Remote Code Execution Vulnerability (981210)
7157| [900236] Microsoft Windows Kernel Could Allow Elevation of Privilege (979683)
7158| [900235] Microsoft Windows Media Player Could Allow Remote Code Execution (979402)
7159| [900232] Microsoft Windows Movie Maker Could Allow Remote Code Execution Vulnerability (975561)
7160| [900230] Microsoft Windows SMB Server Multiple Vulnerabilities (971468)
7161| [900229] Microsoft Data Analyzer ActiveX Control Vulnerability (978262)
7162| [900228] Microsoft Office (MSO) Remote Code Execution Vulnerability (978214)
7163| [900227] Microsoft Windows Shell Handler Could Allow Remote Code Execution Vulnerability (975713)
7164| [900223] Microsoft Ancillary Function Driver Elevation of Privilege Vulnerability (956803)
7165| [900192] Microsoft Internet Explorer Information Disclosure Vulnerability
7166| [900187] Microsoft Internet Explorer Argument Injection Vulnerability
7167| [900178] Microsoft Windows 'UnhookWindowsHookEx' Local DoS Vulnerability
7168| [900173] Microsoft Windows Media Player Version Detection
7169| [900172] Microsoft Windows Media Player 'MIDI' or 'DAT' File DoS Vulnerability
7170| [900170] Microsoft iExplorer '&NBSP
7171| [900131] Microsoft Internet Explorer Denial of Service Vulnerability
7172| [900125] Microsoft SQL Server 2000 sqlvdir.dll ActiveX Buffer Overflow Vulnerability
7173| [900120] Microsoft Organization Chart Remote Code Execution Vulnerability
7174| [900108] Microsoft Windows NSlookup.exe Remote Code Execution Vulnerability
7175| [900097] Vulnerability in Microsoft DirectShow Could Allow Remote Code Execution
7176| [900095] Microsoft ISA Server and Forefront Threat Management Gateway DoS Vulnerability (961759)
7177| [900093] Microsoft DirectShow Remote Code Execution Vulnerability (961373)
7178| [900080] Vulnerabilities in Microsoft Office Visio Could Allow Remote Code Execution (957634)
7179| [900079] Vulnerabilities in Microsoft Exchange Could Allow Remote Code Execution (959239)
7180| [900064] Vulnerability in Microsoft Office SharePoint Server Could Cause Elevation of Privilege (957175)
7181| [900063] Vulnerabilities in Microsoft Office Word Could Allow Remote Code Execution (957173)
7182| [900061] Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (959070)
7183| [900058] Microsoft XML Core Services Remote Code Execution Vulnerability (955218)
7184| [900048] Microsoft Excel Remote Code Execution Vulnerability (956416)
7185| [900047] Microsoft Office nformation Disclosure Vulnerability (957699)
7186| [900046] Microsoft Office Remote Code Execution Vulnerabilities (955047)
7187| [900033] Microsoft PowerPoint Could Allow Remote Code Execution Vulnerabilities (949785)
7188| [900029] Microsoft Office Filters Could Allow Remote Code Execution Vulnerabilities (924090)
7189| [900028] Microsoft Excel Could Allow Remote Code Execution Vulnerabilities (954066)
7190| [900025] Microsoft Office Version Detection
7191| [900006] Microsoft Word Could Allow Remote Code Execution Vulnerability
7192| [900004] Microsoft Access Snapshot Viewer ActiveX Control Vulnerability
7193| [855384] Solaris Update for snmp/mibiisa 108870-36
7194| [855273] Solaris Update for snmp/mibiisa 108869-36
7195| [803028] Microsoft Internet Explorer Remote Code Execution Vulnerability (2757760)
7196| [803007] Microsoft Windows Minimum Certificate Key Length Spoofing Vulnerability (2661254)
7197| [802912] Microsoft Unauthorized Digital Certificates Spoofing Vulnerability (2728973)
7198| [802888] Microsoft Windows Media Service Handshake Sequence DoS Vulnerability
7199| [802886] Microsoft Sidebar and Gadgets Remote Code Execution Vulnerability (2719662)
7200| [802864] Microsoft XML Core Services Remote Code Execution Vulnerability (2719615)
7201| [802774] Microsoft VPN ActiveX Control Remote Code Execution Vulnerability (2695962)
7202| [802726] Microsoft SMB Signing Disabled
7203| [802708] Microsoft Internet Explorer Code Execution and DoS Vulnerabilities
7204| [802634] Microsoft Windows Unauthorized Digital Certificates Spoofing Vulnerability (2718704)
7205| [802500] Microsoft Windows TrueType Font Parsing Privilege Elevation Vulnerability
7206| [802468] Compatibility Issues Affecting Signed Microsoft Binaries (2749655)
7207| [802462] Microsoft ActiveSync Null Pointer Dereference Denial Of Service Vulnerability
7208| [802426] Microsoft Windows ActiveX Control Multiple Vulnerabilities (2647518)
7209| [802383] Microsoft Windows Color Control Panel Privilege Escalation Vulnerability
7210| [802379] Microsoft Windows Kernel 'win32k.sys' Memory Corruption Vulnerability
7211| [802287] Microsoft Internet Explorer Cache Objects History Information Disclosure Vulnerability
7212| [802286] Microsoft Internet Explorer Multiple Information Disclosure Vulnerabilities
7213| [802260] Microsoft Windows WINS Remote Code Execution Vulnerability (2524426)
7214| [802203] Microsoft Internet Explorer Cookie Hijacking Vulnerability
7215| [802202] Microsoft Internet Explorer Cookie Hijacking Vulnerability
7216| [802140] Microsoft Explorer HTTPS Sessions Multiple Vulnerabilities (Windows)
7217| [802136] Microsoft Windows Insecure Library Loading Vulnerability (2269637)
7218| [801991] Microsoft Windows SMB/NETBIOS NULL Session Authentication Bypass Vulnerability
7219| [801966] Microsoft Windows ActiveX Control Multiple Vulnerabilities (2562937)
7220| [801935] Microsoft Silverlight Multiple Memory Leak Vulnerabilities
7221| [801934] Microsoft Silverlight Version Detection
7222| [801914] Microsoft Windows IPv4 Default Configuration Security Bypass Vulnerability
7223| [801876] Microsoft Internet Explorer 'msxml.dll' Information Disclosure Vulnerability
7224| [801831] Microsoft Internet Explorer Incorrect GUI Display Vulnerability
7225| [801830] Microsoft Internet Explorer 'ReleaseInterface()' Remote Code Execution Vulnerability
7226| [801725] Microsoft Products GDI Plus Remote Code Execution Vulnerabilities (954593)
7227| [801721] Microsoft Active Directory Denial of Service Vulnerability (953235)
7228| [801719] Microsoft Windows CSRSS CSRFinalizeContext Local Privilege Escalation Vulnerability (930178)
7229| [801718] Microsoft Windows Vista Information Disclosure Vulnerability (931213)
7230| [801717] Microsoft Windows Vista Teredo Interface Firewall Bypass Vulnerability
7231| [801716] Microsoft Outlook Express/Windows Mail MHTML URI Handler Information Disclosure Vulnerability (929123)
7232| [801715] Microsoft XML Core Services Remote Code Execution Vulnerability (936227)
7233| [801713] Microsoft Outlook Express And Windows Mail NNTP Protocol Heap Buffer Overflow Vulnerability (941202)
7234| [801707] Microsoft Internet Explorer mshtml.dll Remote Memory Corruption Vulnerability (942615)
7235| [801706] Microsoft Windows TCP/IP Remote Code Execution Vulnerabilities (941644)
7236| [801705] Microsoft Windows TCP/IP Denial of Service Vulnerability (946456)
7237| [801704] Microsoft Internet Information Services Privilege Elevation Vulnerability (942831)
7238| [801702] Microsoft Internet Explorer HTML Rendering Remote Memory Corruption Vulnerability (944533)
7239| [801701] Microsoft Windows DNS Client Service Response Spoofing Vulnerability (945553)
7240| [801677] Microsoft WMI Administrative Tools ActiveX Control Remote Code Execution Vulnerabilities
7241| [801606] Microsoft Internet Explorer 'mshtml.dll' Information Disclosure Vulnerability
7242| [801598] Microsoft Windows2k3 Active Directory 'BROWSER ELECTION' Buffer Overflow Vulnerability
7243| [801597] Microsoft Office Excel 2003 Invalid Object Type Remote Code Execution Vulnerability
7244| [801596] Microsoft Excel 2007 Office Drawing Layer Remote Code Execution Vulnerability
7245| [801595] Microsoft Office Excel Axis and Art Object Parsing Remote Code Execution Vulnerabilities
7246| [801594] Microsoft PowerPoint 2007 OfficeArt Atom Remote Code Execution Vulnerability
7247| [801580] Microsoft Windows Fax Cover Page Editor BOF Vulnerabilities
7248| [801527] Microsoft Windows 32-bit Platforms Unspecified vulnerabilities
7249| [801491] Microsoft 'hxvz.dll' ActiveX Control Memory Corruption Vulnerability (948881)
7250| [801489] Microsoft Office Graphics Filters Remote Code Execution Vulnerabilities (968095)
7251| [801488] Microsoft Internet Explorer Data Stream Handling Remote Code Execution Vulnerability (947864)
7252| [801487] Microsoft Windows Kernel Usermode Callback Local Privilege Elevation Vulnerability (941693)
7253| [801486] Microsoft Windows Speech Components Voice Recognition Command Execution Vulnerability (950760)
7254| [801485] Microsoft Pragmatic General Multicast (PGM) Denial of Service Vulnerability (950762)
7255| [801484] Microsoft Windows IPsec Policy Processing Information Disclosure Vulnerability (953733)
7256| [801483] Microsoft Windows Search Remote Code Execution Vulnerability (959349)
7257| [801482] Microsoft Windows ASP.NET Denial of Service Vulnerability(970957)
7258| [801481] Microsoft Wireless LAN AutoConfig Service Remote Code Execution Vulnerability (970710)
7259| [801480] Microsoft Web Services on Devices API Remote Code Execution Vulnerability (973565)
7260| [801479] Microsoft Windows TCP/IP Could Allow Remote Code Execution (974145)
7261| [801457] Microsoft Windows Address Book Insecure Library Loading Vulnerability
7262| [801456] Microsoft Windows Progman Group Converter Insecure Library Loading Vulnerability
7263| [801349] Microsoft Internet Explorer 'IFRAME' Denial Of Service Vulnerability (June-10)
7264| [801348] Microsoft Internet Explorer 'IFRAME' Denial Of Service Vulnerability -june 10
7265| [801345] Microsoft .NET 'ASP.NET' Cross-Site Scripting vulnerability
7266| [801344] Microsoft .NET '__VIEWSTATE' Cross-Site Scripting vulnerability
7267| [801342] Microsoft ASP.NET Cross-Site Scripting vulnerability
7268| [801333] Microsoft Windows Kernel 'win32k.sys' Multiple DOS Vulnerabilities
7269| [801330] Microsoft Internet Explorer Cross Site Data Leakage Vulnerability
7270| [801109] Microsoft IE CA SSL Certificate Security Bypass Vulnerability - Oct09
7271| [801090] Microsoft Windows Indeo Codec Multiple Vulnerabilities
7272| [800968] Microsoft SharePoint Team Services Information Disclosure Vulnerability
7273| [800910] Microsoft Internet Explorer Buffer Overflow Vulnerability - Jul09
7274| [800902] Microsoft Internet Explorer XSS Vulnerability - July09
7275| [800872] Microsoft Internet Explorer 'li' Element DoS Vulnerability - Sep09
7276| [800863] Microsoft Internet Explorer XML Document DoS Vulnerability - Aug09
7277| [800862] Microsoft Windows Kernel win32k.sys Privilege Escalation Vulnerability
7278| [800861] Microsoft Internet Explorer 'findText()' Unicode Parsing DoS Vulnerability
7279| [800845] Microsoft Office Web Components ActiveX Control Code Execution Vulnerability
7280| [800829] Microsoft Video ActiveX Control 'msvidctl.dll' BOF Vulnerability
7281| [800742] Microsoft Internet Explorer Unspecified vulnerability
7282| [800700] Microsoft GDIPlus PNG Infinite Loop Vulnerability
7283| [800687] Microsoft Windows Server 2003 OpenType Font Engine DoS Vulnerability
7284| [800669] Microsoft Internet Explorer Denial Of Service Vulnerability - July09
7285| [800577] Microsoft Windows Server 2003 win32k.sys DoS Vulnerability
7286| [800505] Microsoft HTML Help Workshop buffer overflow vulnerability
7287| [800504] Microsoft Windows XP SP3 denial of service vulnerability
7288| [800481] Microsoft SharePoint Cross Site Scripting Vulnerability
7289| [800480] Microsoft Windows Media Player '.mpg' Buffer Overflow Vulnerability
7290| [800466] Microsoft Windows TLS/SSL Spoofing Vulnerability (977377)
7291| [800461] Microsoft Internet Explorer Information Disclosure Vulnerability (980088)
7292| [800442] Microsoft Windows GP Trap Handler Privilege Escalation Vulnerability
7293| [800429] Microsoft Internet Explorer Remote Code Execution Vulnerability (979352)
7294| [800382] Microsoft PowerPoint File Parsing Remote Code Execution Vulnerability (967340)
7295| [800347] Microsoft Internet Explorer Clickjacking Vulnerability
7296| [800343] Microsoft Word 2007 Sensitive Information Disclosure Vulnerability
7297| [800337] Microsoft Internet Explorer NULL Pointer DoS Vulnerability
7298| [800332] Microsoft Windows Live Messenger Information Disclosure Vulnerability
7299| [800331] Microsoft Windows Live Messenger Client Version Detection
7300| [800328] Integer Overflow vulnerability in Microsoft Windows Media Player
7301| [800310] Microsoft Windows Media Services nskey.dll ActiveX BOF Vulnerability
7302| [800267] Microsoft GDIPlus Library File Integer Overflow Vulnerability
7303| [800218] Microsoft Money 'prtstb06.dll' Denial of Service vulnerability
7304| [800217] Microsoft Money Version Detection
7305| [800209] Microsoft Internet Explorer Version Detection (Win)
7306| [800208] Microsoft Internet Explorer Anti-XSS Filter Vulnerabilities
7307| [800083] Microsoft Outlook Express Malformed MIME Message DoS Vulnerability
7308| [800082] Microsoft SQL Server sp_replwritetovarbin() BOF Vulnerability
7309| [800023] Microsoft Windows Image Color Management System Code Execution Vulnerability (952954)
7310| [103254] Microsoft SharePoint Server 2007 '_layouts/help.aspx' Cross Site Scripting Vulnerability
7311| [102059] Microsoft Windows Vector Markup Language Buffer Overflow (938127)
7312| [102055] Microsoft Windows GDI Multiple Vulnerabilities (925902)
7313| [102053] Microsoft Windows Vector Markup Language Vulnerabilities (929969)
7314| [102015] Microsoft RPC Interface Buffer Overrun (KB824146)
7315| [101100] Vulnerabilities in Microsoft ATL Could Allow Remote Code Execution (973908)
7316| [101017] Microsoft MS03-018 security check
7317| [101016] Microsoft MS03-022 security check
7318| [101015] Microsoft MS03-034 security check
7319| [101014] Microsoft MS00-078 security check
7320| [101012] Microsoft MS03-051 security check
7321| [101010] Microsoft Security Bulletin MS05-004
7322| [101009] Microsoft Security Bulletin MS06-033
7323| [101007] Microsoft dotNET version grabber
7324| [101006] Microsoft Security Bulletin MS06-056
7325| [101005] Microsoft Security Bulletin MS07-040
7326| [101004] Microsoft MS04-017 security check
7327| [101003] Microsoft MS00-058 security check
7328| [101000] Microsoft MS00-060 security check
7329| [100950] Microsoft DNS server internal hostname disclosure detection
7330| [100624] Microsoft Windows SMTP Server DNS spoofing vulnerability
7331| [100607] Microsoft SMTP Service and Exchange Routing Engine Buffer Overflow Vulnerability
7332| [100596] Microsoft Windows SMTP Server MX Record Denial of Service Vulnerability
7333| [100283] Microsoft Windows SMB2 '_Smb2ValidateProviderCallback()' Remote Code Execution Vulnerability
7334| [100062] Microsoft Remote Desktop Protocol Detection
7335| [90024] Windows Vulnerability in Microsoft Jet Database Engine
7336| [80007] Microsoft MS00-06 security check
7337| [13752] Denial of Service (DoS) in Microsoft SMS Client
7338| [11992] Vulnerability in Microsoft ISA Server 2000 H.323 Filter(816458)
7339| [11874] IIS Service Pack - 404
7340| [11808] Microsoft RPC Interface Buffer Overrun (823980)
7341| [11433] Microsoft ISA Server DNS - Denial Of Service (MS03-009)
7342| [11217] Microsoft's SQL Version Query
7343| [11177] Flaw in Microsoft VM Could Allow Code Execution (810030)
7344| [11146] Microsoft RDP flaws could allow sniffing and DOS(Q324380)
7345| [11142] IIS XSS via IDC error
7346| [11067] Microsoft's SQL Hello Overflow
7347| [11003] IIS Possible Compromise
7348| [10993] IIS ASP.NET Application Trace Enabled
7349| [10991] IIS Global.asa Retrieval
7350| [10936] IIS XSS via 404 error
7351| [10862] Microsoft's SQL Server Brute Force
7352| [10755] Microsoft Exchange Public Folders Information Leak
7353| [10732] IIS 5.0 WebDav Memory Leakage
7354| [10699] IIS FrontPage DoS II
7355| [10695] IIS .IDA ISAPI filter applied
7356| [10674] Microsoft's SQL UDP Info Query
7357| [10673] Microsoft's SQL Blank Password
7358| [10671] IIS Remote Command Execution
7359| [10667] IIS 5.0 PROPFIND Vulnerability
7360| [10661] IIS 5 .printer ISAPI filter applied
7361| [10657] NT IIS 5.0 Malformed HTTP Printer Request Header Buffer Overflow Vulnerability
7362| [10585] IIS FrontPage DoS
7363| [10576] Check for dangerous IIS default files
7364| [10575] Check for IIS .cnf file leakage
7365| [10573] IIS 5.0 Sample App reveals physical path of web root
7366| [10572] IIS 5.0 Sample App vulnerable to cross-site scripting attack
7367| [10537] IIS directory traversal
7368| [10492] IIS IDA/IDQ Path Disclosure
7369| [10491] ASP/ASA source using Microsoft Translate f: bug
7370| [10144] Microsoft SQL TCP/IP listener is running
7371|
7372| SecurityTracker - https://www.securitytracker.com:
7373| [1024070] Microsoft Internet Explorer 8 Developer Tools ActiveX Control Memory Corruption Error Lets Remote Users Execute Arbitrary Code
7374| [1027751] Microsoft Internet Information Server (IIS) FTP Server Lets Remote Users Obtain Files and Local Users Obtain Passwords
7375| [1027223] Microsoft IIS Web Server Discloses Potentially Sensitive Information to Remote Users
7376| [1024921] Microsoft IIS FTP Server Lets Remote Users Deny Service
7377| [1024496] Microsoft Internet Information Server (IIS) Web Server Stack Overflow in Reading POST Data Lets Remote Users Deny Service
7378| [1023387] Microsoft Internet Information Services (IIS) Filename Extension Parsing Configuration Error May Let Users Bypass Security Controls
7379| [1022792] Microsoft Internet Information Server (IIS) FTP Server Buffer Overflows Let Remote Authenticated Users Execute Arbitrary Code and Deny Service
7380| [1016466] Microsoft Internet Information Server (IIS) Buffer Overflow in Processing ASP Pages Lets Remote Authenticated Users Execute Arbitrary Code
7381| [1015376] Microsoft IIS Lets Remote Users Deny Service or Execute Arbitrary Code With Malformed HTTP GET Requests
7382| [1015049] Microsoft Internet Explorer Drag-and-Drop Timing May Let Remote Users Install Arbitrary Files
7383| [1014777] Microsoft IIS ASP Error Page May Disclose System Information in Certain Cases
7384| [1011633] Microsoft IIS WebDAV XML Message Handler Error Lets Remote Users Deny Service
7385| [1010692] Microsoft IIS 4.0 Buffer Overflow in Redirect Function Lets Remote Users Execute Arbitrary Code
7386| [1010610] Microsoft IIS Web Server May Disclose Private IP Addresses in Certain Cases
7387| [1010079] Microsoft IIS ASP Script Cookie Processing Flaw May Disclose Application Information to Remote Users
7388| [1008563] Microsoft IIS Fails to Log HTTP TRACK Requests
7389| [1007262] Microsoft IIS 6.0 Vulnerabilities Permit Cross-Site Scripting and Password Changing Attacks Against Administrators
7390| [1007059] Microsoft Windows Media Services (nsiislog.dll) Extension to Internet Information Server (IIS) Has Another Buffer Overflow That Lets Remote Execute Arbitrary Code
7391| [1006867] Microsoft IIS Buffer Overflow Lets Remote Users With Upload Privileges Execute Code - Remote Users Can Also Crash the Service
7392| [1006866] Microsoft Windows Media Services (nsiislog.dll) Extension to Internet Information Server (IIS) Lets Remote Execute Arbitrary Code
7393| [1006704] Microsoft IIS Authentication Manager Discloses Validity of User Names to Remote Users
7394| [1006305] Microsoft IIS Web Server WebDAV Buffer Overflow Lets Remote Users Execute Arbitrary Code
7395| [1005505] Microsoft Internet Information Server (IIS) Script Access Control Bug May Let Remote Authenticated Users Upload Unauthorized Executable Files
7396| [1005504] Microsoft Internet Information Server (IIS) WebDAV Memory Allocation Flaw Lets Remote Users Crash the Server
7397| [1005503] Microsoft Internet Information Server (IIS) Administrative Pages Allow Cross-Site Scripting Attacks
7398| [1005502] Microsoft Internet Information Server (IIS) Out-of-Process Access Control Bug Lets Certain Authenticated Users Gain Full Control of the Server
7399| [1005083] Microsoft Internet Information Server (IIS) Web Server Fails to Properly Validate Client-side Certificates, Allowing Remote Users to Impersonate Other Users or Certificate Issuers
7400| [1004757] Microsoft IIS SMTP Service Encapsulation Bug Lets Remote Users Relay Mail and Send SPAM Via the Service
7401| [1004646] ColdFusion MX Buffer Overflow When Used With Microsoft Internet Information Server (IIS) Lets Remote Users Crash the IIS Web Server or Execute Arbitrary Code
7402| [1004526] Microsoft Internet Information Server (IIS) Heap Overflow in HTR ISAPI Extension While Processing Chunked Encoded Data Lets Remote Users Execute Arbitrary Code
7403| [1004044] Cisco CallManager Affected by Microsoft Internet Information Server (IIS) Bugs
7404| [1004032] Microsoft Internet Information Server (IIS) FTP STAT Command Bug Lets Remote Users Crash Both the FTP and the Web Services
7405| [1004031] Microsoft Internet Information Server (IIS) URL Length Bug Lets Remote Users Crash the Web Service
7406| [1004011] Microsoft Internet Information Server (IIS) Buffer Overflow in ASP Server-Side Include Function May Let Remote Users Execute Arbitrary Code on the Web Server
7407| [1004006] Microsoft Internet Information Server (IIS) Off-By-One Heap Overflow in .HTR Processing May Let Remote Users Execute Arbitrary Code on the Server
7408| [1003224] Microsoft Internet Information Server (IIS) Version 4 Lets Local Users Modify the Log File Undetected
7409| [1002778] Microsoft Internet Information Server (IIS) Lets Remote Users Create Bogus Web Log Entries
7410| [1002733] Microsoft IIS 4.0 Configuration Error May Allow Remote Users to Obtain Physical Directory Path Information
7411| [1002651] Microsoft Internet Information Server (IIS) May Disclose PHP Scripting Source Code
7412| [1002212] Microsoft IIS Web Server Contains Multiple Vulnerabilities That Allow Local Users to Gain System Privileges and Allow Remote Users to Cause the Web Server to Crash
7413| [1002161] Microsoft Internet Information Server (IIS) Web Server Discloses Internal IP Addresses or NetBIOS Host Names to Remote Users
7414| [1001818] Microsoft Internet Information Server (IIS) Web Server Discloses ASP Source Code When Installed on FAT-based Filesystem
7415| [1001576] eEye Digital Security's SecureIIS Application Firewall for Microsoft Web Servers Fails to Filter Certain Web URL Characters, Allowing Remote Users to Bypass the SecureIIS Firewall
7416| [1001565] Microsoft IIS Web Server on Windows 2000 Allows Remote Users to Cause the Server to Consume All Available Memory Due to Memory Leak in WebDAV Lock Method
7417| [1001530] Microsoft IIS Web Server Allows Remote Users to Execute Commands on the Server Due to CGI Decoding Error
7418| [1001483] Microsoft IIS Web Server Lets Remote Users Restart the Web Server with Another Specially Crafted PROPFIND XML Command
7419| [1001464] Microsoft Internet Information Server IIS 5.0 for Windows 2000 Lets Remote Users Execute Arbitrary Code on the Server and Gain Control of the Server
7420| [1001402] Microsoft IIS Web Server Can Be Effectively Shutdown By Certain Internal-Network Attacks When The Underlying OS Supports User Account Lockouts
7421| [1001116] Microsoft Personal Web Server Contains An Old Internet Information Server (IIS) Vulnerability Allowing Unauthorized Directory Listings and Possible Code Execution For Remote Users
7422| [1001050] Microsoft IIS 5.0 Web Server Can Be Restarted Remotely By Any User
7423|
7424| OSVDB - http://www.osvdb.org:
7425| [91269] Microsoft Windows 8 TrueType Font (TTF) Handling Unspecified DoS
7426| [65218] Microsoft IE 8 Developer Tools ActiveX Remote Code Execution
7427| [87555] Adobe ColdFusion for Microsoft IIS Unspecified DoS
7428| [87262] Microsoft IIS FTP Command Injection Information Disclosure
7429| [87261] Microsoft IIS Log File Permission Weakness Local Password Disclosure
7430| [86899] Microsoft IIS 302 Redirect Message Internal IP Address Remote Disclosure
7431| [83771] Microsoft IIS Tilde Character Request Parsing File / Folder Name Information Disclosure
7432| [83454] Microsoft IIS ODBC Tool ctguestb.idc Unauthenticated Remote DSN Initialization
7433| [83386] Microsoft IIS Non-existent IDC File Request Web Root Path Disclosure
7434| [82848] Microsoft IIS $INDEX_ALLOCATION Data Stream Request Authentication Bypass
7435| [76237] Microsoft Forefront Unified Access Gateway IIS NULL Session Cookie Parsing Remote DoS
7436| [71856] Microsoft IIS Status Header Handling Remote Overflow
7437| [70167] Microsoft IIS FTP Server Telnet IAC Character Handling Overflow
7438| [67980] Microsoft IIS Unspecified Remote Directory Authentication Bypass
7439| [67979] Microsoft IIS FastCGI Request Header Handling Remote Overflow
7440| [67978] Microsoft IIS Repeated Parameter Request Unspecified Remote DoS
7441| [66160] Microsoft IIS Basic Authentication NTFS Stream Name Permissions Bypass
7442| [65216] Microsoft IIS Extended Protection for Authentication Memory Corruption
7443| [62229] Microsoft IIS Crafted DNS Response Inverse Lookup Log Corruption XSS
7444| [61432] Microsoft IIS Colon Safe Extension NTFS ADS Filename Syntax Arbitrary Remote File Creation
7445| [61294] Microsoft IIS ASP Crafted semicolon Extension Security Bypass
7446| [61249] Microsoft IIS ctss.idc table Parameter SQL Injection
7447| [59892] Microsoft IIS Malformed Host Header Remote DoS
7448| [59621] Microsoft IIS CodeBrws.asp Off-By-One File Check Bypass Source Disclosure
7449| [59561] Microsoft IIS CodeBrws.asp Encoded Traversal Arbitrary File Source Disclosure
7450| [59360] Microsoft IIS ASP Page Visual Basic Script Malformed Regex Parsing DoS
7451| [57753] Microsoft IIS FTP Server Crafted Recursive Listing Remote DoS
7452| [57589] Microsoft IIS FTP Server NLST Command Remote Overflow
7453| [56474] Microsoft IIS WebDAV Extension URL Decode Crafted HTTP Request Authentication Bypass
7454| [55269] Microsoft IIS Traversal GET Request Remote DoS
7455| [54555] Microsoft IIS WebDAV Unicode URI Request Authentication Bypass
7456| [52924] Microsoft IIS WebDAV PROPFIND Method Forced Directory Listing
7457| [52680] Microsoft IIS httpext.dll WebDav LOCK Method Nonexistent File Request Parsing Memory Exhaustion Remote DoS
7458| [52238] Microsoft IIS IDC Extension XSS
7459| [49899] Microsoft IIS iissext.dll Unspecified ActiveX SetPassword Method Remote Password Manipulation
7460| [49730] Microsoft IIS ActiveX (adsiis.dll) GetObject Method Remote DoS
7461| [49059] Microsoft IIS IPP Service Unspecified Remote Overflow
7462| [45583] Microsoft IIS w/ Visual Interdev Unspecified Authentication Bypass
7463| [43451] Microsoft IIS HTTP Request Smuggling
7464| [41456] Microsoft IIS File Change Handling Local Privilege Escalation
7465| [41445] Microsoft IIS ASP Web Page Input Unspecified Arbitrary Code Execution
7466| [41091] Microsoft IIS webhits.dll Hit-Highlighting Authentication Bypass
7467| [41063] Microsoft IIS ODBC Tool newdsn.exe Remote DSN Creation
7468| [41057] Microsoft IIS w/ .NET MS-DOS Device Request Blacklist Bypass
7469| [35950] Microsoft IIS IUSR_Machine Account Arbitrary Non-EXE Command Execution
7470| [33457] Microsoft IIS Crafted TCP Connection Range Header DoS
7471| [28260] Microsoft IIS FrontPage Server Extensions (FPSE) shtml.exe Path Disclosure
7472| [27152] Microsoft Windows IIS ASP Page Processing Overflow
7473| [27087] Microsoft IIS SMTP Encapsulated SMTP Address Open Relay
7474| [23590] Microsoft IIS Traversal Arbitrary FPSE File Access
7475| [21805] Microsoft IIS Crafted URL Remote DoS
7476| [21537] Microsoft IIS Log File Permission Weakness Remote Modification
7477| [18926] Microsoft IIS SERVER_NAME Variable Spoofing Filter Bypass
7478| [17124] Microsoft IIS Malformed WebDAV Request DoS
7479| [17123] Microsoft IIS Multiple Unspecified Admin Pages XSS
7480| [17122] Microsoft IIS Permission Weakness .COM File Upload
7481| [15749] Microsoft IIS / Site Server code.asp Arbitrary File Access
7482| [15342] Microsoft IIS Persistent FTP Banner Information Disclosure
7483| [14229] Microsoft IIS asp.dll Scripting.FileSystemObject Malformed Program DoS
7484| [13985] Microsoft IIS Malformed HTTP Request Log Entry Spoofing
7485| [13760] Microsoft IIS Malformed URL Request DoS
7486| [13759] Microsoft IIS ISAPI .ASP Parser Script Tag LANGUAGE Argument Overflow
7487| [13634] Microsoft IIS Inetinfo.exe Malformed Long Mail File Name DoS
7488| [13558] Microsoft IIS SSL Request Resource Exhaustion DoS
7489| [13507] Microsoft IIS showfile.asp FileSystemObject Arbitrary File Access
7490| [13479] Microsoft IIS for Far East Parsed Page Source Disclosure
7491| [13473] Microsoft IIS on FAT Partition Local ASP Source Disclosure
7492| [13439] Microsoft IIS HTTP Request Malformed Content-Length Parsing Remote DoS
7493| [13433] Microsoft IIS WebDAV MKCOL Method Location Server Header Internal IP Disclosure
7494| [13432] Microsoft IIS WebDAV WRITE Location Server Header Internal IP Disclosure
7495| [13431] Microsoft IIS WebDAV Malformed PROPFIND Request Internal IP Disclosure
7496| [13430] Microsoft IIS aexp4.htr Password Policy Bypass
7497| [13429] Microsoft IIS aexp3.htr Password Policy Bypass
7498| [13428] Microsoft IIS aexp2b.htr Password Policy Bypass
7499| [13427] Microsoft IIS aexp2.htr Password Policy Bypass
7500| [13426] Microsoft IIS NTLM Authentication Request Parsing Remote Information Disclosure
7501| [13385] Microsoft IIS WebDAV Long PROPFIND/SEARCH Request DoS
7502| [11455] Microsoft IIS / PWS DOS Filename Request Access Bypass
7503| [11452] Microsoft IIS Double Byte Code Arbitrary Source Disclosure
7504| [11277] Microsoft IIS SSL ISAPI Filter Cleartext Information Disclosure
7505| [11257] Microsoft IIS Malformed GET Request DoS
7506| [11157] Microsoft IIS FTP Service PASV Connection Saturation DoS
7507| [11101] Microsoft IIS Multiple Slash ASP Page Request DoS
7508| [9315] Microsoft IIS getdrvs.exe ODBC Sample Information Disclosure
7509| [9314] Microsoft IIS mkilog.exe ODBC Sample Arbitrary Command Execution
7510| [9200] Microsoft IIS Unspecified XSS Variant
7511| [9199] Microsoft IIS shtml.dll XSS
7512| [8098] Microsoft IIS Virtual Directory ASP Source Disclosure
7513| [7807] Microsoft IIS ISAPI Virtual Directory UNC Mapping ASP Source Disclosure
7514| [7737] Microsoft IIS ASP Redirection Function XSS
7515| [7265] Microsoft IIS .ASP Session ID Disclosure and Hijacking
7516| [5851] Microsoft IIS Single Dot Source Code Disclosure
7517| [5736] Microsoft IIS Relative Path System Privilege Escalation
7518| [5693] Microsoft MS00-060 Patch IIS Malformed Request DoS
7519| [5633] Microsoft IIS Invalid WebDAV Request DoS
7520| [5606] Microsoft IIS WebDAV PROPFIND Request DoS
7521| [5584] Microsoft IIS URL Redirection Malformed Length DoS
7522| [5566] Microsoft IIS Form_VBScript.asp XSS
7523| [5316] Microsoft IIS ISAPI HTR Chunked Encoding Overflow
7524| [4864] Microsoft IIS TRACK Logging Failure
7525| [4863] Microsoft IIS Active Server Page Header DoS
7526| [4791] Microsoft IIS Response Object DoS
7527| [4655] Microsoft IIS ssinc.dll Long Filename Overflow
7528| [4535] Microsoft Media Services ISAPI nsiislog.dll POST Overflow
7529| [3512] Microsoft IIS ODBC Tool getdrvrs.exe Remote DSN Creation
7530| [3500] Microsoft IIS fpcount.exe Remote Overflow
7531| [3341] Microsoft IIS Redirect Response XSS
7532| [3339] Microsoft IIS HTTP Error Page XSS
7533| [3338] Microsoft IIS Help File XSS
7534| [3328] Microsoft IIS FTP Status Request DoS
7535| [3326] Microsoft IIS w3svc.dll ISAPI Filter URL Handling Remote DoS
7536| [3325] Microsoft IIS HTR ISAPI Overflow
7537| [3323] Microsoft IIS ISAPI .printer Extension Host Header Overflow
7538| [3320] Microsoft IIS ASP Server-Side Include Buffer Overflow
7539| [3316] Microsoft IIS HTTP Header Field Delimiter Overflow
7540| [3301] Microsoft IIS ASP Chunked Encoding Variant Heap Overflow
7541| [3284] Microsoft IIS Winmsdp.exe Arbitrary File Retrieval
7542| [3231] Microsoft IIS Log Bypass
7543| [2106] Microsoft Media Services ISAPI nsiislog.dll Overflow
7544| [1931] Microsoft IIS MIME Content-Type Header DoS
7545| [1930] Microsoft IIS SSI ssinc.dll Filename Handling Overflow
7546| [1826] Microsoft IIS Domain Guest Account Disclosure
7547| [1824] Microsoft IIS FTP DoS
7548| [1804] Microsoft IIS Long Request Parsing Remote DoS
7549| [1770] Microsoft IIS WebDAV Malformed PROPFIND Request Remote DoS
7550| [1750] Microsoft IIS File Fragment Disclosure
7551| [1543] Microsoft NT/IIS Invalid URL Request DoS
7552| [1504] Microsoft IIS File Permission Canonicalization Bypass
7553| [1465] Microsoft IIS .htr Missing Variable DoS
7554| [1325] Microsoft IIS Malformed Filename Request File Fragment Disclosure
7555| [1322] Microsoft IIS Malformed .htr Request DoS
7556| [1281] Microsoft IIS Escaped Character Saturation Remote DoS
7557| [1261] Microsoft IIS Chunked Transfer Encoding Remote Overflow DoS
7558| [1210] Microsoft IIS WebHits.dll ISAPI Filter Traversal Arbitrary File Access
7559| [1170] Microsoft IIS Escape Character URL Access Bypass
7560| [1083] Microsoft IIS FTP NO ACCESS Read/Delete File
7561| [1082] Microsoft IIS Domain Resolution Access Bypass
7562| [1041] Microsoft IIS Malformed HTTP Request Header DoS
7563| [1020] Microsoft IIS ISAPI GetExtensionVersion() Privilege Escalation
7564| [930] Microsoft IIS Shared ASP Cache Information Disclosure
7565| [929] Microsoft IIS FTP Server NLST Command Overflow
7566| [928] Microsoft IIS Long Request Log Evasion
7567| [815] Microsoft IIS ASP.NET trace.axd Application Tracing Information Disclosure
7568| [814] Microsoft IIS global.asa Remote Information Disclosure
7569| [782] Microsoft IIS / Site Server codebrws.asp Arbitrary File Access
7570| [771] Microsoft IIS Hosting Process (dllhost.exe) Out of Process Application Unspecified Privilege Escalation
7571| [768] Microsoft IIS ASP Chunked Encoding Heap Overflow
7572| [636] Microsoft IIS sqlqhit.asp Sample Script CiScope Parameter Information Disclosure
7573| [630] Microsoft IIS Multiple Malformed Header Field Internal IP Address Disclosure
7574| [568] Microsoft IIS idq.dll IDA/IDQ ISAPI Remote Overflow
7575| [564] Microsoft IIS ISM.dll Fragmented Source Disclosure
7576| [556] Microsoft IIS/PWS Encoded Filename Arbitrary Command Execution
7577| [525] Microsoft IIS Webserver Invalid Filename Request Arbitrary Command Execution
7578| [482] Microsoft IIS FrontPage Server Extensions (FPSE) Malformed Form DoS
7579| [475] Microsoft IIS bdir.htr Arbitrary Directory Listing
7580| [474] Microsoft IIS / Site Server viewcode.asp Arbitrary File Access
7581| [473] Microsoft IIS Multiple .cnf File Information Disclosure
7582| [471] Microsoft IIS ServerVariables_Jscript.asp Path Disclosure
7583| [470] Microsoft IIS Form_JScript.asp XSS
7584| [463] Microsoft IIS Phone Book Service /pbserver/pbserver.dll Remote Overflow
7585| [436] Microsoft IIS Unicode Remote Command Execution
7586| [425] Microsoft IIS WebDAV SEARCH Method Arbitrary Directory Forced Listing
7587| [391] Microsoft IIS IDA/IDQ Document Root Path Disclosure
7588| [390] Microsoft IIS Translate f: Request ASP Source Disclosure
7589| [308] Microsoft IIS Malformed File Extension URL DoS
7590| [285] Microsoft IIS repost.asp File Upload
7591| [284] Microsoft IIS IISADMPWD Virtual Directory Information Enumeration
7592| [283] Microsoft IIS /iissamples Multiple Sample Scripts Installed
7593| [277] Microsoft IIS / PWS %2e Request ASP Source Disclosure
7594| [276] Microsoft IIS ASP::$DATA Stream Request ASP Source Disclosure
7595| [275] Microsoft IIS newdsn.exe Remote Arbitrary File Creation
7596| [274] Microsoft IIS ctss.idc ODBC Sample Arbitrary Command Execution
7597| [273] Microsoft IIS Upgrade ism.dll Local Privilege Escalation
7598| [272] Microsoft IIS MDAC RDS Arbitrary Remote Command Execution
7599| [271] Microsoft IIS WebHits null.htw .asp Source Disclosure
7600| [98] Microsoft IIS perl.exe HTTP Path Disclosure
7601| [97] Microsoft IIS ISM.DLL HTR Request Overflow
7602| [96] Microsoft IIS idq.dll Traversal Arbitrary File Access
7603| [7] Microsoft IIS / Site Server showcode.asp source Parameter Traversal Arbitrary File Access
7604| [4] Microsoft IIS ExAir advsearch.asp Direct Request Remote DoS
7605| [3] Microsoft IIS ExAir query.asp Direct Request Remote DoS
7606| [2] Microsoft IIS ExAir search.asp Direct Request DoS
7607|_
7608Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
7609Device type: general purpose
7610Running (JUST GUESSING): Microsoft Windows 2012 (89%)
7611OS CPE: cpe:/o:microsoft:windows_server_2012:r2
7612Aggressive OS guesses: Microsoft Windows Server 2012 or Windows Server 2012 R2 (89%), Microsoft Windows Server 2012 R2 (89%), Microsoft Windows Server 2012 (87%)
7613No exact OS matches for host (test conditions non-ideal).
7614Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows
7615
7616TRACEROUTE (using port 443/tcp)
7617HOP RTT ADDRESS
76181 168.80 ms 10.250.200.1
76192 168.91 ms 213.184.122.97
76203 168.88 ms bzq-82-80-246-9.cablep.bezeqint.net (82.80.246.9)
76214 168.91 ms bzq-179-124-185.cust.bezeqint.net (212.179.124.185)
76225 222.75 ms bzq-179-124-62.cust.bezeqint.net (212.179.124.62)
76236 228.19 ms bzq-179-124-30.cust.bezeqint.net (212.179.124.30)
76247 222.36 ms ae9.cr1-lon2.ip4.gtt.net (46.33.89.185)
76258 222.19 ms ae9.cr1-lon2.ip4.gtt.net (46.33.89.185)
76269 292.99 ms a100-gw.ip4.gtt.net (173.205.58.70)
762710 290.65 ms a100-gw.ip4.gtt.net (173.205.58.70)
762811 294.91 ms 52.93.1.81
762912 ... 17
763018 294.18 ms 54.239.41.254
763119 ... 30
7632####################################################################################################
7633https://52.44.246.60 [200 OK] ASP_NET[ViewState Encrypted], Cookies[.ASPXANONYMOUS,__RequestVerificationToken,dnn_IsMobile,language], Country[UNITED STATES][US], DotNetNuke, Frame, Google-Analytics[Universal][UA-104193592-1,UA-79157233-1], HTML5, HttpOnly[.ASPXANONYMOUS,__RequestVerificationToken,dnn_IsMobile,language], IP[52.44.246.60], JQuery, Script[text/javascript], Strict-Transport-Security[max-age=31536000, includeSubDomains], Title[The GEO Group - Official Website][Title element contains newline(s)!], X-Frame-Options[SAMEORIGIN], X-UA-Compatible[IE=edge]
7634#####################################################################################################
7635Version: 1.11.13-static
7636OpenSSL 1.0.2-chacha (1.0.2g-dev)
7637
7638Connected to 52.44.246.60
7639
7640Testing SSL server 52.44.246.60 on port 443 using SNI name 52.44.246.60
7641
7642 TLS Fallback SCSV:
7643Server does not support TLS Fallback SCSV
7644
7645 TLS renegotiation:
7646Secure session renegotiation supported
7647
7648 TLS Compression:
7649Compression disabled
7650
7651 Heartbleed:
7652TLS 1.2 not vulnerable to heartbleed
7653TLS 1.1 not vulnerable to heartbleed
7654TLS 1.0 not vulnerable to heartbleed
7655
7656 Supported Server Cipher(s):
7657Preferred TLSv1.2 256 bits ECDHE-RSA-AES256-SHA384 Curve P-256 DHE 256
7658Accepted TLSv1.2 128 bits ECDHE-RSA-AES128-SHA256 Curve P-256 DHE 256
7659Accepted TLSv1.2 256 bits ECDHE-RSA-AES256-SHA Curve P-256 DHE 256
7660Accepted TLSv1.2 128 bits ECDHE-RSA-AES128-SHA Curve P-256 DHE 256
7661Accepted TLSv1.2 256 bits DHE-RSA-AES256-GCM-SHA384 DHE 1024 bits
7662Accepted TLSv1.2 128 bits DHE-RSA-AES128-GCM-SHA256 DHE 1024 bits
7663Accepted TLSv1.2 256 bits DHE-RSA-AES256-SHA DHE 1024 bits
7664Accepted TLSv1.2 128 bits DHE-RSA-AES128-SHA DHE 1024 bits
7665Accepted TLSv1.2 256 bits AES256-GCM-SHA384
7666Accepted TLSv1.2 128 bits AES128-GCM-SHA256
7667Accepted TLSv1.2 256 bits AES256-SHA256
7668Accepted TLSv1.2 128 bits AES128-SHA256
7669Accepted TLSv1.2 256 bits AES256-SHA
7670Accepted TLSv1.2 128 bits AES128-SHA
7671Accepted TLSv1.2 112 bits DES-CBC3-SHA
7672Accepted TLSv1.2 128 bits RC4-SHA
7673Accepted TLSv1.2 128 bits RC4-MD5
7674Preferred TLSv1.1 256 bits ECDHE-RSA-AES256-SHA Curve P-256 DHE 256
7675Accepted TLSv1.1 128 bits ECDHE-RSA-AES128-SHA Curve P-256 DHE 256
7676Accepted TLSv1.1 256 bits DHE-RSA-AES256-SHA DHE 1024 bits
7677Accepted TLSv1.1 128 bits DHE-RSA-AES128-SHA DHE 1024 bits
7678Accepted TLSv1.1 256 bits AES256-SHA
7679Accepted TLSv1.1 128 bits AES128-SHA
7680Accepted TLSv1.1 112 bits DES-CBC3-SHA
7681Accepted TLSv1.1 128 bits RC4-SHA
7682Accepted TLSv1.1 128 bits RC4-MD5
7683Preferred TLSv1.0 256 bits ECDHE-RSA-AES256-SHA Curve P-256 DHE 256
7684Accepted TLSv1.0 128 bits ECDHE-RSA-AES128-SHA Curve P-256 DHE 256
7685Accepted TLSv1.0 256 bits DHE-RSA-AES256-SHA DHE 1024 bits
7686Accepted TLSv1.0 128 bits DHE-RSA-AES128-SHA DHE 1024 bits
7687Accepted TLSv1.0 256 bits AES256-SHA
7688Accepted TLSv1.0 128 bits AES128-SHA
7689Accepted TLSv1.0 112 bits DES-CBC3-SHA
7690Accepted TLSv1.0 128 bits RC4-SHA
7691Accepted TLSv1.0 128 bits RC4-MD5
7692Preferred SSLv3 112 bits DES-CBC3-SHA
7693Accepted SSLv3 128 bits RC4-SHA
7694Accepted SSLv3 128 bits RC4-MD5
7695
7696 SSL Certificate:
7697Signature Algorithm: sha256WithRSAEncryption
7698RSA Key Strength: 2048
7699
7700Subject: www.geogroup.com
7701Altnames: DNS:www.geogroup.com, DNS:geogroup.com
7702Issuer: Go Daddy Secure Certificate Authority - G2
7703
7704Not valid before: Feb 20 04:17:01 2018 GMT
7705Not valid after: Feb 16 21:05:00 2020 GMT
7706#####################################################################################################
7707Starting Nmap 7.70 ( https://nmap.org ) at 2019-07-26 00:55 EDT
7708Nmap scan report for ec2-52-44-246-60.compute-1.amazonaws.com (52.44.246.60)
7709Host is up (0.28s latency).
7710
7711PORT STATE SERVICE VERSION
77123389/tcp open ms-wbt-server Microsoft Terminal Service
7713| rdp-enum-encryption:
7714| Security layer
7715| CredSSP: SUCCESS
7716| Native RDP: SUCCESS
7717| SSL: SUCCESS
7718| RDP Encryption level: Unknown
7719|_ 128-bit RC4: SUCCESS
7720|_rdp-vuln-ms12-020: ERROR: Script execution failed (use -d to debug)
7721| vulscan: VulDB - https://vuldb.com:
7722| [133212] Microsoft Windows up to Server 2019 Terminal Services Memory information disclosure
7723| [31855] Microsoft Internet Explorer 6.0 SP1 Terminal Service tsuserex.dll memory corruption
7724| [134750] Microsoft ASP.NET Core 2.1/2.2 denial of service
7725| [134749] Microsoft .NET Framework/.NET Core denial of service
7726| [134748] Microsoft .NET Framework/.NET Core denial of service
7727| [134729] Microsoft Windows up to Server 2019 Storage Service privilege escalation
7728| [134705] Microsoft .NET Framework/.NET Core Regex denial of service
7729| [134704] Microsoft SQL Server 2017 Analysis Services information disclosure
7730| [134681] Microsoft Windows Remote Desktop Service memory corruption
7731| [133222] Microsoft Windows up to Server 2019 Remote Registry Service memory corruption
7732| [133214] Microsoft Windows up to Server 2019 AppX Deployment Service privilege escalation
7733| [133197] Microsoft ASP.NET Core 2.2 Request denial of service
7734| [132088] PuTTY up to 0.70 Terminal denial of service
7735| [131657] Microsoft Windows up to Server 2019 denial of service
7736| [131650] Microsoft Windows 10 1803/10 1809/Server 2019/Server 1803 Hyper-V denial of service
7737| [131648] Microsoft Windows up to Server 2019 Hyper-V denial of service
7738| [131644] Microsoft Windows up to Server 2019 Hyper-V denial of service
7739| [131629] Microsoft Windows up to Server 2019 Deployment Services TFTP Server memory corruption
7740| [131210] Jamf Self Service 10.9.0 Terminal privilege escalation
7741| [130817] Microsoft Windows up to Server 2019 Storage Service privilege escalation
7742| [128751] Microsoft Windows up to Server 2019 Data Sharing Service privilege escalation
7743| [128747] Microsoft ASP.NET Core 2.1 Web Request denial of service
7744| [128735] Microsoft ASP.NET Core 2.1/2.2 Web Request denial of service
7745| [128727] Microsoft Windows up to Server 2019 Data Sharing Service privilege escalation
7746| [128726] Microsoft Windows up to Server 2019 Data Sharing Service privilege escalation
7747| [128725] Microsoft Windows up to Server 2019 Data Sharing Service privilege escalation
7748| [127881] Microsoft Windows 10 1809/Server 2019 Object denial of service
7749| [127821] Microsoft Windows up to Server 2019 Connected User Experiences and Telemetry Service denial of service
7750| [127813] Microsoft .NET Framework up to 4.7.2 denial of service
7751| [126793] Microsoft Azure App Service on Azure Stack cross site scripting
7752| [126754] Microsoft Skype for Business/Lync Server 2013 SP1/2016 Emoji denial of service
7753| [126730] Microsoft Windows up to Server 2019 Active Directory Federation Services cross site scripting
7754| [126711] Microsoft Windows up to Server 2019 Deployment Services TFTP Server memory corruption
7755| [124217] Microsoft Windows Server 2012/Server 2016 Active Directory Federation Services /adfs/ls Server-Side Request Forgery
7756| [123992] Microsoft Data.OData Web Request denial of service
7757| [123868] Microsoft Windows up to Server 2016 Hyper-V denial of service
7758| [123867] Microsoft Windows 10 1803/Server 1803 Hyper-V denial of service
7759| [123866] Microsoft Windows 10 1803/Server 1803 Hyper-V denial of service
7760| [123856] Microsoft ASP.NET Core/.NET Core System.IO.Pipelines denial of service
7761| [123849] Microsoft Windows up to Server 2016 SMB denial of service
7762| [121120] Microsoft Active Directory Federation Services Web Customizations cross site scripting
7763| [121107] Microsoft Windows up to Server 2016 DNSAPI DNSAPI.dll denial of service
7764| [121092] Microsoft Windows up to Server 2016 FTP Server denial of service
7765| [121086] Microsoft PowerShell Editor Services privilege escalation
7766| [119470] Microsoft Windows up to Server 2016 HTTP HTTP.sys denial of service
7767| [119466] Microsoft Windows 10 1709/Server 1709 Hyper-V denial of service
7768| [119455] Microsoft Windows up to Server 2016 denial of service
7769| [119453] Microsoft Windows 10 1709/10 1803/Server 1709/Server 1803 WebDAV denial of service
7770| [119448] Microsoft Windows up to Server 2016 Code Integrity Module denial of service
7771| [117479] Microsoft .NET Framework up to 4.7.1 XML Data denial of service
7772| [117331] Microsoft Windows Host Compute Host Compute Service Shim Code Execution memory corruption
7773| [116039] Microsoft Windows up to Server 2016 Remote Desktop Protocol denial of service
7774| [116030] Microsoft Windows up to Server 2016 SNMP Service denial of service
7775| [116024] Microsoft Windows up to Server 2016 HTTP.sys denial of service
7776| [114535] Microsoft Windows up to Server 2016 Hyper-V denial of service
7777| [114524] Microsoft ASP.NET Core 2.0 denial of service
7778| [113264] Microsoft Windows 8.1/RT 8.1/Server 2012 R2 SMBv2/SMBv3 denial of service
7779| [113262] Microsoft Windows 10/Server 1709 Storage Services memory corruption
7780| [113124] LibreOffice up to 6.0.1 COM.MICROSOFT.WEBSERVICE information disclosure
7781| [111557] Microsoft .NET Framework up to 5.7 XML denial of service
7782| [111358] Microsoft Windows up to Server 2016 IPsec denial of service
7783| [109360] Microsoft Windows up to Server 2016 Windows Search denial of service
7784| [109359] Microsoft ASP.NET 1.0/1.1/2.0 denial of service
7785| [109358] Microsoft .NET Framework 1.0/1.1/2.0 denial of service
7786| [107759] Microsoft Windows up to Server 2016 SMB denial of service
7787| [107724] Microsoft Windows up to Server 2016 Text Services Framework memory corruption
7788| [106492] Microsoft Windows Server 2012/Server 2012 R2/Server 2016 DHCP Service memory corruption
7789| [106454] Microsoft Windows up to Server 2016 Windows NetBT Session Services race condition memory corruption
7790| [105049] Microsoft Windows 10 1703 Remote Desktop Protocol denial of service
7791| [105013] Microsoft Windows 10 1607/10 1703/Server 2016 Hyper-V denial of service
7792| [105008] Microsoft SQL Server 2012/2014/2016 Analysis Services information disclosure
7793| [104989] Microsoft Windows up to Server 2016 NetBIOS denial of service
7794| [104982] Microsoft Windows up to XP SMBv1 Smbloris denial of service
7795| [103444] Microsoft Windows up to Server 2016 Explorer denial of service
7796| [103443] Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7 denial of service
7797| [101820] Microsoft Windows Vista/7/8.1 NtfsCommonCreate denial of service
7798| [101151] Microsoft ASP.NET Core/.NET Core Web Request denial of service
7799| [101817] Microsoft Windows up to Server 2016 Malware Protection Engine denial of service
7800| [101814] Microsoft Windows up to Server 2016 Malware Protection Engine denial of service
7801| [101812] Microsoft Windows up to Server 2016 Malware Protection Engine denial of service
7802| [101811] Microsoft Windows up to Server 2016 Malware Protection Engine denial of service
7803| [101810] Microsoft Windows up to Server 2016 Malware Protection Engine denial of service
7804| [101043] Microsoft Windows up to XP SP3 SMB denial of service
7805| [101039] Microsoft Windows up to XP SP3 SMB denial of service
7806| [101036] Microsoft Windows up to XP SP3 SMBv1 Server denial of service
7807| [101026] Microsoft Windows DNS Server denial of service
7808| [100918] Microsoft Windows 8/8.1/10/Server 2012/Server 2016 Malware Protection Service Type Confusion privilege escalation
7809| [100807] Rxvt 2.7.10 Terminal Escape Code Integer denial of service
7810| [99697] Microsoft SharePoint Server 2010 SP1/2010 SP2 Excel Services cross site scripting
7811| [99695] Microsoft Hyper-V Network Switch denial of service
7812| [99694] Microsoft Hyper-V denial of service
7813| [99693] Microsoft Hyper-V Network Switch denial of service
7814| [99692] Microsoft Hyper-V Network Switch denial of service
7815| [99691] Microsoft Hyper-V denial of service
7816| [99690] Microsoft Hyper-V denial of service
7817| [99680] Microsoft Windows up to Vista SP2 Win32k denial of service
7818| [99667] Microsoft Windows 10/Server 2016 Active Directory Service Unresponsive denial of service
7819| [98319] Palo Alto Terminal Services Agent 6.0/7.0/8.0 information disclosure
7820| [98113] Microsoft Windows up to Vista SP2 XML Core Services information disclosure
7821| [98110] Microsoft Windows Active Directory Federation Services XXE information disclosure
7822| [98082] Microsoft Office 2010 SP2/2013 SP1/2013 RT SP1/2016 denial of service
7823| [98015] Microsoft Windows 10/Server 2016 Hyper-V denial of service
7824| [98012] Microsoft Windows up to Vista SP2 Hyper-V denial of service
7825| [98011] Microsoft Windows up to Vista SP2 Hyper-V denial of service
7826| [98010] Microsoft Windows up to Vista SP2 Hyper-V denial of service
7827| [98007] Microsoft Windows 10/Server 2016 Hyper-V Network Switch denial of service
7828| [96521] Microsoft Windows 8.1/10/Server 2012/Server 2016 SMB Response mrxsmb20.sys denial of service
7829| [96743] Microsoft ASP.NET Core MVC denial of service
7830| [96234] Palo Alto Terminal Services Agent up to 7.0.6 User spoofing
7831| [95126] Microsoft Windows Local Security Authority Subsystem Service denial of service
7832| [93541] Microsoft Office 2007 SP3 denial of service
7833| [93418] Microsoft Windows up to Vista SP2 Local Security Authority Subsystem Service denial of service
7834| [93235] Microsoft Internet Explorer 11 CalculateImageImmunity denial of service
7835| [91703] Symantec Mail Security for Microsoft Exchange up to 6.5.8/7.0.4/7.5.4 RAR Decompression Memory Consumption denial of service
7836| [91702] Symantec Mail Security for Microsoft Exchange up to 6.5.8/7.0.4/7.5.4 RAR Decompression Out-of-Bounds denial of service
7837| [91560] Microsoft Windows 10 Object denial of service
7838| [90934] Microsoft Windows 7/8.1 FON Font File win32k.sys denial of service
7839| [87961] Microsoft Windows up to Server 2012 R2 Search denial of service
7840| [87960] Microsoft Windows Server 2008 R2/Server 2012/Server 2012 R2 Active Directory denial of service
7841| [82234] Microsoft Windows 10 HTTP.sys HTTP Request denial of service
7842| [82232] Microsoft XML Core Services 3.0 MSXML memory corruption
7843| [81266] Microsoft Windows up to Vista SP2 OpenType Font denial of service
7844| [80879] Microsoft Windows Network Policy Server RADIUS denial of service
7845| [80878] Microsoft Windows Server 2012 R2 Active Directory Federation Service denial of service
7846| [80223] Microsoft Windows 10/1511 RDP Service weak authentication
7847| [79183] Microsoft Windows up to Server 2012 R2 IPsec denial of service
7848| [78371] Microsoft SharePoint Server 2007 SP3/2010 SP2 InfoPath Forms Services XXE information disclosure
7849| [77640] Microsoft Windows Active Directory denial of service
7850| [77632] Microsoft .NET Framework up to 4.6 MVC denial of service
7851| [77622] Microsoft Windows up to Vista SP2 Journal File denial of service
7852| [77613] Microsoft Windows up to Vista SP2 Adobe Type Manager Library atmfd.dll OpenType Font denial of service
7853| [77597] Microsoft Internet Explorer 10/11 File denial of service
7854| [77038] Microsoft Windows Server 2008 SP2 UDDI Services cross site scripting
7855| [77032] Microsoft Windows up to Vista XML Core Services information disclosure
7856| [77031] Microsoft Windows up to Vista XML Core Services information disclosure
7857| [77030] Microsoft Windows up to Vista XML Core Services information disclosure
7858| [76460] Microsoft Windows 7 SP1/8/Server 2012 RDP Server Service memory corruption
7859| [75783] Microsoft Windows Server 2008/Server 2012 Active Directory Federation Services cross site scripting
7860| [75499] Microsoft Internet Explorer 11 denial of service
7861| [75339] Microsoft .NET Framework up to 4.5.2 XML Memory Consumption denial of service
7862| [75335] Microsoft Windows up to Vista SP2 Service Control Manager privilege escalation
7863| [75328] Microsoft Windows up to Vista Management Console denial of service
7864| [66976] Microsoft Access 2010 VBA Datatype denial of service
7865| [74842] Microsoft Windows 8.1/Server 2012 R2 Hyper-V denial of service
7866| [74841] Microsoft XML Core Services 3.0 privilege escalation
7867| [74834] Microsoft Windows Server 2012 R2 Active Directory Federation Services 3.0 privilege escalation
7868| [73961] Microsoft Windows 7 SP1/8/8.1/Server 2012/Server 2012 R2 Remote Desktop Protocol Object Management denial of service
7869| [73960] Microsoft Windows Netlogon Service User spoofing
7870| [73958] Microsoft Windows up to Vista SP2 Text Services memory corruption
7871| [73950] Microsoft Windows up to Vista Adobe Font Driver denial of service
7872| [69153] Microsoft Windows up to Vista Font Mapper win32k.sys denial of service
7873| [68596] Microsoft Windows Internet Authentication Service denial of service
7874| [68593] Microsoft Windows up to Server 2012 Network Location Awareness Service privilege escalation
7875| [68196] Microsoft Windows up to Vista TrueType Array Index denial of service
7876| [68190] Microsoft Windows up to Vista Audio Service privilege escalation
7877| [68211] Microsoft Internet Explorer 8/9/10/11 denial of service
7878| [67518] Microsoft Lync 2013 denial of service
7879| [67516] Microsoft Lync 2010/2013 denial of service
7880| [67514] Microsoft .NET Framework up to 4.5.2 Hash Collision Form denial of service
7881| [67354] Microsoft SQL Server 2008 SP3/2008 R2 SP2/2012 SP1/2014 SQL Master Data Services cross site scripting
7882| [67018] Microsoft Windows Server 2008/Server 2012/Server 2012 R2 Service Bus AMQP Message denial of service
7883| [29831] Microsoft Malware Protection Engine up to 1.1.10600.0 denial of service
7884| [13548] Microsoft Windows up to Vista TCP/IP Packet TCP Options denial of service
7885| [13546] Microsoft Windows up to Vista XML Core Services information disclosure
7886| [13450] Microsoft Internet Explorer 11 WeakMap Integer denial of service
7887| [69756] Novell openSUSE 11.4/12.1 Terminal caps.c denial of service
7888| [13234] Microsoft Windows iSCSI Packets denial of service
7889| [13233] Microsoft Windows iSCSI Packets denial of service
7890| [12843] Microsoft Office 2007/2010/2011/2013 XML Parser Nested Entities Memory Consumption denial of service
7891| [12271] Microsoft .NET Framework up to 4.5.1 HTTP POST denial of service
7892| [12264] Microsoft Windows up to XP XML Core Services Bypass information disclosure
7893| [12238] Microsoft Windows 8/Server 2012/RT IPv6 denial of service
7894| [66083] Microsoft Dynamics AX 4.0 denial of service
7895| [12183] Microsoft .NET Framework 2/4 DTD denial of service
7896| [11673] Microsoft Windows Live Movie Maker 2011 WAV File denial of service
7897| [11457] Microsoft SharePoint Server/Office Web Apps 2010 SP1/2010 SP2/2013 W3WP Service Account privilege escalation
7898| [11147] Microsoft Windows up to XP X.509 Certificate Processor Crypt32.dll/Wcrypt32.dll denial of service
7899| [11230] Microsoft Word 2003 DOC Document Embedded Image denial of service
7900| [10641] Microsoft Windows up to XP Comctl32.dll DSA_InsertItem denial of service
7901| [10640] Microsoft .NET Framework up to 4.5 JSON Data Crash denial of service
7902| [10639] Microsoft .NET Framework up to 4.5 XML External Entity Crash denial of service
7903| [10250] Microsoft SharePoint Server up to 2013 W3WP Process denial of service
7904| [10190] Microsoft Windows Vista/7/8/Server 2008 Active Directory denial of service
7905| [9944] Microsoft Windows up to XP TCP/IP Stack ICMPv6 Packet Stack-Based denial of service
7906| [9943] Microsoft Windows Server 2012 NAT Driver ICMP Packet denial of service
7907| [9929] Microsoft Windows Server 2008/Server 2012 Active Directory Federation Services Unspecified Account information disclosure
7908| [9715] Microsoft PowerPoint 2007 DirectShow Runtime quartz.dll GetMaxSampleSize denial of service
7909| [9259] Microsoft Internet Explorer 7.00.5730.13/8.00.6001.18702 Javascript denial of service
7910| [9101] Microsoft Internet Explorer 9/10 denial of service
7911| [8722] Microsoft Windows 8/Server 2012/RT HTTP.sys denial of service
7912| [12619] Microsoft Internet Explorer XMLDOM ActiveX Control denial of service
7913| [8423] Microsoft Internet Explorer up to 8.00.6001.18702 CSS iexplorer.exe denial of service
7914| [8208] Microsoft Windows win32k.sys denial of service
7915| [8203] Microsoft Windows up to 2012 AD LDAP Query denial of service
7916| [7968] Microsoft SharePoint Server 2010 SP1 Input Validator Eingabe Crash denial of service
7917| [7996] Microsoft Windows 8 TrueType Font denial of service
7918| [7981] FFmpeg up to 1.1.3 Microsoft RLE Data msrledec.c msrle_decode_8_16_24_32 denial of service
7919| [8432] Microsoft Internet Explorer 10 HTML5 Engine localStorage denial of service
7920| [7941] Google Chrome 15.0.874.121/16.0.912.63/26.0.1410.27 Frame Plugin for Microsoft IE protocol_sink_wrap.cc Hook_Terminate denial of service
7921| [7678] Microsoft Windows up to XP TCP FIN WAIT TCP/IP denial of service
7922| [7643] Microsoft Windows Server 2008 R2/Server 2012 NFS Server NULL Pointer Dereference denial of service
7923| [63336] Microsoft XML Core Services 3.0/5.0/6.0 memory corruption
7924| [7259] Microsoft .NET Framework 3.5/3.5 SP1/3.5.1/4 Replace() denial of service
7925| [7255] Microsoft .NET Framework up to 4.5 System.DirectoryServices.Protocolsb Method memory corruption
7926| [7249] Microsoft XML Core Services 1.x XSLT memory corruption
7927| [7199] Microsoft Internet Explorer 8/9 mshtml.dll Unclosed Tags Sequence denial of service
7928| [7121] Microsoft Exchange 2007/2010 RSS Feed denial of service
7929| [7092] Microsoft Internet Explorer 7 Redirect denial of service
7930| [7058] Microsoft Windows 7/Server 2008 R2 DHCPv6 Message denial of service
7931| [7230] Microsoft Excel 2010 SP1 on 32-bit XLS File Formatting Information Crash denial of service
7932| [6627] Microsoft Windows 7/Server 2008 R2 Kerberos denial of service
7933| [5939] Microsoft Windows XP/Vista/7/Server 2003/Server 2008 R2 Print Spooler Service memory corruption
7934| [5938] Microsoft Windows XP/Vista/7/Server 2003/Server 2008 R2 Remote Administration Protocol netapi32.dll RAP Request denial of service
7935| [61375] Nalin Dahyabhai Vte up to 0.19.0 Terminal denial of service
7936| [61230] Synel SY-780/A Time & Attendance terminal 3735 Terminal denial of service
7937| [61153] Keith Winstein mosh up to 1.2-2 Terminal denial of service
7938| [5553] Microsoft Windows XP/Vista/7/Server 2003/Server 2008 OpenType Font atmfd.dll denial of service
7939| [5526] Microsoft XML Core Services up to 6.0 memory corruption
7940| [5474] Microsoft WordPad 5.1 DOC Document denial of service
7941| [60711] Microsoft .NET Framework 4.0 denial of service
7942| [4803] Microsoft Windows Server 2003/Server 2008 DNS Server Domain Resource Record Query Parser denial of service
7943| [4802] Microsoft Windows XP/Vista/7/Server 2003/Server 2008 Remote Desktop Protocol denial of service
7944| [4798] Microsoft Windows XP/Vista/7/Server 2003/Server 2008 Remote Desktop Service memory corruption
7945| [4848] Microsoft Internet Explorer 6/7/8/9/10 Integrity Process denial of service
7946| [4509] Microsoft .NET Framework 1.1 SP1/2.0 SP2/3.5 SP1/3.5.1/4.0 Forms Authentication Ticket Caching denial of service
7947| [4506] Microsoft .NET Framework 1.1 SP1/2.0 SP2/3.5 SP1/3.5.1/4.0 ASP.NET Hash denial of service
7948| [4484] Microsoft Windows Phone 7.5 SMS Service denial of service
7949| [4455] Microsoft Windows XP Keyboard Layout win32k.sys denial of service
7950| [4439] Microsoft Windows True Type Fonts denial of service
7951| [4438] Microsoft Windows Vista/7/Server 2008 TCP/IP Reference Counter denial of service
7952| [59008] Microsoft Forefront Unified Access Gateway 2010 Crash denial of service
7953| [59005] Microsoft Host Integration Server 2004 denial of service
7954| [4424] Microsoft Host Integration Server up to 2010 denial of service
7955| [58236] Microsoft Windows TCP/IP Stack Stack-Based denial of service
7956| [4396] Microsoft Windows Vista/7/Server 2008 TCP/IP Stack denial of service
7957| [4394] Microsoft Windows DNS Service Domain Lookup denial of service
7958| [4393] Microsoft Windows Server 2008 DNS Service memory corruption
7959| [4392] Microsoft Windows Remote Access Service memory corruption
7960| [4389] Microsoft Windows Remote Desktop Protocol denial of service
7961| [4388] Microsoft Windows Vista/7/Server 2008 File Metadata Parser denial of service
7962| [4386] Microsoft Windows XP denial of service
7963| [91971] Microsoft Skype 2.2.x/5.2.x/5.3.x denial of service
7964| [57812] Microsoft Windows XP lots-of-polys-example.html denial of service
7965| [57693] Microsoft Forefront Threat Management Gateway 2010 NSPLookupServiceNext memory corruption
7966| [57692] Microsoft Windows XP denial of service
7967| [57691] Microsoft SQL Server 2008 Web Service information disclosure
7968| [4367] Microsoft Windows Server 2008 Hyper-V VMBus denial of service
7969| [4362] Microsoft Windows Vista/7/Server 2008 denial of service
7970| [4347] Microsoft Windows WINS Service Stack-based Designfehler
7971| [57299] Microsoft Silverlight up to 4.0.60129.0 Grid Control Memory Leak denial of service
7972| [57298] Microsoft Silverlight up to 4.0.60129.0 Memory Leak denial of service
7973| [4337] Microsoft Windows OpenType Font Stack-based denial of service
7974| [4301] Microsoft Windows Server 2003 SMB Browser Heap-based denial of service
7975| [56383] Microsoft Windows denial of service
7976| [55937] Microsoft Windows XP denial of service
7977| [4234] Microsoft IIS 7.5 FTP Server Telnet IAC Character Heap-based denial of service
7978| [4230] Microsoft Exchange 2007 on 64-bit RPC store.exe MAPI Request denial of service
7979| [4229] Microsoft SharePoint 2007 Document Conversion Launcher Service Eingabeung\xC3\xBCltigkeit
7980| [4228] Microsoft Windows Server 2008 Hyper-V VMBus denial of service
7981| [4227] Microsoft Windows Netlogon RPC Service denial of service
7982| [4231] Microsoft Windows XP/Vista/7/Server 2003/Server 2008 Driver win32k.sys GreEnableEUDC denial of service
7983| [4194] Microsoft Windows Vista/7/Server 2008 SChannel Client Certificate Request denial of service
7984| [54774] Microsoft Word 2003 word_crash_11.8326.8324_poc.doc denial of service
7985| [4180] Microsoft IIS 5.1/6.0/7.0/7.5 Repeated Parameter Request denial of service
7986| [4187] Microsoft Windows Vista/7/Server 2008 TCP/IP Stack Ipv4SetEchoRequestCreate() denial of service
7987| [54333] Microsoft Windows denial of service
7988| [54332] Microsoft Windows denial of service
7989| [4165] Microsoft Windows Vista/7/Server 2008 TCP/IP Stack denial of service
7990| [4163] Microsoft XML Core Services 3.x HTTP HTTP Response memory corruption
7991| [53508] Microsoft SharePoint Services 3.0 denial of service
7992| [4134] Microsoft Windows OpenType Compact Font Format Driver denial of service
7993| [53422] Microsoft Internet Explorer 6.0.2900.2180 denial of service
7994| [53421] Microsoft Internet Explorer 6/7/8 denial of service
7995| [53284] Microsoft Internet Explorer 6/7/8 denial of service
7996| [4107] Microsoft Windows 7/Server 2008 Kernel denial of service
7997| [4104] Microsoft Windows SMTP Service denial of service
7998| [4103] Microsoft Windows Server 2003 Media Services Stack-based memory corruption
7999| [52400] Microsoft Internet Explorer 6.00.2800.1106 NULL Pointer Dereference denial of service
8000| [52336] Microsoft Windows denial of service
8001| [51809] Microsoft Windows denial of service
8002| [51803] Microsoft Windows NULL Pointer Dereference denial of service
8003| [51796] Microsoft Windows denial of service
8004| [51497] Microsoft Windows Live Messenger 2009 ActiveX Control msnmsgr.exe denial of service
8005| [4067] Microsoft Windows Active Directory Federation Service memory corruption
8006| [4066] Microsoft Windows Local Security Authority Subsystem denial of service
8007| [50823] Microsoft Internet Explorer 6/7 denial of service
8008| [50811] Microsoft Windows denial of service
8009| [4058] Microsoft Windows Active Directory denial of service
8010| [50445] Microsoft Windows EducatedScholar denial of service
8011| [50444] Microsoft Windows Local Security Authority Subsystem Service Integer denial of service
8012| [50139] Microsoft Enterprise Library 4.0 denial of service
8013| [50128] Microsoft Internet Explorer 7.00.5730.1100 window.print denial of service
8014| [50125] Microsoft Internet Explorer 6/7 denial of service
8015| [4030] Microsoft Windows Vista/Server 2008 Wireless LAN AutoConfig Service Heap-based memory corruption
8016| [4029] Microsoft Windows 2000/XP TCP/IP Window Size denial of service
8017| [4024] Microsoft IIS 5.0/6.0/7.0 FTP Server denial of service
8018| [49745] Microsoft Windows Server 2003 denial of service
8019| [49744] Microsoft Internet Explorer 7 Crash denial of service
8020| [49699] Sophos PureMessage for Microsoft Exchange Installation denial of service
8021| [49698] Sophos PureMessage for Microsoft Exchange EdgeTransport.exe denial of service
8022| [49697] Sophos PureMessage for Microsoft Exchange Message Queue PMScanner.exe denial of service
8023| [49620] Microsoft Internet Explorer up to 6.0.2900.2180 JavaScript denial of service
8024| [49434] Microsoft Windows 7 Crash denial of service
8025| [4014] Microsoft Windows Workstation Service memory corruption
8026| [4013] Microsoft Windows Message Queuing Service Designfehler
8027| [4012] Microsoft Windows WINS Service memory corruption
8028| [4011] Microsoft Windows WINS Service Heap-based memory corruption
8029| [4009] Microsoft NET Framework 2.x/3.x denial of service
8030| [49262] Microsoft Internet Explorer 6/7 denial of service
8031| [49242] Microsoft Internet Explorer 7/8 on Win XP mshtml.dll denial of service
8032| [49122] Microsoft Internet Explorer 5/6/7 Unicode Character Memory Consumption denial of service
8033| [49074] Microsoft Internet Explorer 5/6/7/8 Memory Consumption denial of service
8034| [48518] Microsoft ADAM XP Active Directory Memory Leak denial of service
8035| [48033] Microsoft Windows XP denial of service
8036| [47808] Microsoft Internet Explorer 7/8 on Win XP/Vista Document denial of service
8037| [47804] Microsoft Windows Media Player 11.0.5721.5260 Integer denial of service
8038| [86702] Microsoft ISA Server / denial of service
8039| [3952] Microsoft ISA Server 2004/2006 denial of service
8040| [3950] Microsoft Windows HTTP Service memory corruption
8041| [47465] Microsoft Windows GDI+ gdiplus.dll GpFont::SetData denial of service
8042| [46637] Microsoft Windows DNS Server Memory Leak denial of service
8043| [46620] Microsoft Windows Live Messenger 2009 msnmsgr.exe denial of service
8044| [46455] Microsoft Exchange Server 2007 denial of service
8045| [46294] Microsoft XML Core Services information disclosure
8046| [46007] Microsoft Windows Mobile 6.0 FTP Service Stack-Based directory traversal
8047| [45911] Microsoft Windows Domain Controller denial of service
8048| [45826] Microsoft Internet Explorer 6/7/8 Crash denial of service
8049| [45758] Microsoft Money 2006 ActiveX Control prtstb06.dll denial of service
8050| [45676] Microsoft Windows Media Player 9 quartz.dll denial of service
8051| [45392] Microsoft Outlook Express 6.00.2900.5512 InetComm.dll MimeOleClearDirtyTree denial of service
8052| [45379] Microsoft Office SharePoint Server 2007 denial of service
8053| [45131] Microsoft Office Communicator denial of service
8054| [45130] Microsoft Office Communicator Memory Consumption denial of service
8055| [45129] Microsoft Windows Live Messenger Crash denial of service
8056| [44976] Microsoft XML Core Services up to 6.0 information disclosure
8057| [44975] Microsoft XML Core Services 3.0/4.0 information disclosure
8058| [44860] Microsoft Windows Media Player up to 9 Crash denial of service
8059| [44780] Microsoft Debug Diagnostic Tool 1.0 ActiveX Control CrashHangExt.dll denial of service
8060| [3851] Microsoft Windows IIS IPP Service memory corruption
8061| [44306] Microsoft Internet Explorer 7 alert denial of service
8062| [44249] Microsoft Windows XP SP3 gdiplus.dll denial of service
8063| [44246] Microsoft Windows XP SP3 denial of service
8064| [44237] Microsoft iis ActiveX Control adsiis.dll denial of service
8065| [44236] Microsoft Authentication Service iashlpr.dll denial of service
8066| [44227] Microsoft Windows Mobile 6.0 Bluetooth denial of service
8067| [44092] Microsoft Internet Explorer 7/8 Beta PNG Image Mshtml.dll CDwnTaskExec::ThreadExec denial of service
8068| [44069] Microsoft Windows denial of service
8069| [42732] Microsoft Windows XP/Vista/Server 2003 denial of service
8070| [42731] Microsoft Windows Server 2003 denial of service
8071| [3733] Microsoft Windows Active Directory LDAP Request denial of service
8072| [42328] Microsoft Windows Live Onecare 1.1.3520.0 Malware Protection Engine mpengine.dll denial of service
8073| [42327] Microsoft Windows Live Onecare 1.1.3520.0 Malware Protection Engine mpengine.dll denial of service
8074| [40987] Microsoft Windows 2000 denial of service
8075| [40986] Microsoft Windows Vista denial of service
8076| [40353] Microsoft Internet Explorer 7 ActiveX Control npupload.dll SetPassword denial of service
8077| [40242] Microsoft Publisher 2000/2002/2003/2007 Crash denial of service
8078| [3510] Microsoft Media Services 9.x ASF File Heap-based memory corruption
8079| [39937] Microsoft Windows Media Player 11 Crash denial of service
8080| [36994] Microsoft Visual Database Tools Database Designer 7.0 ActiveX Control vdt70.dll notsafe denial of service
8081| [3372] Microsoft Windows SharePoint Services cross site scripting
8082| [3370] Microsoft Windows RPC Authentication denial of service
8083| [38999] Microsoft Windows Server 2003 explorer.exe denial of service
8084| [3302] Microsoft Windows Services for UNIX memory corruption
8085| [3252] Microsoft XML Core Services substringData() cross site scripting
8086| [38272] Microsoft Windows Media Player 11 wmplayer.exe denial of service
8087| [38227] Microsoft Internet Explorer 6 JPG Image explorer.exe denial of service
8088| [38246] Microsoft Windows Crash denial of service
8089| [37962] Microsoft Internet Explorer GIF File explorer.exe denial of service
8090| [3179] Microsoft Windows Active Directory LDAP ASN denial of service
8091| [37724] Microsoft Register Server denial of service
8092| [37627] Microsoft Internet Explorer 6.0/7.0 Zone denial of service
8093| [37526] Microsoft Windows 2000/Server 2003 denial of service
8094| [37405] Microsoft Internet Explorer 6 on Win XP SysFreeString denial of service
8095| [37508] Microsoft MSN Messenger 4.7 Flooding denial of service
8096| [37157] Microsoft Windows XP Graphics Device Interface gdiplus.dll denial of service
8097| [86350] Microsoft Windows denial of service
8098| [36936] Microsoft Internet Information Services 5.0 Authentication Mechanism webhits.dll unknown vulnerability
8099| [36711] Microsoft Terminal Server 6.0 Remote Desktop Protocol unknown vulnerability
8100| [36621] Microsoft Exchange Server 2000 Integer denial of service
8101| [36618] Microsoft Exchange Server 2000 NULL Pointer Dereference denial of service
8102| [36305] Microsoft Internet Explorer 7.0 denial of service
8103| [3012] Microsoft Windows 2000/Server 2003 DNS Service Stack-based memory corruption
8104| [36002] Microsoft Windows XP/2000 denial of service
8105| [2991] Microsoft Windows Vista ATI Radeon Kernel Mode Driver Crash denial of service
8106| [35822] Microsoft Windows Proxy Server denial of service
8107| [35704] Microsoft Windows XP/Vista ARP denial of service
8108| [35703] Microsoft Windows Vista LLTD Mapper denial of service
8109| [35654] Microsoft Windows XP winmm.dll mmioread denial of service
8110| [35373] Microsoft Excel 2003 denial of service
8111| [35372] Microsoft Office 2003 denial of service
8112| [35254] Microsoft Internet Explorer 6 mshtml.dll denial of service
8113| [35206] Microsoft Windows XP/Server 2003 Crash denial of service
8114| [35209] Microsoft Internet Explorer 7.0 LOAD Crash denial of service
8115| [35165] Microsoft Internet Explorer up to 6.0.2900 mshtml.dll denial of service
8116| [35164] Microsoft Internet Explorer up to 6.0 mshtml.dll denial of service
8117| [35163] Microsoft Internet Explorer denial of service
8118| [34991] Microsoft Visual Studio 8.0 msvcr80.dll denial of service
8119| [34967] Microsoft Windows Mobile 5.0 denial of service
8120| [34875] Microsoft Internet Explorer 6.0 SP1/6.0 SP2 NULL Pointer Dereference denial of service
8121| [34793] Microsoft Windows Mobile 5.0 denial of service
8122| [34655] Microsoft Internet Explorer Crash denial of service
8123| [34737] Microsoft Internet Explorer 7 ActiveX Control mshtml.dll denial of service
8124| [34690] Microsoft Windows Explorer 6.0.2900.2180 explorer.exe denial of service
8125| [2809] Microsoft Outlook 2000/2002/2003 Header denial of service
8126| [34253] Microsoft IIS denial of service
8127| [85073] Microsoft Internet Explorer denial of service
8128| [34124] Microsoft Dynamics GP up to 9.0 Crash denial of service
8129| [2789] Microsoft Windows 2000/XP RPC Request NetrWkstaUserEnum() denial of service
8130| [33949] Microsoft Internet Explorer 7.0 ActiveX Control ole32.dll denial of service
8131| [33890] Microsoft Windows XP SP2 Explorer explorer.exe denial of service
8132| [33889] Microsoft Windows Media Player 10.00.00.4036 denial of service
8133| [2739] Microsoft Windows 2000 Remote Installation Service Fehlende Authentifizierung
8134| [2737] Microsoft Windows XP/Server 2003 Manifest denial of service
8135| [33643] Microsoft Internet Explorer 6.0.2900.2180 denial of service
8136| [33642] Microsoft Internet Explorer up to 6.0 Crash denial of service
8137| [33589] Microsoft Windows Live Messenger up to 8.0 denial of service
8138| [2717] Microsoft Windows 2000 Print Spooler Memory Consumption denial of service
8139| [2689] Microsoft Windows up to 2000 SP4 Active Directory denial of service
8140| [2688] Microsoft Windows 2000/XP/Server 2003 Client Service for Netware denial of service
8141| [2686] Microsoft Windows 2000/XP/Server 2003 Client Service for Netware memory corruption
8142| [2684] Microsoft Windows 2000/XP Workstation Service Stack-based memory corruption
8143| [2655] Microsoft Windows 2000/XP/Server 2003 XML Core Services Designfehler
8144| [2640] Microsoft Windows XP Windows NAT Helper Component ipnathlp.dll DNS Query denial of service
8145| [2610] Microsoft PowerPoint 2003 PPT Document NULL Pointer Dereference denial of service
8146| [32692] Microsoft XML Core Services up to 2.6 memory corruption
8147| [32691] Microsoft XML Core Services up to 2.6 memory corruption
8148| [2601] Microsoft Windows XP/Server 2003 IPv6 Stack denial of service
8149| [2600] Microsoft Windows XP/Server 2003 IPv6 Stack TCP denial of service
8150| [2599] Microsoft Windows XP/Server 2003 IPv6 Stack ICMP denial of service
8151| [2522] Microsoft Windows 2000/XP/Server 2003 Indexing Service cross site scripting
8152| [32026] Microsoft Terminal Server Client Connection Manager memory corruption
8153| [84706] Microsoft Internet Explorer dxtmsft3.dll denial of service
8154| [31920] Microsoft Internet Explorer 6.0 SP1 dximagetransform.microsoft.chroma.1 denial of service
8155| [31736] Microsoft Windows XP gdiplus.dll denial of service
8156| [2426] Microsoft Windows 2000/XP/Server 2003 WMF File gdi32.dll denial of service
8157| [2415] Microsoft Windows 2000/XP/Server 2003 SMB File srv.sys denial of service
8158| [35255] Microsoft Internet Explorer up to 7.0.6000.16473 NULL Pointer Dereference denial of service
8159| [31521] Microsoft Windows NT 4.0/2000/XP IP Stack Stack-Based denial of service
8160| [31551] Microsoft Internet Explorer 6 window.alert denial of service
8161| [31582] Microsoft Internet Explorer 6 Integer denial of service
8162| [31527] Microsoft Internet Explorer 6.0 on Win 2000 ActiveX Object Stack-Based denial of service
8163| [32623] Microsoft Internet Explorer up to 6.0 wininet.dll denial of service
8164| [31528] Microsoft Internet Explorer 6.0 ActiveX Object Click denial of service
8165| [31529] Microsoft Internet Explorer 6.0 ActiveX Object cenroll.cenroll.2 stringtobinary denial of service
8166| [31546] Microsoft Internet Explorer 6 ActiveX Object newdefaultitem denial of service
8167| [31431] Microsoft Internet Explorer 6 DataSourceControl Integer denial of service
8168| [31358] Microsoft PowerPoint 2003 powerpnt.exe denial of service
8169| [31352] Microsoft Works 8.0 Spreadsheet wksss.exe denial of service
8170| [31355] Microsoft Internet Explorer 6 ActiveX Object Stack-Based denial of service
8171| [31357] Microsoft Internet Explorer 6 ActiveX Object Crash denial of service
8172| [31356] Microsoft Internet Explorer 6 Security Check Crash denial of service
8173| [32375] Microsoft Internet Explorer up to 6 denial of service
8174| [31331] Microsoft Internet Explorer 6.0 ActiveX Object Crash denial of service
8175| [31272] Microsoft Internet Explorer 7.0 Crash denial of service
8176| [31319] Microsoft Internet Explorer NULL Pointer Dereference denial of service
8177| [2369] Microsoft Windows 2000/XP/Server 2003 Server Service Mailslot Heap-based memory corruption
8178| [31239] Microsoft Internet Explorer Crash denial of service
8179| [31240] Microsoft Internet Explorer ActiveX Object Crash denial of service
8180| [31241] Microsoft Internet Explorer danim.dll denial of service
8181| [31238] Microsoft Internet Explorer 6.0 on Win 2000 Crash denial of service
8182| [31213] Microsoft Internet Explorer 6 Crash denial of service
8183| [31204] Microsoft Internet Explorer 6.0 ActiveX Object Crash denial of service
8184| [31214] Microsoft Internet Explorer 6.0/6.0 SP1 denial of service
8185| [32150] Microsoft System Information ActiveX control ActiveX Control msinfo.dll savefile denial of service
8186| [28142] Microsoft Outlook Express Book Control Address Book Crash denial of service
8187| [31136] Microsoft Internet Explorer 6 ActiveX Object Crash denial of service
8188| [30973] Microsoft Internet Explorer 6.0.2900 Crash denial of service
8189| [2309] Microsoft Windows 2000/XP/Server 2003 Routing and Remote Access Service RPC Request memory corruption
8190| [30131] Microsoft Windows NT 4.0/XP/2000/Server 2003 Distributed Transaction Coordinator Crash denial of service
8191| [2218] Microsoft Windows 2000/XP/Server 2003 MSDTC Heap-based denial of service
8192| [29604] Microsoft Internet Explorer 6 Crash denial of service
8193|
8194| MITRE CVE - https://cve.mitre.org:
8195| [CVE-2012-0152] The Remote Desktop Protocol (RDP) service in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows remote attackers to cause a denial of service (application hang) via a series of crafted packets, aka "Terminal Server Denial of Service Vulnerability."
8196| [CVE-2011-1991] Multiple untrusted search path vulnerabilities in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allow local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .doc, .rtf, or .txt file, related to (1) deskpan.dll in the Display Panning CPL Extension, (2) EAPHost Authenticator Service, (3) Folder Redirection, (4) HyperTerminal, (5) the Japanese Input Method Editor (IME), and (6) Microsoft Management Console (MMC), aka "Windows Components Insecure Library Loading Vulnerability."
8197| [CVE-2009-1929] Heap-based buffer overflow in the Microsoft Terminal Services Client ActiveX control running RDP 6.1 on Windows XP SP2, Vista SP1 or SP2, or Server 2008 Gold or SP2
8198| [CVE-2009-1133] Heap-based buffer overflow in Microsoft Remote Desktop Connection (formerly Terminal Services Client) running RDP 5.0 through 6.1 on Windows, and Remote Desktop Connection Client for Mac 2.0, allows remote attackers to execute arbitrary code via unspecified parameters, aka "Remote Desktop Connection Heap Overflow Vulnerability."
8199| [CVE-2006-4219] The Terminal Services COM object (tsuserex.dll) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by instantiating it as an ActiveX object in Internet Explorer 6.0 SP1 on Microsoft Windows 2003 EE SP1 CN.
8200| [CVE-2005-3176] Microsoft Windows 2000 before Update Rollup 1 for SP4 does not record the IP address of a Windows Terminal Services client in a security log event if the client connects successfully, which could make it easier for attackers to escape detection.
8201| [CVE-2004-0900] The DHCP Server service for Microsoft Windows NT 4.0 Server and Terminal Server Edition does not properly validate the length of certain messages, which allows remote attackers to execute arbitrary code via a malformed DHCP message, aka the "DHCP Request Vulnerability."
8202| [CVE-2004-0899] The DHCP Server service for Microsoft Windows NT 4.0 Server and Terminal Server Edition, with DHCP logging enabled, does not properly validate the length of certain messages, which allows remote attackers to cause a denial of service (application crash) via a malformed DHCP message, aka "Logging Vulnerability."
8203| [CVE-2003-0807] Buffer overflow in the COM Internet Services and in the RPC over HTTP Proxy components for Microsoft Windows NT Server 4.0, NT 4.0 Terminal Server Edition, 2000, XP, and Server 2003 allows remote attackers to cause a denial of service via a crafted request.
8204| [CVE-2003-0003] Buffer overflow in the RPC Locator service for Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute arbitrary code via an RPC call to the service containing certain parameter information.
8205| [CVE-2002-1933] The terminal services screensaver for Microsoft Windows 2000 does not automatically lock the terminal window if the window is minimized, which could allow local users to gain access to the terminal server window.
8206| [CVE-2002-1795] Cross-site scripting (XSS) vulnerability in connect.asp in Microsoft Terminal Services Advanced Client (TSAC) ActiveX control allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
8207| [CVE-2002-0726] Buffer overflow in Microsoft Terminal Services Advanced Client (TSAC) ActiveX control allows remote attackers to execute arbitrary code via a long server name field.
8208| [CVE-2013-3661] The EPATHOBJ::bFlatten function in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not check whether linked-list traversal is continually accessing the same list member, which allows local users to cause a denial of service (infinite traversal) via vectors that trigger a crafted PATHRECORD chain.
8209| [CVE-2013-3178] Microsoft Silverlight 5 before 5.1.20513.0 does not properly initialize arrays, which allows remote attackers to execute arbitrary code or cause a denial of service (NULL pointer dereference) via a crafted Silverlight application, aka "Null Pointer Vulnerability."
8210| [CVE-2013-3172] Buffer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to cause a denial of service (system hang) via a crafted application that leverages improper handling of objects in memory, aka "Win32k Buffer Overflow Vulnerability."
8211| [CVE-2013-3164] Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
8212| [CVE-2013-3163] Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3144 and CVE-2013-3151.
8213| [CVE-2013-3162] Microsoft Internet Explorer 7 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3115.
8214| [CVE-2013-3161] Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3143.
8215| [CVE-2013-3153] Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3148.
8216| [CVE-2013-3152] Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3146.
8217| [CVE-2013-3151] Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3144 and CVE-2013-3163.
8218| [CVE-2013-3150] Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3145.
8219| [CVE-2013-3149] Microsoft Internet Explorer 7 and 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
8220| [CVE-2013-3148] Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3153.
8221| [CVE-2013-3147] Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
8222| [CVE-2013-3146] Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3152.
8223| [CVE-2013-3145] Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3150.
8224| [CVE-2013-3144] Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3151 and CVE-2013-3163.
8225| [CVE-2013-3143] Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3161.
8226| [CVE-2013-3142] Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3112, CVE-2013-3113, CVE-2013-3121, and CVE-2013-3139.
8227| [CVE-2013-3141] Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3110.
8228| [CVE-2013-3139] Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3112, CVE-2013-3113, CVE-2013-3121, and CVE-2013-3142.
8229| [CVE-2013-3138] Integer overflow in the TCP/IP kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allows remote attackers to cause a denial of service (system hang) via crafted TCP packets, aka "TCP/IP Integer Overflow Vulnerability."
8230| [CVE-2013-3125] Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3118 and CVE-2013-3120.
8231| [CVE-2013-3124] Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3117 and CVE-2013-3122.
8232| [CVE-2013-3123] Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3111.
8233| [CVE-2013-3122] Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3117 and CVE-2013-3124.
8234| [CVE-2013-3121] Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3112, CVE-2013-3113, CVE-2013-3139, and CVE-2013-3142.
8235| [CVE-2013-3120] Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3118 and CVE-2013-3125.
8236| [CVE-2013-3119] Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3114.
8237| [CVE-2013-3118] Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3120 and CVE-2013-3125.
8238| [CVE-2013-3117] Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3122 and CVE-2013-3124.
8239| [CVE-2013-3116] Microsoft Internet Explorer 7 through 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
8240| [CVE-2013-3115] Microsoft Internet Explorer 7 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3162.
8241| [CVE-2013-3114] Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3119.
8242| [CVE-2013-3113] Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3112, CVE-2013-3121, CVE-2013-3139, and CVE-2013-3142.
8243| [CVE-2013-3112] Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3113, CVE-2013-3121, CVE-2013-3139, and CVE-2013-3142.
8244| [CVE-2013-3111] Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3123.
8245| [CVE-2013-3110] Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3141.
8246| [CVE-2013-2558] Unspecified vulnerability in Microsoft Windows 8 allows remote attackers to cause a denial of service (reboot) or possibly have unknown other impact via a crafted TrueType Font (TTF) file, as demonstrated by the 120612-69701-01.dmp error report.
8247| [CVE-2013-2557] The sandbox protection mechanism in Microsoft Internet Explorer 9 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, as demonstrated against Adobe Flash Player by VUPEN during a Pwn2Own competition at CanSecWest 2013.
8248| [CVE-2013-2496] The msrle_decode_8_16_24_32 function in msrledec.c in libavcodec in FFmpeg through 1.1.3 does not properly determine certain end pointers, which allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) or possibly have unspecified other impact via crafted Microsoft RLE data.
8249| [CVE-2013-1346] mpengine.dll in Microsoft Malware Protection Engine before 1.1.9506.0 on x64 platforms allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file.
8250| [CVE-2013-1305] HTTP.sys in Microsoft Windows 8, Windows Server 2012, and Windows RT allows remote attackers to cause a denial of service (infinite loop) via a crafted HTTP header, aka "HTTP.sys Denial of Service Vulnerability."
8251| [CVE-2013-1293] The NTFS kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via a crafted application that leverages improper handling of objects in memory, aka "NTFS NULL Pointer Dereference Vulnerability."
8252| [CVE-2013-1291] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, Windows 7 Gold and SP1, and Windows 8 allows local users to cause a denial of service (reboot) via a crafted OpenType font, aka "OpenType Font Parsing Vulnerability" or "Win32k Font Parsing Vulnerability."
8253| [CVE-2013-1282] The LDAP service in Microsoft Active Directory, Active Directory Application Mode (ADAM), Active Directory Lightweight Directory Service (AD LDS), and Active Directory Services allows remote attackers to cause a denial of service (memory consumption and service outage) via a crafted query, aka "Memory Consumption Vulnerability."
8254| [CVE-2013-1281] The NFS server in Microsoft Windows Server 2008 R2 and R2 SP1 and Server 2012 allows remote attackers to cause a denial of service (NULL pointer dereference and reboot) via an attempted renaming of a file or folder located on a read-only share, aka "NULL Dereference Vulnerability."
8255| [CVE-2013-0085] Buffer overflow in Microsoft SharePoint Server 2010 SP1 and SharePoint Foundation 2010 SP1 allows remote attackers to cause a denial of service (W3WP process crash and site outage) via a crafted URL, aka "Buffer Overflow Vulnerability."
8256| [CVE-2013-0075] The TCP/IP implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows remote attackers to cause a denial of service (reboot) via a crafted packet that terminates a TCP connection, aka "TCP FIN WAIT Vulnerability."
8257| [CVE-2013-0011] The Print Spooler in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted print job, aka "Windows Print Spooler Components Vulnerability."
8258| [CVE-2013-0007] Microsoft XML Core Services (aka MSXML) 4.0, 5.0, and 6.0 does not properly parse XML content, which allows remote attackers to execute arbitrary code via a crafted web page, aka "MSXML XSLT Vulnerability."
8259| [CVE-2013-0006] Microsoft XML Core Services (aka MSXML) 3.0, 5.0, and 6.0 does not properly parse XML content, which allows remote attackers to execute arbitrary code via a crafted web page, aka "MSXML Integer Truncation Vulnerability."
8260| [CVE-2013-0005] The WCF Replace function in the Open Data (aka OData) protocol implementation in Microsoft .NET Framework 3.5, 3.5 SP1, 3.5.1, and 4, and the Management OData IIS Extension on Windows Server 2012, allows remote attackers to cause a denial of service (resource consumption and daemon restart) via crafted values in HTTP requests, aka "Replace Denial of Service Vulnerability."
8261| [CVE-2013-0003] Buffer overflow in a System.DirectoryServices.Protocols (S.DS.P) namespace method in Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, and 4.5 allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application that leverages a missing array-size check during a memory copy operation, aka "S.DS.P Buffer Overflow Vulnerability."
8262| [CVE-2012-5672] Microsoft Excel Viewer (aka Xlview.exe) and Excel in Microsoft Office 2007 (aka Office 12) allow remote attackers to cause a denial of service (read access violation and application crash) via a crafted spreadsheet file, as demonstrated by a .xls file with battery voltage data.
8263| [CVE-2012-4791] Microsoft Exchange Server 2007 SP3 and 2010 SP1 and SP2 allows remote authenticated users to cause a denial of service (Information Store service hang) by subscribing to a crafted RSS feed, aka "RSS Feed May Cause Exchange DoS Vulnerability."
8264| [CVE-2012-3456] Heap-based buffer overflow in the read function in filters/words/msword-odf/wv2/src/styles.cpp in the Microsoft import filter in Calligra 2.4.3 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted ODF style in an ODF document. NOTE: this is the same vulnerability as CVE-2012-3455, but it was SPLIT by the CNA even though Calligra and KOffice share the same codebase.
8265| [CVE-2012-3455] Heap-based buffer overflow in the read function in filters/words/msword-odf/wv2/src/styles.cpp in the Microsoft import filter in KOffice 2.3.3 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted ODF style in an ODF document. NOTE: this is the same vulnerability as CVE-2012-3456, but it was SPLIT by the CNA even though Calligra and KOffice share the same codebase.
8266| [CVE-2012-2970] The Synel SY-780/A Time & Attendance terminal allows remote attackers to cause a denial of service (device hang) via network traffic to port (1) 1641, (2) 3734, or (3) 3735.
8267| [CVE-2012-2738] The VteTerminal in gnome-terminal (vte) before 0.32.2 allows remote authenticated users to cause a denial of service (long loop and CPU consumption) via an escape sequence with a large repeat count value.
8268| [CVE-2012-2552] Cross-site scripting (XSS) vulnerability in the SQL Server Report Manager in Microsoft SQL Server 2000 Reporting Services SP2 and SQL Server 2005 SP4, 2008 SP2 and SP3, 2008 R2 SP1, and 2012 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka "Reflected XSS Vulnerability."
8269| [CVE-2012-2551] The server in Kerberos in Microsoft Windows Server 2008 R2 and R2 SP1, and Windows 7 Gold and SP1, allows remote attackers to cause a denial of service (NULL pointer dereference and reboot) via a crafted session request, aka "Kerberos NULL Dereference Vulnerability."
8270| [CVE-2012-2550] Microsoft Works 9 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted Word .doc file, aka "Works Heap Vulnerability."
8271| [CVE-2012-2532] Microsoft FTP Service 7.0 and 7.5 for Internet Information Services (IIS) processes unspecified commands before TLS is enabled for a session, which allows remote attackers to obtain sensitive information by reading the replies to these commands, aka "FTP Command Injection Vulnerability."
8272| [CVE-2012-2531] Microsoft Internet Information Services (IIS) 7.5 uses weak permissions for the Operational log, which allows local users to discover credentials by reading this file, aka "Password Disclosure Vulnerability."
8273| [CVE-2012-2524] Microsoft Office 2007 SP2 and SP3 and 2010 SP1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Computer Graphics Metafile (CGM) file, aka "CGM File Format Memory Corruption Vulnerability."
8274| [CVE-2012-2520] Cross-site scripting (XSS) vulnerability in Microsoft InfoPath 2007 SP2 and SP3 and 2010 SP1, Communicator 2007 R2, Lync 2010 and 2010 Attendee, SharePoint Server 2007 SP2 and SP3 and 2010 SP1, Groove Server 2010 SP1, Windows SharePoint Services 3.0 SP2, SharePoint Foundation 2010 SP1, and Office Web Apps 2010 SP1 allows remote attackers to inject arbitrary web script or HTML via a crafted string, aka "HTML Sanitization Vulnerability."
8275| [CVE-2012-2385] The terminal dispatcher in mosh before 1.2.1 allows remote authenticated users to cause a denial of service (long loop and CPU consumption) via an escape sequence with a large repeat count value.
8276| [CVE-2012-1889] Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
8277| [CVE-2012-1863] Cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint Server 2007 SP2 and SP3 Windows SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via crafted JavaScript elements in a URL, aka "SharePoint Reflected List Parameter Vulnerability."
8278| [CVE-2012-1860] Microsoft Office SharePoint Server 2007 SP2 and SP3, SharePoint Server 2010 Gold and SP1, and Office Web Apps 2010 Gold and SP1 do not properly check permissions for search scopes, which allows remote authenticated users to obtain sensitive information or cause a denial of service (data modification) by changing a parameter in a search-scope URL, aka "SharePoint Search Scope Vulnerability."
8279| [CVE-2012-1853] Stack-based buffer overflow in the Remote Administration Protocol (RAP) implementation in the LanmanWorkstation service in Microsoft Windows XP SP3 allows remote attackers to execute arbitrary code via crafted RAP response packets, aka "Remote Administration Protocol Stack Overflow Vulnerability."
8280| [CVE-2012-1852] Heap-based buffer overflow in the Remote Administration Protocol (RAP) implementation in the LanmanWorkstation service in Microsoft Windows XP SP2 and SP3 allows remote attackers to execute arbitrary code via crafted RAP response packets, aka "Remote Administration Protocol Heap Overflow Vulnerability."
8281| [CVE-2012-1851] Format string vulnerability in the Print Spooler service in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted response, aka "Print Spooler Service Format String Vulnerability."
8282| [CVE-2012-1850] The Remote Administration Protocol (RAP) implementation in the LanmanWorkstation service in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle RAP responses, which allows remote attackers to cause a denial of service (service hang) via crafted RAP packets, aka "Remote Administration Protocol Denial of Service Vulnerability."
8283| [CVE-2012-1545] Microsoft Internet Explorer 6 through 9, and 10 Consumer Preview, allows remote attackers to bypass Protected Mode or cause a denial of service (memory corruption) by leveraging access to a Low integrity process, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2012.
8284| [CVE-2012-1194] The resolver in the DNS Server service in Microsoft Windows Server 2008 before R2 overwrites cached server names and TTL values in NS records during the processing of a response to an A record query, which allows remote attackers to trigger continued resolvability of revoked domain names via a "ghost domain names" attack.
8285| [CVE-2012-0183] Microsoft Word 2003 SP3 and 2007 SP2 and SP3, Office 2008 and 2011 for Mac, and Office Compatibility Pack SP2 and SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted RTF data, aka "RTF Mismatch Vulnerability."
8286| [CVE-2012-0164] Microsoft .NET Framework 4 does not properly compare index values, which allows remote attackers to cause a denial of service (application hang) via crafted requests to a Windows Presentation Foundation (WPF) application, aka ".NET Framework Index Comparison Vulnerability."
8287| [CVE-2012-0156] DirectWrite in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly render Unicode characters, which allows remote attackers to cause a denial of service (application hang) via a (1) instant message or (2) web site, aka "DirectWrite Application Denial of Service Vulnerability."
8288| [CVE-2012-0006] The DNS server in Microsoft Windows Server 2003 SP2 and Server 2008 SP2, R2, and R2 SP1 does not properly handle objects in memory during record lookup, which allows remote attackers to cause a denial of service (daemon restart) via a crafted query, aka "DNS Denial of Service Vulnerability."
8289| [CVE-2011-5046] The Graphics Device Interface (GDI) in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly validate user-mode input, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted data, as demonstrated by a large height attribute of an IFRAME element rendered by Safari, aka "GDI Access Violation Vulnerability."
8290| [CVE-2011-3414] The CaseInsensitiveHashProvider.getHashCode function in the HashTable implementation in the ASP.NET subsystem in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters, aka "Collisions in HashTable May Cause DoS Vulnerability."
8291| [CVE-2011-3406] Buffer overflow in Active Directory, Active Directory Application Mode (ADAM), and Active Directory Lightweight Directory Service (AD LDS) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote authenticated users to execute arbitrary code via a crafted query that leverages incorrect memory initialization, aka "Active Directory Buffer Overflow Vulnerability."
8292| [CVE-2011-3260] Buffer overflow in OfficeImport in Apple iOS before 5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Microsoft Word document.
8293| [CVE-2011-2014] The LDAP over SSL (aka LDAPS) implementation in Active Directory, Active Directory Application Mode (ADAM), and Active Directory Lightweight Directory Service (AD LDS) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not examine Certificate Revocation Lists (CRLs), which allows remote authenticated users to bypass intended certificate restrictions and access Active Directory resources by leveraging a revoked X.509 certificate for a domain account, aka "LDAPS Authentication Bypass Vulnerability."
8294| [CVE-2011-2012] Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 does not properly validate session cookies, which allows remote attackers to cause a denial of service (IIS outage) via unspecified network traffic, aka "Null Session Cookie Crash."
8295| [CVE-2011-2008] Microsoft Host Integration Server (HIS) 2004 SP1, 2006 SP1, 2009, and 2010 allows remote attackers to cause a denial of service (SNA Server service outage) via crafted TCP or UDP traffic, aka "Access of Unallocated Memory DoS Vulnerability."
8296| [CVE-2011-2007] Microsoft Host Integration Server (HIS) 2004 SP1, 2006 SP1, 2009, and 2010 allows remote attackers to cause a denial of service (SNA Server service outage) via crafted TCP or UDP traffic, aka "Endless Loop DoS in snabase.exe Vulnerability."
8297| [CVE-2011-2004] Array index error in win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows remote attackers to cause a denial of service (reboot) via a crafted TrueType font file, aka "TrueType Font Parsing Vulnerability," a different vulnerability than CVE-2011-3402.
8298| [CVE-2011-2002] win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle TrueType fonts, which allows local users to cause a denial of service (system hang) via a crafted font file, aka "Win32k TrueType Font Type Translation Vulnerability."
8299| [CVE-2011-1985] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly validate user-mode input, which allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via a crafted application, aka "Win32k Null Pointer De-reference Vulnerability."
8300| [CVE-2011-1974] NDISTAPI.sys in the NDISTAPI driver in Remote Access Service (RAS) in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP2 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "NDISTAPI Elevation of Privilege Vulnerability."
8301| [CVE-2011-1971] The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly parse file metadata, which allows local users to cause a denial of service (reboot) via a crafted file, aka "Windows Kernel Metadata Parsing DOS Vulnerability."
8302| [CVE-2011-1970] The DNS server in Microsoft Windows Server 2003 SP2 and Windows Server 2008 SP2, R2, and R2 SP1 does not properly initialize memory, which allows remote attackers to cause a denial of service (service outage) via a query for a nonexistent domain, aka "DNS Uninitialized Memory Corruption Vulnerability."
8303| [CVE-2011-1968] The Remote Desktop Protocol (RDP) implementation in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP2 does not properly process packets in memory, which allows remote attackers to cause a denial of service (reboot) by sending crafted RDP packets triggering access to an object that (1) was not properly initialized or (2) is deleted, as exploited in the wild in 2011, aka "Remote Desktop Protocol Vulnerability."
8304| [CVE-2011-1965] Tcpip.sys in the TCP/IP stack in Microsoft Windows 7 Gold and SP1 and Windows Server 2008 R2 and R2 SP1 does not properly implement URL-based QoS, which allows remote attackers to cause a denial of service (reboot) via a crafted URL to a web server, aka "TCP/IP QOS Denial of Service Vulnerability."
8305| [CVE-2011-1893] Cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint Server 2010, Windows SharePoint Services 2.0 and 3.0 SP2, and SharePoint Foundation 2010 allows remote attackers to inject arbitrary web script or HTML via the URI, aka "SharePoint XSS Vulnerability."
8306| [CVE-2011-1892] Microsoft Office Groove 2007 SP2, SharePoint Workspace 2010 Gold and SP1, Office Forms Server 2007 SP2, Office SharePoint Server 2007 SP2, Office SharePoint Server 2010 Gold and SP1, Office Groove Data Bridge Server 2007 SP2, Office Groove Management Server 2007 SP2, Groove Server 2010 Gold and SP1, Windows SharePoint Services 3.0 SP2, SharePoint Foundation 2010, and Office Web Apps 2010 Gold and SP1 do not properly handle Web Parts containing XML classes referencing external entities, which allows remote authenticated users to read arbitrary files via a crafted XML and XSL file, aka "SharePoint Remote File Disclosure Vulnerability."
8307| [CVE-2011-1891] Cross-site scripting (XSS) vulnerability in Microsoft Windows SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and SP1, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters in a request to a script, aka "Contact Details Reflected XSS Vulnerability."
8308| [CVE-2011-1889] The NSPLookupServiceNext function in the client in Microsoft Forefront Threat Management Gateway (TMG) 2010 allows remote attackers to execute arbitrary code via vectors involving unspecified requests, aka "TMG Firewall Client Memory Corruption Vulnerability."
8309| [CVE-2011-1872] Hyper-V in Microsoft Windows Server 2008 Gold, SP2, R2, and R2 SP1 allows guest OS users to cause a denial of service (host OS infinite loop) via malformed machine instructions in a VMBus packet, aka "VMBus Persistent DoS Vulnerability."
8310| [CVE-2011-1871] Tcpip.sys in the TCP/IP stack in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to cause a denial of service (reboot) via a series of crafted ICMP messages, aka "ICMP Denial of Service Vulnerability."
8311| [CVE-2011-1870] Integer overflow in the Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, and Windows Server 2003 SP2, allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application that triggers an incorrect memory assignment for a user transaction, aka "CSRSS Local EOP SrvWriteConsoleOutputString Vulnerability."
8312| [CVE-2011-1869] The Distributed File System (DFS) implementation in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote DFS servers to cause a denial of service (system hang) via a crafted referral response, aka "DFS Referral Response Vulnerability."
8313| [CVE-2011-1845] Multiple memory leaks in the DataGrid control implementation in Microsoft Silverlight 4 before 4.0.60310.0 allow remote attackers to cause a denial of service (memory consumption) via an application involving (1) subscriptions to an INotifyDataErrorInfo.ErrorsChanged event or (2) a TextBlock or TextBox element.
8314| [CVE-2011-1844] Memory leak in Microsoft Silverlight 4 before 4.0.60310.0 allows remote attackers to cause a denial of service (memory consumption) via an application involving a popup control and a custom DependencyProperty property, related to lack of garbage collection.
8315| [CVE-2011-1652] ** DISPUTED ** The default configuration of Microsoft Windows 7 immediately prefers a new IPv6 and DHCPv6 service over a currently used IPv4 and DHCPv4 service upon receipt of an IPv6 Router Advertisement (RA), and does not provide an option to ignore an unexpected RA, which allows remote attackers to conduct man-in-the-middle attacks on communication with external IPv4 servers via vectors involving RAs, a DHCPv6 server, and NAT-PT on the local network, aka a "SLAAC Attack." NOTE: it can be argued that preferring IPv6 complies with RFC 3484, and that attempting to determine the legitimacy of an RA is currently outside the scope of recommended behavior of host operating systems.
8316| [CVE-2011-1417] Integer overflow in QuickLook, as used in Apple Mac OS X before 10.6.7 and MobileSafari in Apple iOS before 4.2.7 and 4.3.x before 4.3.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a Microsoft Office document with a crafted size field in the OfficeArtMetafileHeader, related to OfficeArtBlip, as demonstrated on the iPhone by Charlie Miller and Dion Blazakis during a Pwn2Own competition at CanSecWest 2011.
8317| [CVE-2011-1284] Integer overflow in the Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application that triggers an incorrect memory assignment for a user transaction, aka "CSRSS Local EOP SrvWriteConsoleOutput Vulnerability."
8318| [CVE-2011-1283] The Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, and Windows Server 2008 Gold and SP2 does not ensure that an unspecified array index has a non-negative value before performing read and write operations, which allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application that triggers an incorrect memory assignment for a user transaction, aka "CSRSS Local EOP SrvSetConsoleNumberOfCommand Vulnerability."
8319| [CVE-2011-1282] The Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly initialize memory and consequently uses a NULL pointer in an unspecified function call, which allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application that triggers an incorrect memory assignment for a user transaction, aka "CSRSS Local EOP SrvSetConsoleLocalEUDC Vulnerability."
8320| [CVE-2011-1281] The Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly restrict the number of console objects for a process, which allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application that triggers an incorrect memory assignment for a user transaction, aka "CSRSS Local EOP AllocConsole Vulnerability."
8321| [CVE-2011-1279] Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information during parsing of Excel spreadsheets, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted spreadsheet, aka "Excel Out of Bounds WriteAV Vulnerability."
8322| [CVE-2011-1278] Microsoft Excel 2002 SP3 and Office 2004 for Mac do not properly validate record information during parsing of Excel spreadsheets, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted spreadsheet, aka "Excel WriteAV Vulnerability."
8323| [CVE-2011-1277] Microsoft Excel 2002 SP3, Office 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information during parsing of Excel spreadsheets, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted spreadsheet, aka "Excel Memory Corruption Vulnerability."
8324| [CVE-2011-1267] The SMB server in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to cause a denial of service (system hang) via a crafted (1) SMBv1 or (2) SMBv2 request, aka "SMB Request Parsing Vulnerability."
8325| [CVE-2011-1264] Cross-site scripting (XSS) vulnerability in Active Directory Certificate Services Web Enrollment in Microsoft Windows Server 2003 SP2 and Server 2008 Gold, SP2, R2, and R2 SP1 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka "Active Directory Certificate Services Vulnerability."
8326| [CVE-2011-1257] Race condition in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors involving access to an object, aka "Window Open Race Condition Vulnerability."
8327| [CVE-2011-1252] Cross-site scripting (XSS) vulnerability in the SafeHTML function in the toStaticHTML API in Microsoft Internet Explorer 7 and 8, Office SharePoint Server 2007 SP2, Office SharePoint Server 2010 Gold and SP1, Groove Server 2010 Gold and SP1, Windows SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via unspecified strings, aka "toStaticHTML Information Disclosure Vulnerability" or "HTML Sanitization Vulnerability."
8328| [CVE-2011-1248] WINS in Microsoft Windows Server 2003 SP2 and Server 2008 Gold, SP2, R2, and R2 SP1 does not properly handle socket send exceptions, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted packets, related to unintended stack-frame values and buffer passing, aka "WINS Service Failed Response Vulnerability."
8329| [CVE-2011-0661] The SMB Server service in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly validate fields in SMB requests, which allows remote attackers to execute arbitrary code via a malformed request in a (1) SMBv1 or (2) SMBv2 packet, aka "SMB Transaction Parsing Vulnerability."
8330| [CVE-2011-0654] Integer underflow in the BowserWriteErrorLogEntry function in the Common Internet File System (CIFS) browser service in Mrxsmb.sys or bowser.sys in Active Directory in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code or cause a denial of service (system crash) via a malformed BROWSER ELECTION message, leading to a heap-based buffer overflow, aka "Browser Pool Corruption Vulnerability." NOTE: some of these details are obtained from third party information.
8331| [CVE-2011-0647] The irccd.exe service in EMC Replication Manager Client before 5.3 and NetWorker Module for Microsoft Applications 2.1.x and 2.2.x allows remote attackers to execute arbitrary commands via the RunProgram function to TCP port 6542.
8332| [CVE-2011-0627] Adobe Flash Player before 10.3.181.14 on Windows, Mac OS X, Linux, and Solaris and before 10.3.185.21 on Android allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content, as possibly exploited in the wild in May 2011 by a Microsoft Office document with an embedded .swf file.
8333| [CVE-2011-0346] Use-after-free vulnerability in the ReleaseInterface function in MSHTML.DLL in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to the DOM implementation and the BreakAASpecial and BreakCircularMemoryReferences functions, as demonstrated by cross_fuzz, aka "MSHTML Memory Corruption Vulnerability."
8334| [CVE-2011-0290] The BlackBerry Collaboration Service in Research In Motion (RIM) BlackBerry Enterprise Server (BES) 5.0.3 through MR4 for Microsoft Exchange and Lotus Domino allows remote authenticated users to log into arbitrary user accounts associated with the same organization, and send messages, read messages, read contact lists, or cause a denial of service (login unavailability), via unspecified vectors.
8335| [CVE-2011-0208] QuickLook in Apple Mac OS X 10.6 before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Microsoft Office document.
8336| [CVE-2011-0104] Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted HLink record in an Excel file, aka "Excel Buffer Overwrite Vulnerability."
8337| [CVE-2011-0103] Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted record information in an Excel file, aka "Excel Memory Corruption Vulnerability."
8338| [CVE-2011-0101] Microsoft Excel 2002 SP3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted RealTimeData record, related to a stTopic field, doubly-byte characters, and an incorrect pointer calculation, aka "Excel Record Parsing WriteAV Vulnerability."
8339| [CVE-2011-0043] Kerberos in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 supports weak hashing algorithms, which allows local users to gain privileges by operating a service that sends crafted service tickets, as demonstrated by the CRC32 algorithm, aka "Kerberos Unkeyed Checksum Vulnerability."
8340| [CVE-2011-0040] The server in Microsoft Active Directory on Windows Server 2003 SP2 does not properly handle an update request for a service principal name (SPN), which allows remote attackers to cause a denial of service (authentication downgrade or outage) via a crafted request that triggers name collisions, aka "Active Directory SPN Validation Vulnerability."
8341| [CVE-2011-0039] The Local Security Authority Subsystem Service (LSASS) in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly process authentication requests, which allows local users to gain privileges via a request with a crafted length, aka "LSASS Length Validation Vulnerability."
8342| [CVE-2010-4701] Heap-based buffer overflow in the CDrawPoly::Serialize function in fxscover.exe in Microsoft Windows Fax Services Cover Page Editor 5.2 r2 in Windows XP Professional SP3, Server 2003 R2 Enterprise Edition SP2, and Windows 7 Professional allows remote attackers to execute arbitrary code via a long record in a Fax Cover Page (.cov) file. NOTE: some of these details are obtained from third party information.
8343| [CVE-2010-4669] The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Microsoft Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, and Windows 7 allows remote attackers to cause a denial of service (CPU consumption and system hang) by sending many Router Advertisement (RA) messages with different source addresses, as demonstrated by the flood_router6 program in the thc-ipv6 package.
8344| [CVE-2010-4643] Heap-based buffer overflow in Impress in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Truevision TGA (TARGA) file in an ODF or Microsoft Office document.
8345| [CVE-2010-4253] Heap-based buffer overflow in Impress in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file in an ODF or Microsoft Office document, as demonstrated by a PowerPoint (aka PPT) document.
8346| [CVE-2010-3972] Heap-based buffer overflow in the TELNET_STREAM_CONTEXT::OnSendData function in ftpsvc.dll in Microsoft FTP Service 7.0 and 7.5 for Internet Information Services (IIS) 7.0, and IIS 7.5, allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a crafted FTP command, aka "IIS FTP Service Heap Buffer Overrun Vulnerability." NOTE: some of these details are obtained from third party information.
8347| [CVE-2010-3971] Use-after-free vulnerability in the CSharedStyleSheet::Notify function in the Cascading Style Sheets (CSS) parser in mshtml.dll, as used in Microsoft Internet Explorer 6 through 8 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a self-referential @import rule in a stylesheet, aka "CSS Memory Corruption Vulnerability."
8348| [CVE-2010-3964] Unrestricted file upload vulnerability in the Document Conversions Launcher Service in Microsoft Office SharePoint Server 2007 SP2, when the Document Conversions Load Balancer Service is enabled, allows remote attackers to execute arbitrary code via a crafted SOAP request to TCP port 8082, aka "Malformed Request Code Execution Vulnerability."
8349| [CVE-2010-3963] Buffer overflow in the Routing and Remote Access NDProxy component in the kernel in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a crafted application, related to the Routing and Remote Access service (RRAS) and improper copying from user mode to the kernel, aka "Kernel NDProxy Buffer Overflow Vulnerability."
8350| [CVE-2010-3960] Hyper-V in Microsoft Windows Server 2008 Gold, SP2, and R2 allows guest OS users to cause a denial of service (host OS hang) by sending a crafted encapsulated packet over the VMBus, aka "Hyper-V VMBus Vulnerability."
8351| [CVE-2010-3954] Microsoft Publisher 2002 SP3, 2003 SP3, and 2010 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Publisher file, aka "Microsoft Publisher Memory Corruption Vulnerability."
8352| [CVE-2010-3952] The FlashPix image converter in the graphics filters in Microsoft Office XP SP3 and Office Converter Pack allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted FlashPix image in an Office document, aka "FlashPix Image Converter Heap Corruption Vulnerability."
8353| [CVE-2010-3950] The TIFF image converter in the graphics filters in Microsoft Office XP SP3, Office Converter Pack, and Works 9 does not properly convert data, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted TIFF image in an Office document, aka "TIFF Image Converter Memory Corruption Vulnerability."
8354| [CVE-2010-3937] Microsoft Exchange Server 2007 SP2 on the x64 platform allows remote authenticated users to cause a denial of service (infinite loop and MSExchangeIS outage) via a crafted RPC request, aka "Exchange Server Infinite Loop Vulnerability."
8355| [CVE-2010-3785] Buffer overflow in QuickLook in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Microsoft Office document.
8356| [CVE-2010-3454] Multiple off-by-one errors in the WW8DopTypography::ReadFromMem function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted typography information in a Microsoft Word .DOC file that triggers an out-of-bounds write.
8357| [CVE-2010-3453] The WW8ListManager::WW8ListManager function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 does not properly handle an unspecified number of list levels in user-defined list styles in WW8 data in a Microsoft Word document, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted .DOC file that triggers an out-of-bounds write.
8358| [CVE-2010-3332] Microsoft .NET Framework 1.1 SP1, 2.0 SP1 and SP2, 3.5, 3.5 SP1, 3.5.1, and 4.0, as used for ASP.NET in Microsoft Internet Information Services (IIS), provides detailed error codes during decryption attempts, which allows remote attackers to decrypt and modify encrypted View State (aka __VIEWSTATE) form data, and possibly forge cookies or read application files, via a padding oracle attack, aka "ASP.NET Padding Oracle Vulnerability."
8359| [CVE-2010-3324] The toStaticHTML function in Microsoft Internet Explorer 8, and the SafeHTML function in Microsoft Windows SharePoint Services 3.0 SP2, SharePoint Foundation 2010, Office SharePoint Server 2007 SP2, Groove Server 2010, and Office Web Apps, allows remote attackers to bypass the cross-site scripting (XSS) protection mechanism and conduct XSS attacks via a crafted use of the Cascading Style Sheets (CSS) @import rule, aka "HTML Sanitization Vulnerability," a different vulnerability than CVE-2010-1257.
8360| [CVE-2010-3243] Cross-site scripting (XSS) vulnerability in the toStaticHTML function in Microsoft Internet Explorer 8, and the SafeHTML function in Microsoft Windows SharePoint Services 3.0 SP2 and Office SharePoint Server 2007 SP2, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "HTML Sanitization Vulnerability."
8361| [CVE-2010-3229] The Secure Channel (aka SChannel) security package in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, when IIS 7.x is used, does not properly process client certificates during SSL and TLS handshakes, which allows remote attackers to cause a denial of service (LSASS outage and reboot) via a crafted packet, aka "TLSv1 Denial of Service Vulnerability."
8362| [CVE-2010-3225] Use-after-free vulnerability in the Media Player Network Sharing Service in Microsoft Windows Vista SP1 and SP2 and Windows 7 allows remote attackers to execute arbitrary code via a crafted Real Time Streaming Protocol (RTSP) packet, aka "RTSP Use After Free Vulnerability."
8363| [CVE-2010-3223] The user interface in Microsoft Cluster Service (MSCS) in Microsoft Windows Server 2008 R2 does not properly set administrative-share permissions for new cluster disks that are shared as part of a failover cluster, which allows remote attackers to read or modify data on these disks via requests to the associated share, aka "Permissions on New Cluster Disks Vulnerability."
8364| [CVE-2010-3200] MSO.dll in Microsoft Word 2003 SP3 11.8326.11.8324 allows remote attackers to cause a denial of service (NULL pointer dereference and multiple-instance application crash) via a crafted buffer in a Word document, as demonstrated by word_crash_11.8326.8324_poc.doc.
8365| [CVE-2010-2742] The Netlogon RPC Service in Microsoft Windows Server 2003 SP2 and Server 2008 Gold, SP2, and R2, when the domain controller role is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and reboot) via a crafted RPC packet, aka "Netlogon RPC Null dereference DOS Vulnerability."
8366| [CVE-2010-2739] Buffer overflow in the CreateDIBPalette function in win32k.sys in Microsoft Windows XP SP3, Server 2003 R2 Enterprise SP2, Vista Business SP1, Windows 7, and Server 2008 SP2 allows local users to cause a denial of service (crash) and possibly execute arbitrary code by performing a clipboard operation (GetClipboardData API function) with a crafted bitmap with a palette that contains a large number of colors.
8367| [CVE-2010-2731] Unspecified vulnerability in Microsoft Internet Information Services (IIS) 5.1 on Windows XP SP3, when directory-based Basic Authentication is enabled, allows remote attackers to bypass intended access restrictions and execute ASP files via a crafted request, aka "Directory Authentication Bypass Vulnerability."
8368| [CVE-2010-2730] Buffer overflow in Microsoft Internet Information Services (IIS) 7.5, when FastCGI is enabled, allows remote attackers to execute arbitrary code via crafted headers in a request, aka "Request Header Buffer Overflow Vulnerability."
8369| [CVE-2010-2729] The Print Spooler service in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, when printer sharing is enabled, does not properly validate spooler access permissions, which allows remote attackers to create files in a system directory, and consequently execute arbitrary code, by sending a crafted print request over RPC, as exploited in the wild in September 2010, aka "Print Spooler Service Impersonation Vulnerability."
8370| [CVE-2010-2569] pubconv.dll (aka the Publisher Converter DLL) in Microsoft Publisher 2002 SP3, 2003 SP3, and 2007 SP2 does not properly handle an unspecified size field in certain older file formats, which allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted Publisher file, aka "Size Value Heap Corruption in pubconv.dll Vulnerability."
8371| [CVE-2010-2564] Buffer overflow in Microsoft Windows Movie Maker (WMM) 2.1, 2.6, and 6.0 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted project file, aka "Movie Maker Memory Corruption Vulnerability."
8372| [CVE-2010-2562] Microsoft Office Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Excel file, aka "Excel Memory Corruption Vulnerability."
8373| [CVE-2010-2561] Microsoft XML Core Services (aka MSXML) 3.0 does not properly handle HTTP responses, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted response, aka "Msxml2.XMLHTTP.3.0 Response Handling Memory Corruption Vulnerability."
8374| [CVE-2010-2558] Race condition in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors related to an object in memory, aka "Race Condition Memory Corruption Vulnerability."
8375| [CVE-2010-2555] The Tracing Feature for Services in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly determine the length of strings in the registry, which allows local users to gain privileges or cause a denial of service (memory corruption) via vectors involving a long string, aka "Tracing Memory Corruption Vulnerability."
8376| [CVE-2010-2554] The Tracing Feature for Services in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 has incorrect ACLs on its registry keys, which allows local users to gain privileges via vectors involving a named pipe and impersonation, aka "Tracing Registry Key ACL Vulnerability."
8377| [CVE-2010-2552] Stack consumption vulnerability in the SMB Server in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows remote attackers to cause a denial of service (system hang) via a malformed SMBv2 compounded request, aka "SMB Stack Exhaustion Vulnerability."
8378| [CVE-2010-2551] The SMB Server in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate an internal variable in an SMB packet, which allows remote attackers to cause a denial of service (system hang) via a crafted (1) SMBv1 or (2) SMBv2 packet, aka "SMB Variable Validation Vulnerability."
8379| [CVE-2010-2549] Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Vista SP1 and SP2 and Server 2008 Gold and SP2 allows local users to gain privileges or cause a denial of service (system crash) by using a large number of calls to the NtUserCheckAccessForIntegrityLevel function to trigger a failure in the LockProcessByClientId function, leading to deletion of an in-use process object, aka "Win32k Reference Count Vulnerability."
8380| [CVE-2010-2119] Microsoft Internet Explorer 6.0.2900.2180 allows remote attackers to cause a denial of service (resource consumption) via JavaScript code containing an infinite loop that creates IFRAME elements for invalid nntp:// URIs.
8381| [CVE-2010-2118] Microsoft Internet Explorer 6.0.2900.2180 and 8.0.7600.16385 allows remote attackers to cause a denial of service (resource consumption) via JavaScript code containing an infinite loop that creates IFRAME elements for invalid news:// URIs.
8382| [CVE-2010-1991] Microsoft Internet Explorer 6.0.2900.2180, 7, and 8.0.7600.16385 executes a mail application in situations where an IFRAME element has a mailto: URL in its SRC attribute, which allows remote attackers to cause a denial of service (excessive application launches) via an HTML document with many IFRAME elements.
8383| [CVE-2010-1903] Microsoft Office Word 2002 SP3 and 2003 SP3, and Office Word Viewer, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a malformed record in a Word file, aka "Word HTML Linked Objects Memory Corruption Vulnerability."
8384| [CVE-2010-1899] Stack consumption vulnerability in the ASP implementation in Microsoft Internet Information Services (IIS) 5.1, 6.0, 7.0, and 7.5 allows remote attackers to cause a denial of service (daemon outage) via a crafted request, related to asp.dll, aka "IIS Repeated Parameter Request Denial of Service Vulnerability."
8385| [CVE-2010-1892] The TCP/IP stack in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly handle malformed IPv6 packets, which allows remote attackers to cause a denial of service (system hang) via multiple crafted packets, aka "IPv6 Memory Corruption Vulnerability."
8386| [CVE-2010-1890] The kernel in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate ACLs on kernel objects, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Improper Validation Vulnerability."
8387| [CVE-2010-1887] The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 do not properly validate an unspecified system-call argument, which allows local users to cause a denial of service (system hang) via a crafted application, aka "Win32k Bounds Checking Vulnerability."
8388| [CVE-2010-1886] Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 SP2 and R2, and Windows 7 allow local users to gain privileges by leveraging access to a process with NetworkService credentials, as demonstrated by TAPI Server, SQL Server, and IIS processes, and related to the Windows Service Isolation feature. NOTE: the vendor states that privilege escalation from NetworkService to LocalSystem does not cross a "security boundary."
8389| [CVE-2010-1881] The FieldList ActiveX control in the Microsoft Access Wizard Controls in ACCWIZ.dll in Microsoft Office Access 2003 SP3 does not properly interact with the memory-access approach used by Internet Explorer and Office during instantiation, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via an HTML document that references this control along with crafted persistent storage data, aka "ACCWIZ.dll Uninitialized Variable Vulnerability."
8390| [CVE-2010-1847] The kernel in Apple Mac OS X 10.6.x before 10.6.5 does not properly perform memory management associated with terminal devices, which allows local users to cause a denial of service (system crash) via unspecified vectors.
8391| [CVE-2010-1735] The SfnLOGONNOTIFY function in win32k.sys in the kernel in Microsoft Windows 2000, XP, and Server 2003 allows local users to cause a denial of service (system crash) via a 0x4c value in the second argument (aka the Msg argument) of a PostMessage function call for the DDEMLEvent window.
8392| [CVE-2010-1734] The SfnINSTRING function in win32k.sys in the kernel in Microsoft Windows 2000, XP, and Server 2003 allows local users to cause a denial of service (system crash) via a 0x18d value in the second argument (aka the Msg argument) of a PostMessage function call for the DDEMLEvent window.
8393| [CVE-2010-1264] Unspecified vulnerability in Microsoft Windows SharePoint Services 3.0 SP1 and SP2 allows remote attackers to cause a denial of service (hang) via crafted requests to the Help page that cause repeated restarts of the application pool, aka "Sharepoint Help Page Denial of Service Vulnerability."
8394| [CVE-2010-1127] Microsoft Internet Explorer 6 and 7 does not initialize certain data structures during execution of the createElement method, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted JavaScript code, as demonstrated by setting the (1) outerHTML or (2) value property of an object returned by createElement.
8395| [CVE-2010-1098] The ANI parser in Microsoft Windows before 7 on the x86 platform, as used in Internet Explorer and other applications, allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted biClrUsed value in the BITMAPINFO header of a .ANI file.
8396| [CVE-2010-1042] Microsoft Windows Media Player 11 does not properly perform colorspace conversion, which allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted .AVI file. NOTE: the provenance of this information is unknown
8397| [CVE-2010-0820] Heap-based buffer overflow in the Local Security Authority Subsystem Service (LSASS), as used in Active Directory in Microsoft Windows Server 2003 SP2 and Windows Server 2008 Gold, SP2, and R2
8398| [CVE-2010-0817] Cross-site scripting (XSS) vulnerability in _layouts/help.aspx in Microsoft SharePoint Server 2007 12.0.0.6421 and possibly earlier, and SharePoint Services 3.0 SP1 and SP2, versions, allows remote attackers to inject arbitrary web script or HTML via the cid0 parameter.
8399| [CVE-2010-0810] The kernel in Microsoft Windows Vista Gold, SP1, and SP2, and Windows Server 2008 Gold and SP2, does not properly handle unspecified exceptions, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Exception Handler Vulnerability."
8400| [CVE-2010-0719] An unspecified API in Microsoft Windows 2000, Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, and Windows 7 does not validate arguments, which allows local users to cause a denial of service (system crash) via a crafted application.
8401| [CVE-2010-0718] Buffer overflow in Microsoft Windows Media Player 9 and 11.0.5721.5145 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted .mpg file.
8402| [CVE-2010-0482] The kernel in Microsoft Windows Server 2008 R2 and Windows 7 does not properly validate relocation sections of image files, which allows local users to cause a denial of service (reboot) via a crafted file, aka "Windows Kernel Malformed Image Vulnerability."
8403| [CVE-2010-0481] The kernel in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly translate a registry key's virtual path to its real path, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Virtual Path Parsing Vulnerability."
8404| [CVE-2010-0478] Stack-based buffer overflow in nsum.exe in the Windows Media Unicast Service in Media Services for Microsoft Windows 2000 Server SP4 allows remote attackers to execute arbitrary code via crafted packets associated with transport information, aka "Media Services Stack-based Buffer Overflow Vulnerability."
8405| [CVE-2010-0476] The SMB client in Microsoft Windows Server 2003 SP2, Vista Gold, SP1, and SP2, and Windows Server 2008 Gold and SP2 allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and reboot) via a crafted SMB transaction response that uses (1) SMBv1 or (2) SMBv2, aka "SMB Client Response Parsing Vulnerability."
8406| [CVE-2010-0278] A certain ActiveX control in msgsc.14.0.8089.726.dll in Microsoft Windows Live Messenger 2009 build 14.0.8089.726 on Windows Vista and Windows 7 allows remote attackers to cause a denial of service (msnmsgr.exe crash) by calling the ViewProfile method with a crafted argument during an MSN Messenger session.
8407| [CVE-2010-0270] The SMB client in Microsoft Windows Server 2008 R2 and Windows 7 does not properly validate fields in SMB transaction responses, which allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and reboot) via a crafted (1) SMBv1 or (2) SMBv2 response, aka "SMB Client Transaction Vulnerability."
8408| [CVE-2010-0242] The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 allows remote attackers to cause a denial of service (system hang) via crafted packets with malformed TCP selective acknowledgement (SACK) values, aka "TCP/IP Selective Acknowledgement Vulnerability."
8409| [CVE-2010-0238] Unspecified vulnerability in registry-key validation in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Vista Gold allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Registry Key Vulnerability."
8410| [CVE-2010-0235] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Vista Gold does not perform the expected validation before creating a symbolic link, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Symbolic Link Value Vulnerability."
8411| [CVE-2010-0234] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 does not properly validate a registry-key argument to an unspecified system call, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Null Pointer Vulnerability."
8412| [CVE-2010-0231] The SMB implementation in the Server service in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not use a sufficient source of entropy, which allows remote attackers to obtain access to files and other SMB resources via a large number of authentication requests, related to server-generated challenges, certain "duplicate values," and spoofing of an authentication token, aka "SMB NTLM Authentication Lack of Entropy Vulnerability."
8413| [CVE-2010-0035] The Key Distribution Center (KDC) in Kerberos in Microsoft Windows 2000 SP4, Server 2003 SP2, and Server 2008 Gold and SP2, when a trust relationship with a non-Windows Kerberos realm exists, allows remote authenticated users to cause a denial of service (NULL pointer dereference and domain controller outage) via a crafted Ticket Granting Ticket (TGT) renewal request, aka "Kerberos Null Pointer Dereference Vulnerability."
8414| [CVE-2010-0026] The Hyper-V server implementation in Microsoft Windows Server 2008 Gold, SP2, and R2 on the x64 platform allows guest OS users to cause a denial of service (host OS hang) via a crafted application that executes a malformed series of machine instructions, aka "Hyper-V Instruction Set Validation Vulnerability."
8415| [CVE-2010-0024] The SMTP component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Server 2008 Gold, SP2, and R2, and Exchange Server 2003 SP2, does not properly parse MX records, which allows remote DNS servers to cause a denial of service (service outage) via a crafted response to a DNS MX record query, aka "SMTP Server MX Record Vulnerability."
8416| [CVE-2010-0022] The SMB implementation in the Server service in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate the share and servername fields in SMB packets, which allows remote attackers to cause a denial of service (system hang) via a crafted packet, aka "SMB Null Pointer Vulnerability."
8417| [CVE-2010-0021] Multiple race conditions in the SMB implementation in the Server service in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allow remote attackers to cause a denial of service (system hang) via a crafted (1) SMBv1 or (2) SMBv2 Negotiate packet, aka "SMB Memory Corruption Vulnerability."
8418| [CVE-2010-0020] The SMB implementation in the Server service in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate request fields, which allows remote authenticated users to execute arbitrary code via a malformed request, aka "SMB Pathname Overflow Vulnerability."
8419| [CVE-2010-0019] Microsoft Silverlight 3 before 3.0.50611.0 on Windows, and before 3.0.41130.0 on Mac OS X, does not properly handle pointers, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and framework outage) via a crafted web site, aka "Microsoft Silverlight Memory Corruption Vulnerability."
8420| [CVE-2009-4445] Microsoft Internet Information Services (IIS), when used in conjunction with unspecified third-party upload applications, allows remote attackers to create empty files with arbitrary extensions via a filename containing an initial extension followed by a : (colon) and a safe extension, as demonstrated by an upload of a .asp:.jpg file that results in creation of an empty .asp file, related to support for the NTFS Alternate Data Streams (ADS) filename syntax. NOTE: it could be argued that this is a vulnerability in the third-party product, not IIS, because the third-party product should be applying its extension restrictions to the portion of the filename before the colon.
8421| [CVE-2009-4444] Microsoft Internet Information Services (IIS) 5.x and 6.x uses only the portion of a filename before a
8422| [CVE-2009-4313] ir32_32.dll 3.24.15.3 in the Indeo32 codec in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to cause a denial of service (heap corruption) or execute arbitrary code via malformed data in a stream in a media file, as demonstrated by an AVI file.
8423| [CVE-2009-4210] The Indeo codec in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via crafted media content.
8424| [CVE-2009-3943] Microsoft Internet Explorer 6 through 6.0.2900.2180 and 7 through 7.0.6000.16711 allows remote attackers to cause a denial of service (application hang) via a JavaScript loop that configures the home page by using the setHomePage method and a DHTML behavior property.
8425| [CVE-2009-3830] The download functionality in Team Services in Microsoft Office SharePoint Server 2007 12.0.0.4518 and 12.0.0.6219 allows remote attackers to read ASP.NET source code via pathnames in the SourceUrl and Source parameters to _layouts/download.aspx.
8426| [CVE-2009-3678] Integer overflow in cdd.dll in the Canonical Display Driver (CDD) in Microsoft Windows Server 2008 R2 and Windows 7 on 64-bit platforms, when the Windows Aero theme is installed, allows context-dependent attackers to cause a denial of service (reboot) or possibly execute arbitrary code via a crafted image file that triggers incorrect data parsing after user-mode data is copied to kernel mode, as demonstrated using "Browse with Irfanview" and certain actions on a folder containing a large number of thumbnail images in Resample mode, possibly related to the ATI graphics driver or win32k.sys, aka "Canonical Display Driver Integer Overflow Vulnerability."
8427| [CVE-2009-3677] The Internet Authentication Service (IAS) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold and SP1, and Server 2008 Gold does not properly verify the credentials in an MS-CHAP v2 Protected Extensible Authentication Protocol (PEAP) authentication request, which allows remote attackers to access network resources via a malformed request, aka "MS-CHAP Authentication Bypass Vulnerability."
8428| [CVE-2009-3676] The SMB client in the kernel in Microsoft Windows Server 2008 R2 and Windows 7 allows remote SMB servers and man-in-the-middle attackers to cause a denial of service (infinite loop and system hang) via a (1) SMBv1 or (2) SMBv2 response packet that contains (a) an incorrect length value in a NetBIOS header or (b) an additional length field at the end of this response packet, aka "SMB Client Incomplete Response Vulnerability."
8429| [CVE-2009-3675] LSASS.exe in the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote authenticated users to cause a denial of service (CPU consumption) via a malformed ISAKMP request over IPsec, aka "Local Security Authority Subsystem Service Resource Exhaustion Vulnerability."
8430| [CVE-2009-3555] The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate renegotiation handshakes with an existing connection, which allows man-in-the-middle attackers to insert data into HTTPS sessions, and possibly other types of sessions protected by TLS or SSL, by sending an unauthenticated request that is processed retroactively by a server in a post-renegotiation context, related to a "plaintext injection" attack, aka the "Project Mogul" issue.
8431| [CVE-2009-3294] The popen API function in TSRM/tsrm_win32.c in PHP before 5.2.11 and 5.3.x before 5.3.1, when running on certain Windows operating systems, allows context-dependent attackers to cause a denial of service (crash) via a crafted (1) "e" or (2) "er" string in the second argument (aka mode), possibly related to the _fdopen function in the Microsoft C runtime library. NOTE: this might not cross privilege boundaries except in rare cases in which the mode argument is accessible to an attacker outside of an application that uses the popen function.
8432| [CVE-2009-3275] Blocks/Common/Src/Configuration/Manageability/Adm/AdmContentBuilder.cs in Microsoft patterns & practices Enterprise Library (aka EntLib) allows context-dependent attackers to cause a denial of service (CPU consumption) via an input string composed of many \ (backslash) characters followed by a " (double quote), related to a certain regular expression, aka a "ReDoS" vulnerability.
8433| [CVE-2009-3270] Microsoft Internet Explorer 7 through 7.0.6000.16711 allows remote attackers to cause a denial of service (unusable browser) by calling the window.print function in a loop, aka a "printing DoS attack," possibly a related issue to CVE-2009-0821.
8434| [CVE-2009-3267] Microsoft Internet Explorer 6 through 6.0.2900.2180, and 7.0.6000.16711, allows remote attackers to cause a denial of service (CPU consumption) via an automatically submitted form containing a KEYGEN element, a related issue to CVE-2009-1828.
8435| [CVE-2009-3126] Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a crafted PNG image file, aka "GDI+ PNG Integer Overflow Vulnerability."
8436| [CVE-2009-3103] Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, and Windows 7 RC allows remote attackers to execute arbitrary code or cause a denial of service (system crash) via an & (ampersand) character in a Process ID High header field in a NEGOTIATE PROTOCOL REQUEST packet, which triggers an attempted dereference of an out-of-bounds memory location, aka "SMBv2 Negotiation Vulnerability." NOTE: some of these details are obtained from third party information.
8437| [CVE-2009-3043] The tty_ldisc_hangup function in drivers/char/tty_ldisc.c in the Linux kernel 2.6.31-rc before 2.6.31-rc8 allows local users to cause a denial of service (system crash, sometimes preceded by a NULL pointer dereference) or possibly gain privileges via certain pseudo-terminal I/O activity, as demonstrated by KernelTtyTest.c.
8438| [CVE-2009-3023] Buffer overflow in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 6.0 allows remote authenticated users to execute arbitrary code via a crafted NLST (NAME LIST) command that uses wildcards, leading to memory corruption, aka "IIS FTP Service RCE and DoS Vulnerability."
8439| [CVE-2009-3020] win32k.sys in Microsoft Windows Server 2003 SP2 allows remote attackers to cause a denial of service (system crash) by referencing a crafted .eot file in the src descriptor of an @font-face Cascading Style Sheets (CSS) rule in an HTML document, possibly related to the Embedded OpenType (EOT) Font Engine, a different vulnerability than CVE-2006-0010, CVE-2009-0231, and CVE-2009-0232. NOTE: some of these details are obtained from third party information.
8440| [CVE-2009-3019] Microsoft Internet Explorer 6 on Windows XP SP2 and SP3, and Internet Explorer 7 on Vista, allows remote attackers to cause a denial of service (application crash) via JavaScript code that calls createElement to create an instance of the LI element, and then calls setAttribute to set the value attribute.
8441| [CVE-2009-2954] Microsoft Internet Explorer 6.0.2900.2180 and earlier allows remote attackers to cause a denial of service (CPU consumption and application hang) via JavaScript code with a long string value for the hash property (aka location.hash), a related issue to CVE-2008-5715.
8442| [CVE-2009-2838] Integer overflow in QuickLook in Apple Mac OS X 10.5.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Microsoft Office document that triggers a buffer overflow.
8443| [CVE-2009-2764] Microsoft Internet Explorer 8.0.7100.0 on Windows 7 RC on the x64 platform allows remote attackers to cause a denial of service (application crash) via a certain DIV element in conjunction with SCRIPT elements that have empty contents and no reference to a valid external script location.
8444| [CVE-2009-2668] Microsoft Internet Explorer 6 through 6.0.2900.2180 and 7 through 7.0.6000.16473 allows remote attackers to cause a denial of service (CPU consumption) via an XML document composed of a long series of start-tags with no corresponding end-tags, a related issue to CVE-2009-1232.
8445| [CVE-2009-2655] mshtml.dll in Microsoft Internet Explorer 7 and 8 on Windows XP SP3 allows remote attackers to cause a denial of service (application crash) by calling the JavaScript findText method with a crafted Unicode string in the first argument, and only one additional argument, as demonstrated by a second argument of -1.
8446| [CVE-2009-2576] Microsoft Internet Explorer 6.0.2900.2180 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via a long Unicode string argument to the write method, a related issue to CVE-2009-2479. NOTE: it was later reported that 7.0.6000.16473 and earlier are also affected.
8447| [CVE-2009-2536] Microsoft Internet Explorer 5 through 8 allows remote attackers to cause a denial of service (memory consumption and application crash) via a large integer value for the length property of a Select object, a related issue to CVE-2009-1692.
8448| [CVE-2009-2532] Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, and Windows 7 RC do not properly process the command value in an SMB Multi-Protocol Negotiate Request packet, which allows remote attackers to execute arbitrary code via a crafted SMBv2 packet to the Server service, aka "SMBv2 Command Value Vulnerability."
8449| [CVE-2009-2526] Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 do not properly validate fields in SMBv2 packets, which allows remote attackers to cause a denial of service (infinite loop and system hang) via a crafted packet to the Server service, aka "SMBv2 Infinite Loop Vulnerability."
8450| [CVE-2009-2524] Integer underflow in the NTLM authentication feature in the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows remote attackers to cause a denial of service (reboot) via a malformed packet, aka "Local Security Authority Subsystem Service Integer Overflow Vulnerability."
8451| [CVE-2009-2521] Stack consumption vulnerability in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 7.0 allows remote authenticated users to cause a denial of service (daemon crash) via a list (ls) -R command containing a wildcard that references a subdirectory, followed by a .. (dot dot), aka "IIS FTP Service DoS Vulnerability."
8452| [CVE-2009-2517] The kernel in Microsoft Windows Server 2003 SP2 does not properly handle unspecified exceptions when an error condition occurs, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Exception Handler Vulnerability."
8453| [CVE-2009-2509] Active Directory Federation Services (ADFS) in Microsoft Windows Server 2003 SP2 and Server 2008 Gold and SP2 does not properly validate headers in HTTP requests, which allows remote authenticated users to execute arbitrary code via a crafted request to an IIS web server, aka "Remote Code Execution in ADFS Vulnerability."
8454| [CVE-2009-2508] The single sign-on implementation in Active Directory Federation Services (ADFS) in Microsoft Windows Server 2003 SP2 and Server 2008 Gold and SP2 does not properly remove credentials at the end of a network session, which allows physically proximate attackers to obtain the credentials of a previous user of the same web browser by using data from the browser's cache, aka "Single Sign On Spoofing in ADFS Vulnerability."
8455| [CVE-2009-2507] A certain ActiveX control in the Indexing Service in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly process URLs, which allows remote attackers to execute arbitrary programs via unspecified vectors that cause a "vulnerable binary" to load and run, aka "Memory Corruption in Indexing Service Vulnerability."
8456| [CVE-2009-2505] The Internet Authentication Service (IAS) in Microsoft Windows Vista SP2 and Server 2008 SP2 does not properly validate MS-CHAP v2 Protected Extensible Authentication Protocol (PEAP) authentication requests, which allows remote attackers to execute arbitrary code via crafted structures in a malformed request, aka "Internet Authentication Service Memory Corruption Vulnerability."
8457| [CVE-2009-2504] Multiple integer overflows in unspecified APIs in GDI+ in Microsoft .NET Framework 1.1 SP1, .NET Framework 2.0 SP1 and SP2, Windows XP SP2 and SP3, Windows Server 2003 SP2, Vista Gold and SP1, Server 2008 Gold, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allow remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "GDI+ .NET API Vulnerability."
8458| [CVE-2009-2503] GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Windows Server 2003 SP2, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 does not properly allocate an unspecified buffer, which allows remote attackers to execute arbitrary code via a crafted TIFF image file that triggers memory corruption, aka "GDI+ TIFF Memory Corruption Vulnerability."
8459| [CVE-2009-2502] Buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a crafted TIFF image file, aka "GDI+ TIFF Buffer Overflow Vulnerability."
8460| [CVE-2009-2501] Heap-based buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a crafted PNG image file, aka "GDI+ PNG Heap Overflow Vulnerability."
8461| [CVE-2009-2500] Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a crafted WMF image file, aka "GDI+ WMF Integer Overflow Vulnerability."
8462| [CVE-2009-2498] Microsoft Windows Media Format Runtime 9.0, 9.5, and 11 and Windows Media Services 9.1 and 2008 do not properly parse malformed headers in Advanced Systems Format (ASF) files, which allows remote attackers to execute arbitrary code via a crafted (1) .asf, (2) .wmv, or (3) .wma file, aka "Windows Media Header Parsing Invalid Free Vulnerability."
8463| [CVE-2009-2484] Stack-based buffer overflow in the Win32AddConnection function in modules/access/smb.c in VideoLAN VLC media player 0.9.9, when running on Microsoft Windows, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long smb URI in a playlist file.
8464| [CVE-2009-2433] Stack-based buffer overflow in the AddFavorite method in Microsoft Internet Explorer allows remote attackers to cause a denial of service (application crash) and possibly have unspecified other impact via a long URL in the first argument.
8465| [CVE-2009-1930] The Telnet service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote Telnet servers to execute arbitrary code on a client machine by replaying the NTLM credentials of a client user, aka "Telnet Credential Reflection Vulnerability," a related issue to CVE-2000-0834.
8466| [CVE-2009-1928] Stack consumption vulnerability in the LDAP service in Active Directory on Microsoft Windows 2000 SP4, Server 2003 SP2, and Server 2008 Gold and SP2
8467| [CVE-2009-1926] Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allow remote attackers to cause a denial of service (TCP outage) via a series of TCP sessions that have pending data and a (1) small or (2) zero receive window size, and remain in the FIN-WAIT-1 or FIN-WAIT-2 state indefinitely, aka "TCP/IP Orphaned Connections Vulnerability."
8468| [CVE-2009-1925] The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 does not properly manage state information, which allows remote attackers to execute arbitrary code by sending packets to a listening service, and thereby triggering misinterpretation of an unspecified field as a function pointer, aka "TCP/IP Timestamps Code Execution Vulnerability."
8469| [CVE-2009-1924] Integer overflow in the Windows Internet Name Service (WINS) component for Microsoft Windows 2000 SP4 allows remote WINS replication partners to execute arbitrary code via crafted data structures in a packet, aka "WINS Integer Overflow Vulnerability."
8470| [CVE-2009-1923] Heap-based buffer overflow in the Windows Internet Name Service (WINS) component for Microsoft Windows 2000 SP4 and Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted WINS replication packet that triggers an incorrect buffer-length calculation, aka "WINS Heap Overflow Vulnerability."
8471| [CVE-2009-1922] The Message Queuing (aka MSMQ) service for Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP2, and Vista Gold does not properly validate unspecified IOCTL request data from user mode before passing this data to kernel mode, which allows local users to gain privileges via a crafted request, aka "MSMQ Null Pointer Vulnerability."
8472| [CVE-2009-1808] Microsoft Windows XP SP3 allows local users to cause a denial of service (system crash) by making an SPI_SETDESKWALLPAPER SystemParametersInfo call with an improperly terminated pvParam argument, followed by an SPI_GETDESKWALLPAPER SystemParametersInfo call.
8473| [CVE-2009-1717] Integer overflow in Terminal in Apple Mac OS X 10.5 before 10.5.7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted size value in a CSI[4 xterm resize escape sequence that triggers a heap-based buffer overflow.
8474| [CVE-2009-1546] Integer overflow in Avifil32.dll in the Windows Media file handling functionality in Microsoft Windows allows remote attackers to execute arbitrary code on a Windows 2000 SP4 system via a crafted AVI file, or cause a denial of service on a Windows XP SP2 or SP3, Server 2003 SP2, Vista Gold, SP1, or SP2, or Server 2008 Gold or SP2 system via a crafted AVI file, aka "AVI Integer Overflow Vulnerability."
8475| [CVE-2009-1544] Double free vulnerability in the Workstation service in Microsoft Windows allows remote authenticated users to gain privileges via a crafted RPC message to a Windows XP SP2 or SP3 or Server 2003 SP2 system, or cause a denial of service via a crafted RPC message to a Vista Gold, SP1, or SP2 or Server 2008 Gold or SP2 system, aka "Workstation Service Memory Corruption Vulnerability."
8476| [CVE-2009-1536] ASP.NET in Microsoft .NET Framework 2.0 SP1 and SP2 and 3.5 Gold and SP1, when ASP 2.0 is used in integrated mode on IIS 7.0, does not properly manage request scheduling, which allows remote attackers to cause a denial of service (daemon outage) via a series of crafted HTTP requests, aka "Remote Unauthenticated Denial of Service in ASP.NET Vulnerability."
8477| [CVE-2009-1535] The WebDAV extension in Microsoft Internet Information Services (IIS) 5.1 and 6.0 allows remote attackers to bypass URI-based protection mechanisms, and list folders or read, create, or modify files, via a %c0%af (Unicode / character) at an arbitrary position in the URI, as demonstrated by inserting %c0%af into a "/protected/" initial pathname component to bypass the password protection on the protected\ folder, aka "IIS 5.1 and 6.0 WebDAV Authentication Bypass Vulnerability," a different vulnerability than CVE-2009-1122.
8478| [CVE-2009-1511] GDI+ in Microsoft Windows XP SP3 allows remote attackers to cause a denial of service (infinite loop) via a PNG file that contains a certain large btChunkLen value.
8479| [CVE-2009-1335] Microsoft Internet Explorer 7 and 8 on Windows XP and Vista allows remote attackers to cause a denial of service (application hang) via a large document composed of unprintable characters, aka MSRC 9011jr.
8480| [CVE-2009-1331] Integer overflow in Microsoft Windows Media Player (WMP) 11.0.5721.5260 allows remote attackers to cause a denial of service (application crash) via a crafted .mid file, as demonstrated by crash.mid.
8481| [CVE-2009-1217] Off-by-one error in the GpFont::SetData function in gdiplus.dll in Microsoft GDI+ on Windows XP allows remote attackers to cause a denial of service (stack corruption and application termination) via a crafted EMF file that triggers an integer overflow, as demonstrated by voltage-exploit.emf, aka the "Microsoft GdiPlus EMF GpFont.SetData integer overflow."
8482| [CVE-2009-1216] Multiple unspecified vulnerabilities in (1) unlzh.c and (2) unpack.c in the gzip libraries in Microsoft Windows Server 2008, Windows Services for UNIX 3.0 and 3.5, and the Subsystem for UNIX-based Applications (SUA)
8483| [CVE-2009-1139] Memory leak in the LDAP service in Active Directory on Microsoft Windows 2000 SP4 and Server 2003 SP2, and Active Directory Application Mode (ADAM) on Windows XP SP2 and SP3 and Server 2003 SP2, allows remote attackers to cause a denial of service (memory consumption and service outage) via (1) LDAP or (2) LDAPS requests with unspecified OID filters, aka "Active Directory Memory Leak Vulnerability."
8484| [CVE-2009-1138] The LDAP service in Active Directory on Microsoft Windows 2000 SP4 does not properly free memory for LDAP and LDAPS requests, which allows remote attackers to execute arbitrary code via a request that uses hexadecimal encoding, whose associated memory is not released, related to a "DN AttributeValue," aka "Active Directory Invalid Free Vulnerability." NOTE: this issue is probably a memory leak.
8485| [CVE-2009-1132] Heap-based buffer overflow in the Wireless LAN AutoConfig Service (aka Wlansvc) in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a malformed wireless frame, aka "Wireless Frame Parsing Remote Code Execution Vulnerability."
8486| [CVE-2009-1122] The WebDAV extension in Microsoft Internet Information Services (IIS) 5.0 on Windows 2000 SP4 does not properly decode URLs, which allows remote attackers to bypass authentication, and possibly read or create files, via a crafted HTTP request, aka "IIS 5.0 WebDAV Authentication Bypass Vulnerability," a different vulnerability than CVE-2009-1535.
8487| [CVE-2009-0944] The Microsoft Office Spotlight Importer in Spotlight in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 does not properly validate Microsoft Office files, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a file that triggers memory corruption.
8488| [CVE-2009-0550] Windows HTTP Services (aka WinHTTP) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008
8489| [CVE-2009-0537] Integer overflow in the fts_build function in fts.c in libc in (1) OpenBSD 4.4 and earlier and (2) Microsoft Interix 6.0 build 10.0.6030.0 allows context-dependent attackers to cause a denial of service (application crash) via a deep directory tree, related to the fts_level structure member, as demonstrated by (a) du, (b) rm, (c) chmod, and (d) chgrp on OpenBSD
8490| [CVE-2009-0419] Microsoft XML Core Services, as used in Microsoft Expression Web, Office, Internet Explorer 6 and 7, and other products, does not properly restrict access from web pages to Set-Cookie2 HTTP response headers, which allows remote attackers to obtain sensitive information from cookies via XMLHttpRequest calls, related to the HTTPOnly protection mechanism. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2008-4033.
8491| [CVE-2009-0268] Race condition in the pseudo-terminal (aka pty) driver module in Sun Solaris 8 through 10, and OpenSolaris before snv_103, allows local users to cause a denial of service (panic) via unspecified vectors related to lack of "properly sequenced code" in ptc and ptsl.
8492| [CVE-2009-0244] Directory traversal vulnerability in the OBEX FTP Service in the Microsoft Bluetooth stack in Windows Mobile 6 Professional, and probably Windows Mobile 5.0 for Pocket PC and 5.0 for Pocket PC Phone Edition, allows remote authenticated users to list arbitrary directories, and create or read arbitrary files, via a .. (dot dot) in a pathname. NOTE: this can be leveraged for code execution by writing to a Startup folder.
8493| [CVE-2009-0234] The DNS Resolver Cache Service (aka DNSCache) in Windows DNS Server in Microsoft Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008 does not properly cache crafted DNS responses, which makes it easier for remote attackers to predict transaction IDs and poison caches by sending many crafted DNS queries that trigger "unnecessary lookups," aka "DNS Server Response Validation Vulnerability."
8494| [CVE-2009-0233] The DNS Resolver Cache Service (aka DNSCache) in Windows DNS Server in Microsoft Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008, when dynamic updates are enabled, does not reuse cached DNS responses in all applicable situations, which makes it easier for remote attackers to predict transaction IDs and poison caches by simultaneously sending crafted DNS queries and responses, aka "DNS Server Query Validation Vulnerability."
8495| [CVE-2009-0229] The Windows Printing Service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 allows local users to read arbitrary files via a crafted separator page, aka "Print Spooler Read File Vulnerability."
8496| [CVE-2009-0228] Stack-based buffer overflow in the EnumeratePrintShares function in Windows Print Spooler Service (win32spl.dll) in Microsoft Windows 2000 SP4 allows remote printer servers to execute arbitrary code via a a crafted ShareName in a response to an RPC request, related to "printing data structures," aka "Buffer Overflow in Print Spooler Vulnerability."
8497| [CVE-2009-0119] Buffer overflow in Microsoft Windows XP SP3 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted .chm file.
8498| [CVE-2009-0099] The Electronic Messaging System Microsoft Data Base (EMSMDB32) provider in Microsoft Exchange 2000 Server SP3 and Exchange Server 2003 SP2, as used in Exchange System Attendant, allows remote attackers to cause a denial of service (application outage) via a malformed MAPI command, aka "Literal Processing Vulnerability."
8499| [CVE-2009-0089] Windows HTTP Services (aka WinHTTP) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, and Vista Gold allows remote web servers to impersonate arbitrary https web sites by using DNS spoofing to "forward a connection" to a different https web site that has a valid certificate matching its own domain name, but not a certificate matching the domain name of the host requested by the user, aka "Windows HTTP Services Certificate Name Mismatch Vulnerability."
8500| [CVE-2009-0086] Integer underflow in Windows HTTP Services (aka WinHTTP) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote HTTP servers to execute arbitrary code via crafted parameter values in a response, related to error handling, aka "Windows HTTP Services Integer Underflow Vulnerability."
8501| [CVE-2009-0079] The RPCSS service in Microsoft Windows XP SP2 and SP3 and Server 2003 SP1 and SP2 does not properly implement isolation among a set of distinct processes that (1) all run under the NetworkService account or (2) all run under the LocalService account, which allows local users to gain privileges by accessing the resources of one of the processes, aka "Windows RPCSS Service Isolation Vulnerability."
8502| [CVE-2009-0078] The Windows Management Instrumentation (WMI) provider in Microsoft Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly implement isolation among a set of distinct processes that (1) all run under the NetworkService account or (2) all run under the LocalService account, which allows local users to gain privileges by accessing the resources of one of the processes, aka "Windows WMI Service Isolation Vulnerability."
8503| [CVE-2009-0072] Microsoft Internet Explorer 6.0 through 8.0 beta2 allows remote attackers to cause a denial of service (application crash) via an onload=screen[""] attribute value in a BODY element.
8504| [CVE-2008-7106] The installation of Sophos PureMessage for Microsoft Exchange 3.0 before 3.0.2, when both anti-virus and anti-spam are supported, does not create or launch the associated scan engines when the system is under heavy load, which has unspecified impact, probably remote bypass of scanner protection or a denial of service (message loss or delay).
8505| [CVE-2008-7105] Sophos PureMessage for Microsoft Exchange 3.0 before 3.0.2 allows remote attackers to cause a denial of service (EdgeTransport.exe termination) via a TNEF-encoded message with a crafted rich text body that is not properly handled during conversion to plain text. NOTE: this might be related to CVE-2008-7104.
8506| [CVE-2008-7104] Sophos PureMessage Scanner service (PMScanner.exe) in PureMessage for Microsoft Exchange 3.0 before 3.0.2 allows remote attackers to cause a denial of service (message queue delay and incomplete spam rule update) via a crafted (1) RTF or (2) PDF file.
8507| [CVE-2008-6819] win32k.sys in Microsoft Windows Server 2003 and Vista allows local users to cause a denial of service (system crash) via vectors related to CreateWindow, TranslateMessage, and DispatchMessage, possibly a race condition between threads, a different vulnerability than CVE-2008-1084. NOTE: some of these details are obtained from third party information.
8508| [CVE-2008-6219] nsrexecd.exe in multiple EMC Networker products including EMC NetWorker Server, Storage Node, and Client 7.3.x and 7.4, 7.4.1, 7.4.2, Client and Storage Node for Open VMS 7.3.2 ECO6 and earlier, Module for Microsoft Exchange 5.1 and earlier, Module for Microsoft Applications 2.0 and earlier, Module for Meditech 2.0 and earlier, and PowerSnap 2.4 SP1 and earlier does not properly control the allocation of memory, which allows remote attackers to cause a denial of service (memory exhaustion) via multiple crafted RPC requests.
8509| [CVE-2008-6194] Memory leak in the DNS server in Microsoft Windows allows remote attackers to cause a denial of service (memory consumption) via DNS packets. NOTE: this issue reportedly exists because of an incorrect fix for CVE-2007-3898.
8510| [CVE-2008-5823] An ActiveX control in prtstb06.dll in Microsoft Money 2006, when used with WScript in Windows Script Host (WSH) on Windows Vista, allows remote attackers to cause a denial of service (access violation and application crash) via a zero value for the Startup property.
8511| [CVE-2008-5745] Integer overflow in quartz.dll in the DirectShow framework in Microsoft Windows Media Player (WMP) 9, 10, and 11, including 11.0.5721.5260, allows remote attackers to cause a denial of service (application crash) via a crafted (1) WAV, (2) SND, or (3) MID file. NOTE: this has been incorrectly reported as a code-execution vulnerability. NOTE: it is not clear whether this issue is related to CVE-2008-4927.
8512| [CVE-2008-5232] Buffer overflow in the CallHTMLHelp method in the Microsoft Windows Media Services ActiveX control in nskey.dll 4.1.00.3917 in Windows Media Services on Microsoft Windows NT and 2000, and Avaya Media and Message Application servers, allows remote attackers to execute arbitrary code via a long argument. NOTE: the provenance of this information is unknown
8513| [CVE-2008-5229] Stack-based buffer overflow in Microsoft Device IO Control in iphlpapi.dll in Microsoft Windows Vista Gold and SP1 allows local users in the Network Configuration Operator group to gain privileges or cause a denial of service (system crash) via a large invalid PrefixLength to the CreateIpForwardEntry2 method, as demonstrated by a "route add" command. NOTE: this issue might not cross privilege boundaries.
8514| [CVE-2008-5181] Microsoft Communicator allows remote attackers to cause a denial of service (application or device outage) via instant messages containing large numbers of emoticons.
8515| [CVE-2008-5180] Microsoft Communicator, and Communicator in Microsoft Office 2010 beta, allows remote attackers to cause a denial of service (memory consumption) via a large number of SIP INVITE requests, which trigger the creation of many sessions.
8516| [CVE-2008-5179] Unspecified vulnerability in Microsoft Office Communications Server (OCS), Office Communicator, and Windows Live Messenger allows remote attackers to cause a denial of service (crash) via a crafted Real-time Transport Control Protocol (RTCP) receiver report packet.
8517| [CVE-2008-5044] Race condition in Microsoft Windows Server 2003 and Vista allows local users to cause a denial of service (crash or hang) via a multi-threaded application that makes many calls to UnhookWindowsHookEx while certain other desktop activity is occurring.
8518| [CVE-2008-4927] Microsoft Windows Media Player (WMP) 9.0 through 11 allows user-assisted attackers to cause a denial of service (application crash) via a malformed (1) MIDI or (2) DAT file, related to "MThd Header Parsing." NOTE: the provenance of this information is unknown
8519| [CVE-2008-4835] SMB in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to execute arbitrary code via malformed values of unspecified "fields inside the SMB packets" in an NT Trans2 request, related to "insufficiently validating the buffer size," aka "SMB Validation Remote Code Execution Vulnerability."
8520| [CVE-2008-4834] Buffer overflow in SMB in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via malformed values of unspecified "fields inside the SMB packets" in an NT Trans request, aka "SMB Buffer Overflow Remote Code Execution Vulnerability."
8521| [CVE-2008-4800] The DebugDiag ActiveX control in CrashHangExt.dll, possibly 1.0, in Microsoft Debug Diagnostic Tool allows remote attackers to cause a denial of service (NULL pointer dereference and Internet Explorer 6.0 crash) via a large negative integer argument to the GetEntryPointForThread method. NOTE: this issue might only be exploitable in limited environments or non-default browser settings.
8522| [CVE-2008-4609] The TCP implementation in (1) Linux, (2) platforms based on BSD Unix, (3) Microsoft Windows, (4) Cisco products, and probably other operating systems allows remote attackers to cause a denial of service (connection queue exhaustion) via multiple vectors that manipulate information in the TCP state table, as demonstrated by sockstress.
8523| [CVE-2008-4544] Unspecified vulnerability in an unspecified Microsoft API, as used by Cisco Unity and possibly other products, allows remote attackers to cause a denial of service by sending crafted packets to dynamic UDP ports, related to a "processing error."
8524| [CVE-2008-4510] Microsoft Windows Vista Home and Ultimate Edition SP1 and earlier allows local users to cause a denial of service (page fault and system crash) via multiple attempts to access a virtual address in a PAGE_NOACCESS memory page.
8525| [CVE-2008-4381] Microsoft Internet Explorer 7 allows remote attackers to cause a denial of service (application crash) via Javascript that calls the alert function with a URL-encoded string of a large number of invalid characters.
8526| [CVE-2008-4327] gdiplus.dll in GDI+ in Microsoft Windows XP SP3 does not properly handle crafted .ico files, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a certain crash.ico file on a web site, and allows user-assisted attackers to cause a denial of service (divide-by-zero error and persistent application crash) via this crash.ico file on the desktop, a different vulnerability than CVE-2007-2237.
8527| [CVE-2008-4323] Windows Explorer in Microsoft Windows XP SP3 allows user-assisted attackers to cause a denial of service (application crash) via a crafted .ZIP file.
8528| [CVE-2008-4301] ** DISPUTED ** A certain ActiveX control in iisext.dll in Microsoft Internet Information Services (IIS) allows remote attackers to set a password via a string argument to the SetPassword method. NOTE: this issue could not be reproduced by a reliable third party. In addition, the original researcher is unreliable. Therefore the original disclosure is probably erroneous.
8529| [CVE-2008-4300] A certain ActiveX control in adsiis.dll in Microsoft Internet Information Services (IIS) allows remote attackers to cause a denial of service (browser crash) via a long string in the second argument to the GetObject method. NOTE: this issue was disclosed by an unreliable researcher, so it might be incorrect.
8530| [CVE-2008-4299] A certain ActiveX control in the Microsoft Internet Authentication Service (IAS) Helper COM Component in iashlpr.dll allows remote attackers to cause a denial of service (browser crash) via a large integer value in the first argument to the PutProperty method. NOTE: this issue was disclosed by an unreliable researcher, so it might be incorrect.
8531| [CVE-2008-4295] Microsoft Windows Mobile 6.0 on HTC Wiza 200 and HTC MDA 8125 devices does not properly handle the first attempt to establish a Bluetooth connection to a peer with a long name, which allows remote attackers to cause a denial of service (device reboot) by configuring a Bluetooth device with a long hci name and (1) connecting directly to the Windows Mobile system or (2) waiting for the Windows Mobile system to scan for nearby devices.
8532| [CVE-2008-4250] The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitrary code via a crafted RPC request that triggers the overflow during path canonicalization, as exploited in the wild by Gimmiv.A in October 2008, aka "Server Service Vulnerability."
8533| [CVE-2008-4211] Integer signedness error in (1) QuickLook in Apple Mac OS X 10.5.5 and (2) Office Viewer in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via a crafted Microsoft Excel file that triggers an out-of-bounds memory access, related to "handling of columns."
8534| [CVE-2008-4127] Mshtml.dll in Microsoft Internet Explorer 7 Gold 7.0.5730 and 8 Beta 8.0.6001 on Windows XP SP2 allows remote attackers to cause a denial of service (failure of subsequent image rendering) via a crafted PNG file, related to an infinite loop in the CDwnTaskExec::ThreadExec function.
8535| [CVE-2008-4114] srv.sys in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to cause a denial of service (system crash) or possibly have unspecified other impact via an SMB WRITE_ANDX packet with an offset that is inconsistent with the packet size, related to "insufficiently validating the buffer size," as demonstrated by a request to the \PIPE\lsarpc named pipe, aka "SMB Validation Denial of Service Vulnerability."
8536| [CVE-2008-4110] Buffer overflow in the SQLVDIRLib.SQLVDirControl ActiveX control in Tools\Binn\sqlvdir.dll in Microsoft SQL Server 2000 (aka SQL Server 8.0) allows remote attackers to cause a denial of service (browser crash) or possibly execute arbitrary code via a long URL in the second argument to the Connect method. NOTE: this issue is not a vulnerability in many environments, since the control is not marked as safe for scripting and would not execute with default Internet Explorer settings.
8537| [CVE-2008-4071] A certain ActiveX control in Adobe Acrobat 9, when used with Microsoft Windows Vista and Internet Explorer 7, allows remote attackers to cause a denial of service (browser crash) via an src property value with an invalid acroie:// URL.
8538| [CVE-2008-4033] Cross-domain vulnerability in Microsoft XML Core Services 3.0 through 6.0, as used in Microsoft Expression Web, Office, Internet Explorer, and other products, allows remote attackers to obtain sensitive information from another domain and corrupt the session state via HTTP request header fields, as demonstrated by the Transfer-Encoding field, aka "MSXML Header Request Vulnerability."
8539| [CVE-2008-4032] Microsoft Office SharePoint Server 2007 Gold and SP1 and Microsoft Search Server 2008 do not properly perform authentication and authorization for administrative functions, which allows remote attackers to cause a denial of service (server load), obtain sensitive information, and "create scripts that would run in the context of the site" via requests to administrative URIs, aka "Access Control Vulnerability."
8540| [CVE-2008-4029] Cross-domain vulnerability in Microsoft XML Core Services 3.0 and 4.0, as used in Internet Explorer, allows remote attackers to obtain sensitive information from another domain via a crafted XML document, related to improper error checks for external DTDs, aka "MSXML DTD Cross-Domain Scripting Vulnerability."
8541| [CVE-2008-3956] orgchart.exe in Microsoft Organization Chart 2.00 allows user-assisted attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted .opx file.
8542| [CVE-2008-3479] Heap-based buffer overflow in the Microsoft Message Queuing (MSMQ) service (mqsvc.exe) in Microsoft Windows 2000 SP4 allows remote attackers to read memory contents and execute arbitrary code via a crafted RPC call, related to improper processing of parameters to string APIs, aka "Message Queuing Service Remote Code Execution Vulnerability."
8543| [CVE-2008-3465] Heap-based buffer overflow in an API in GDI in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows context-dependent attackers to cause a denial of service or execute arbitrary code via a WMF file with a malformed file-size parameter, which would not be properly handled by a third-party application that uses this API for a copy operation, aka "GDI Heap Overflow Vulnerability."
8544| [CVE-2008-3015] Integer overflow in gdiplus.dll in GDI+ in Microsoft Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a BMP image file with a malformed BitMapInfoHeader that triggers a buffer overflow, aka "GDI+ BMP Integer Overflow Vulnerability."
8545| [CVE-2008-3014] Buffer overflow in gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a malformed WMF image file that triggers improper memory allocation, aka "GDI+ WMF Buffer Overrun Vulnerability."
8546| [CVE-2008-3013] gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a malformed GIF image file containing many extension markers for graphic control extensions and subsequent unknown labels, aka "GDI+ GIF Parsing Vulnerability."
8547| [CVE-2008-3012] gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 does not properly perform memory allocation, which allows remote attackers to execute arbitrary code via a malformed EMF image file, aka "GDI+ EMF Memory Corruption Vulnerability."
8548| [CVE-2008-3010] Microsoft Windows Media Player 6.4, Windows Media Format Runtime 7.1 through 11, and Windows Media Services 4.1 and 9 incorrectly associate ISATAP addresses with the Local Intranet zone, which allows remote servers to capture NTLM credentials, and execute arbitrary code through credential-reflection attacks, by sending an authentication request, aka "ISATAP Vulnerability."
8549| [CVE-2008-3009] Microsoft Windows Media Player 6.4, Windows Media Format Runtime 7.1 through 11, and Windows Media Services 4.1, 9, and 2008 do not properly use the Service Principal Name (SPN) identifier when validating replies to authentication requests, which allows remote servers to execute arbitrary code via vectors that employ NTLM credential reflection, aka "SPN Vulnerability."
8550| [CVE-2008-2752] Microsoft Word 2000 9.0.2812 and 2003 11.8106.8172 does not properly handle unordered lists, which allows user-assisted remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted .doc file. NOTE: some of these details are obtained from third party information.
8551| [CVE-2008-2325] QuickLook in Apple Mac OS X 10.4.11 and 10.5.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Microsoft Office file, related to insufficient "bounds checking."
8552| [CVE-2008-2258] Microsoft Internet Explorer 5.01, 6, and 7 accesses uninitialized memory in certain conditions, which allows remote attackers to cause a denial of service (crash) and execute arbitrary code via vectors related to a document object "appended in a specific order" with "particular functions ... performed on" document objects, aka "HTML Objects Memory Corruption Vulnerability" or "Table Layout Memory Corruption Vulnerability," a different vulnerability than CVE-2008-2257.
8553| [CVE-2008-2257] Microsoft Internet Explorer 5.01, 6, and 7 accesses uninitialized memory in certain conditions, which allows remote attackers to cause a denial of service (crash) and execute arbitrary code via vectors related to a document object "appended in a specific order," aka "HTML Objects Memory Corruption Vulnerability" or "XHTML Rendering Memory Corruption Vulnerability," a different vulnerability than CVE-2008-2258.
8554| [CVE-2008-2256] Microsoft Internet Explorer 5.01, 6, and 7 does not properly handle objects that have been incorrectly initialized or deleted, which allows remote attackers to cause a denial of service (crash) and execute arbitrary code via unknown vectors, aka "Uninitialized Memory Corruption Vulnerability."
8555| [CVE-2008-2255] Microsoft Internet Explorer 5.01, 6, and 7 accesses uninitialized memory, which allows remote attackers to cause a denial of service (crash) and execute arbitrary code via unknown vectors, a different vulnerability than CVE-2008-2254, aka "HTML Object Memory Corruption Vulnerability."
8556| [CVE-2008-2254] Microsoft Internet Explorer 6 and 7 accesses uninitialized memory, which allows remote attackers to cause a denial of service (crash) and execute arbitrary code via unknown vectors, aka "HTML Object Memory Corruption Vulnerability."
8557| [CVE-2008-1898] A certain ActiveX control in WkImgSrv.dll 7.03.0616.0, as distributed in Microsoft Works 7 and Microsoft Office 2003 and 2007, allows remote attackers to execute arbitrary code or cause a denial of service (browser crash) via an invalid WksPictureInterface property value, which triggers an improper function call.
8558| [CVE-2008-1888] Cross-site scripting (XSS) vulnerability in Microsoft Windows SharePoint Services 2.0 allows remote attackers to inject arbitrary web script or HTML via the Picture Source (aka picture object source) field in the Rich Text Editor.
8559| [CVE-2008-1453] The Bluetooth stack in Microsoft Windows XP SP2 and SP3, and Vista Gold and SP1, allows physically proximate attackers to execute arbitrary code via a large series of Service Discovery Protocol (SDP) packets.
8560| [CVE-2008-1451] The WINS service on Microsoft Windows 2000 SP4, and Server 2003 SP1 and SP2, does not properly validate data structures in WINS network packets, which allows local users to gain privileges via a crafted packet, aka "Memory Overwrite Vulnerability."
8561| [CVE-2008-1446] Integer overflow in the Internet Printing Protocol (IPP) ISAPI extension in Microsoft Internet Information Services (IIS) 5.0 through 7.0 on Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, and Server 2008 allows remote authenticated users to execute arbitrary code via an HTTP POST request that triggers an outbound IPP connection from a web server to a machine operated by the attacker, aka "Integer Overflow in IPP Service Vulnerability."
8562| [CVE-2008-1445] Active Directory on Microsoft Windows 2000 Server SP4, XP Professional SP2 and SP3, Server 2003 SP1 and SP2, and Server 2008 allows remote authenticated users to cause a denial of service (system hang or reboot) via a crafted LDAP request.
8563| [CVE-2008-1441] Microsoft Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to cause a denial of service (system hang) via a series of Pragmatic General Multicast (PGM) packets with invalid fragment options, aka the "PGM Malformed Fragment Vulnerability."
8564| [CVE-2008-1440] Microsoft Windows XP SP2 and SP3, and Server 2003 SP1 and SP2, does not properly validate the option length field in Pragmatic General Multicast (PGM) packets, which allows remote attackers to cause a denial of service (infinite loop and system hang) via a crafted PGM packet, aka the "PGM Invalid Length Vulnerability."
8565| [CVE-2008-1438] Unspecified vulnerability in Microsoft Malware Protection Engine (mpengine.dll) 1.1.3520.0 and 0.1.13.192, as used in multiple Microsoft products, allows context-dependent attackers to cause a denial of service (disk space exhaustion) via a file with "crafted data structures" that trigger the creation of large temporary files, a different vulnerability than CVE-2008-1437.
8566| [CVE-2008-1437] Unspecified vulnerability in Microsoft Malware Protection Engine (mpengine.dll) 1.1.3520.0 and 0.1.13.192, as used in multiple Microsoft products, allows context-dependent attackers to cause a denial of service (engine hang and restart) via a crafted file, a different vulnerability than CVE-2008-1438.
8567| [CVE-2008-1436] Microsoft Windows XP Professional SP2, Vista, and Server 2003 and 2008 does not properly assign activities to the (1) NetworkService and (2) LocalService accounts, which might allow context-dependent attackers to gain privileges by using one service process to capture a resource from a second service process that has a LocalSystem privilege-escalation ability, related to improper management of the SeImpersonatePrivilege user right, as originally reported for Internet Information Services (IIS), aka Token Kidnapping.
8568| [CVE-2008-1088] Microsoft Project 2000 Service Release 1, 2002 SP1, and 2003 SP2 allows user-assisted remote attackers to execute arbitrary code via a crafted Project file, related to improper validation of "memory resource allocations."
8569| [CVE-2008-0088] Unspecified vulnerability in Active Directory on Microsoft Windows 2000 and Windows Server 2003, and Active Directory Application Mode (ADAM) on XP and Server 2003, allows remote attackers to cause a denial of service (hang and restart) via a crafted LDAP request.
8570| [CVE-2008-0084] Unspecified vulnerability in the TCP/IP support in Microsoft Windows Vista allows remote DHCP servers to cause a denial of service (hang and restart) via a crafted DHCP packet.
8571| [CVE-2008-0075] Unspecified vulnerability in Microsoft Internet Information Services (IIS) 5.1 through 6.0 allows remote attackers to execute arbitrary code via crafted inputs to ASP pages.
8572| [CVE-2008-0074] Unspecified vulnerability in Microsoft Internet Information Services (IIS) 5.0 through 7.0 allows local users to gain privileges via unknown vectors related to file change notifications in the TPRoot, NNTPFile\Root, or WWWRoot folders.
8573| [CVE-2007-6534] Multiple unspecified vulnerabilities in Microsoft Office Publisher allow user-assisted remote attackers to cause a denial of service (application crash) via a crafted PUB file, possibly involving wordart.
8574| [CVE-2007-6236] Microsoft Windows Media Player (WMP) allows remote attackers to cause a denial of service (application crash) via a certain AIFF file that triggers a divide-by-zero error, as demonstrated by kr.aiff.
8575| [CVE-2007-5861] Unspecified vulnerability in Spotlight in Apple Mac OS X 10.4.11 allows user-assisted attackers to cause a denial of service (application termination) or execute arbitrary code via a crafted .XLS file that triggers memory corruption in the Microsoft Office Spotlight Importer.
8576| [CVE-2007-5634] Speedfan.sys in Alfredo Milani Comparetti SpeedFan 4.33, when used on Microsoft Windows Vista x64, does not properly check a buffer during an IOCTL 0x9c402420 call, which allows local users to cause a denial of service (machine crash) and possibly gain privileges via unspecified vectors.
8577| [CVE-2007-5352] Unspecified vulnerability in Local Security Authority Subsystem Service (LSASS) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2 allows local users to gain privileges via a crafted local procedure call (LPC) request.
8578| [CVE-2007-5348] Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via an image file with crafted gradient sizes in gradient fill input, which triggers a heap-based buffer overflow related to GdiPlus.dll and VGX.DLL, aka "GDI+ VML Buffer Overrun Vulnerability."
8579| [CVE-2007-5145] Multiple buffer overflows in system DLL files in Microsoft Windows XP, as used by Microsoft Windows Explorer (explorer.exe) 6.00.2900.2180, Don Ho Notepad++, unspecified Adobe Macromedia applications, and other programs, allow user-assisted remote attackers to cause a denial of service (application crash) via long strings in the (1) author, (2) title, (3) subject, and (4) comment Properties fields of a file, possibly involving improper handling of extended file attributes by the (a) NtQueryInformationFile, (b) NtQueryDirectoryFile, (c) NtSetInformationFile, (d) FileAllInformation, (e) FileNameInformation, and other FILE_INFORMATION_CLASS functions in ntdll.dll and the (f) GetFileAttributesExW and (g) GetFileAttributesW functions in kernel32.dll, a related issue to CVE-2007-1347.
8580| [CVE-2007-5133] Microsoft Windows Explorer (explorer.exe) allows user-assisted remote attackers to cause a denial of service (CPU consumption) via a certain PNG file with a large tEXt chunk that possibly triggers an integer overflow in PNG chunk size handling, as demonstrated by badlycrafted.png.
8581| [CVE-2007-4916] Heap-based buffer overflow in the FileFind::FindFile method in (1) MFC42.dll, (2) MFC42u.dll, (3) MFC71.dll, and (4) MFC71u.dll in Microsoft Foundation Class (MFC) Library 8.0, as used by the ListFiles method in hpqutil.dll 2.0.0.138 in Hewlett-Packard (HP) All-in-One and Photo & Imaging Gallery 1.1 and probably other products, allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long first argument.
8582| [CVE-2007-4288] Microsoft Windows Media Player 11 (wmplayer.exe) allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted .au file that triggers a divide-by-zero error, as demonstrated by iapetus.au.
8583| [CVE-2007-4247] Windows Calendar on Microsoft Windows Vista allows remote attackers to cause a denial of service (NULL dereference and persistent application crash) via a malformed ICS file.
8584| [CVE-2007-4227] Microsoft Windows Explorer (explorer.exe) allows user-assisted remote attackers to cause a denial of service via a certain JPG file, as demonstrated by something.jpg. NOTE: this issue might be related to CVE-2007-3958.
8585| [CVE-2007-4036] ** DISPUTED ** Guidance Software EnCase allows user-assisted remote attackers to cause a denial of service via (1) a corrupted Microsoft Exchange database, which triggers an application crash when many options are selected
8586| [CVE-2007-3958] Microsoft Windows Explorer (explorer.exe) allows user-assisted remote attackers to cause a denial of service via a certain GIF file, as demonstrated by Art.gif.
8587| [CVE-2007-3724] The process scheduler in the Microsoft Windows XP kernel does not make use of the process statistics kept by the kernel, performs scheduling based on CPU billing gathered from periodic process sampling ticks, and gives preference to "interactive" processes that perform voluntary sleeps, which allows local users to cause a denial of service (CPU consumption), as described in "Secretly Monopolizing the CPU Without Superuser Privileges."
8588| [CVE-2007-3658] Unspecified vulnerability in Microsoft Register Server (REGSVR) allows attackers to cause a denial of service via a crafted DLL library.
8589| [CVE-2007-3550] ** DISPUTED ** Microsoft Internet Explorer 6.0 and 7.0 allows remote attackers to fill Zones with arbitrary domains using certain metacharacters such as wildcards via JavaScript, which results in a denial of service (website suppression and resource consumption), aka "Internet Explorer Zone Domain Specification Dos and Page Suppressing". NOTE: this issue has been disputed by a third party, who states that the zone settings cannot be manipulated.
8590| [CVE-2007-3436] Microsoft MSN Messenger 4.7 on Windows XP allows remote attackers to cause a denial of service (resource consumption) via a flood of SIP INVITE requests to the port specified for voice conversation.
8591| [CVE-2007-3282] Buffer overflow in the Microsoft Office MSODataSourceControl ActiveX object allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long argument to the DeleteRecordSourceIfUnused method.
8592| [CVE-2007-3040] Stack-based buffer overflow in agentdpv.dll 2.0.0.3425 in Microsoft Agent on Windows 2000 SP4 allows remote attackers to execute arbitrary code via a crafted URL to the Agent (Agent.Control) ActiveX control, which triggers an overflow within the Agent Service (agentsrv.exe) process, a different issue than CVE-2007-1205.
8593| [CVE-2007-3039] Stack-based buffer overflow in the Microsoft Message Queuing (MSMQ) service in Microsoft Windows 2000 Server SP4, Windows 2000 Professional SP4, and Windows XP SP2 allows attackers to execute arbitrary code via a long string in an opnum 0x06 RPC call to port 2103. NOTE: this is remotely exploitable on Windows 2000 Server.
8594| [CVE-2007-3036] Unspecified vulnerability in the (1) Windows Services for UNIX 3.0 and 3.5, and (2) Subsystem for UNIX-based Applications in Microsoft Windows 2000, XP, Server 2003, and Vista allows local users to gain privileges via unspecified vectors related to "certain setuid binary files."
8595| [CVE-2007-3028] The LDAP service in Windows Active Directory in Microsoft Windows 2000 Server SP4 does not properly check "the number of convertible attributes", which allows remote attackers to cause a denial of service (service unavailability) via a crafted LDAP request, related to "client sent LDAP request logic," aka "Windows Active Directory Denial of Service Vulnerability". NOTE: this is probably a different issue than CVE-2007-0040.
8596| [CVE-2007-2967] Multiple F-Secure anti-virus products for Microsoft Windows and Linux before 20070522 allow remote attackers to cause a denial of service (file scanning infinite loop) via certain crafted (1) ARJ archives or (2) FSG packed files.
8597| [CVE-2007-2966] Buffer overflow in the LHA decompresion component in F-Secure anti-virus products for Microsoft Windows and Linux before 20070529 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted LHA archive, related to an integer wrap, a similar issue to CVE-2006-4335.
8598| [CVE-2007-2903] Buffer overflow in the HelpPopup method in the Microsoft Office 2000 Controllo UA di Microsoft Office ActiveX control (OUACTRL.OCX) 1.0.1.9 allows remote attackers to cause a denial of service (probably winhlp32.exe crash) via a long first argument. NOTE: it is not clear whether this issue crosses privilege boundaries.
8599| [CVE-2007-2897] Microsoft Internet Information Services (IIS) 6.0 allows remote attackers to cause a denial of service (server instability or device hang), and possibly obtain sensitive information (device communication traffic)
8600| [CVE-2007-2885] The NotSafe function in the MSVDTDatabaseDesigner7 ActiveX control in VDT70.DLL in Microsoft Visual Database Tools (MSVDT) Database Designer 7.0 allows remote attackers to cause a denial of service (Internet Explorer 6 crash) via a long argument.
8601| [CVE-2007-2884] Multiple stack-based buffer overflows in Microsoft Visual Basic 6 allow user-assisted remote attackers to cause a denial of service (CPU consumption) or execute arbitrary code via a Visual Basic Project (vbp) file with a long (1) Description or (2) Company Name (VersionCompanyName) field.
8602| [CVE-2007-2815] The "hit-highlighting" functionality in webhits.dll in Microsoft Internet Information Services (IIS) Web Server 5.0 only uses Windows NT ACL configuration, which allows remote attackers to bypass NTLM and basic authentication mechanisms and access private web directories via the CiWebhitsfile parameter to null.htw.
8603| [CVE-2007-2593] The Terminal Server in Microsoft Windows 2003 Server, when using TLS, allows remote attackers to bypass SSL and self-signed certificate requirements, downgrade the server security, and possibly conduct man-in-the-middle attacks via unspecified vectors, as demonstrated using the Remote Desktop Protocol (RDP) 6.0 client. NOTE: a third party claims that the vendor may have fixed this in approximately 2006.
8604| [CVE-2007-2581] Multiple cross-site scripting (XSS) vulnerabilities in Microsoft Windows SharePoint Services 3.0 for Windows Server 2003 and Office SharePoint Server 2007 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO (query string) in "every main page," as demonstrated by default.aspx.
8605| [CVE-2007-2237] Microsoft Windows Graphics Device Interface (GDI+, GdiPlus.dll) allows context-dependent attackers to cause a denial of service (crash) via an ICO file with an InfoHeader containing a Height of zero, which triggers a divide-by-zero error.
8606| [CVE-2007-2228] rpcrt4.dll (aka the RPC runtime library) in Microsoft Windows XP SP2, XP Professional x64 Edition, Server 2003 SP1 and SP2, Server 2003 x64 Edition and x64 Edition SP2, and Vista and Vista x64 Edition allows remote attackers to cause a denial of service (RPCSS service stop and system restart) via an RPC request that uses NTLMSSP PACKET authentication with a zero-valued verification trailer signature, which triggers an invalid dereference. NOTE: this also affects Windows 2000 SP4, although the impact is an information leak.
8607| [CVE-2007-2223] Microsoft XML Core Services (MSXML) 3.0 through 6.0 allows remote attackers to execute arbitrary code via the substringData method on a (1) TextNode or (2) XMLDOM object, which causes an integer overflow that leads to a buffer overflow.
8608| [CVE-2007-2218] Unspecified vulnerability in the Windows Schannel Security Package for Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2, allows remote servers to execute arbitrary code or cause a denial of service via crafted digital signatures that are processed during an SSL handshake.
8609| [CVE-2007-2161] Microsoft Internet Explorer 7 allows remote attackers to cause a denial of service (browser hang) via JavaScript that matches a regular expression against a long string, as demonstrated using /(.)*/.
8610| [CVE-2007-1946] Integer overflow in Windows Explorer in Microsoft Windows XP SP1 might allow user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large width dimension in a crafted BMP image, as demonstrated by w4intof.bmp.
8611| [CVE-2007-1911] Multiple unspecified vulnerabilities in Microsoft Word 2007 allow remote attackers to cause a denial of service (CPU consumption) via crafted documents, as demonstrated by (1) file798-1.doc and (2) file613-1.doc, possibly related to a buffer overflow.
8612| [CVE-2007-1910] Buffer overflow in wwlib.dll in Microsoft Word 2007 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted document, as demonstrated by file789-1.doc.
8613| [CVE-2007-1765] Unspecified vulnerability in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a malformed ANI file, which results in memory corruption when processing cursors, animated cursors, and icons, a similar issue to CVE-2005-0416, as originally demonstrated using Internet Explorer 6 and 7. NOTE: this issue might be a duplicate of CVE-2007-0038
8614| [CVE-2007-1763] The ATI kernel driver (atikmdag.sys) in Microsoft Windows Vista allows user-assisted remote attackers to cause a denial of service (crash) via a crafted JPG image, as demonstrated by a slideshow, possibly due to a buffer overflow.
8615| [CVE-2007-1748] Stack-based buffer overflow in the RPC interface in the Domain Name System (DNS) Server Service in Microsoft Windows 2000 Server SP 4, Server 2003 SP 1, and Server 2003 SP 2 allows remote attackers to execute arbitrary code via a long zone name containing character constants represented by escape sequences.
8616| [CVE-2007-1644] The dynamic DNS update mechanism in the DNS Server service on Microsoft Windows does not properly authenticate clients in certain deployments or configurations, which allows remote attackers to change DNS records for a web proxy server and conduct man-in-the-middle (MITM) attacks on web traffic, conduct pharming attacks by poisoning DNS records, and cause a denial of service (erroneous name resolution).
8617| [CVE-2007-1537] \Device\NdisTapi (NDISTAPI.sys) in Microsoft Windows XP SP2 and 2003 SP1 uses weak permissions, which allows local users to write to the device and cause a denial of service, as demonstrated by using an IRQL to acquire a spinlock on paged memory via the NdisTapiDispatch function.
8618| [CVE-2007-1531] Microsoft Windows XP and Vista overwrites ARP table entries included in gratuitous ARP, which allows remote attackers to cause a denial of service (loss of network access) by sending a gratuitous ARP for the address of the Vista host.
8619| [CVE-2007-1530] The LLTD Mapper in Microsoft Windows Vista does not properly gather responses to EMIT packets, which allows remote attackers to cause a denial of service (mapping failure) by omitting an ACK response, which triggers an XML syntax error.
8620| [CVE-2007-1492] winmm.dll in Microsoft Windows XP allows user-assisted remote attackers to cause a denial of service (infinite loop) via a large cch argument value to the mmioRead function, as demonstrated by a crafted WAV file.
8621| [CVE-2007-1347] Microsoft Windows Explorer on Windows 2000 SP4 FR and XP SP2 FR, and possibly other versions and platforms, allows remote attackers to cause a denial of service (memory corruption and crash) via an Office file with crafted document summary information, which causes an error in Ole32.dll.
8622| [CVE-2007-1278] Unspecified vulnerability in the IIS connector in Adobe JRun 4.0 Updater 6, and ColdFusion MX 6.1 and 7.0 Enterprise, when using Microsoft IIS 6, allows remote attackers to cause a denial of service via unspecified vectors, involving the request of a file in the JRun web root.
8623| [CVE-2007-1239] Microsoft Excel 2003 does not properly parse .XLS files, which allows remote attackers to cause a denial of service (application crash) via a file with a (1) corrupted XML format or a (2) corrupted XLS format, which triggers a NULL pointer dereference.
8624| [CVE-2007-1238] Microsoft Office 2003 allows user-assisted remote attackers to cause a denial of service (application crash) by attempting to insert a corrupted WMF file.
8625| [CVE-2007-1204] Stack-based buffer overflow in the Universal Plug and Play (UPnP) service in Microsoft Windows XP SP2 allows remote attackers on the same subnet to execute arbitrary code via crafted HTTP headers in request or notification messages, which trigger memory corruption.
8626| [CVE-2007-1094] Microsoft Internet Explorer 7 allows remote attackers to cause a denial of service (NULL dereference and application crash) via JavaScript onUnload handlers that modify the structure of a document.
8627| [CVE-2007-1090] Microsoft Windows Explorer on Windows XP and 2003 allows remote user-assisted attackers to cause a denial of service (crash) via a malformed WMF file, which triggers the crash when the user browses the folder.
8628| [CVE-2007-1083] Buffer overflow in the Configuration Checker (ConfigChk) ActiveX control in VSCnfChk.dll 2.0.0.2 for Verisign Managed PKI Service, Secure Messaging for Microsoft Exchange, and Go Secure! allows remote attackers to execute arbitrary code via long arguments to the VerCompare method.
8629| [CVE-2007-0878] Unspecified vulnerability in Microsoft Internet Explorer on Windows Mobile 5.0 allows remote attackers to cause a denial of service (loss of browser and other device functionality) via a malformed WML page, related to an "overflow state." NOTE: it is possible that this issue is related to CVE-2007-0685.
8630| [CVE-2007-0870] Unspecified vulnerability in Microsoft Word 2000 allows remote attackers to cause a denial of service (crash) via unknown vectors, a different vulnerability than CVE-2006-5994, CVE-2006-6456, CVE-2006-6561, and CVE-2007-0515, a variant of Exploit-MS06-027.
8631| [CVE-2007-0842] The 64-bit versions of Microsoft Visual C++ 8.0 standard library (MSVCR80.DLL) time functions, including (1) localtime, (2) localtime_s, (3) gmtime, (4) gmtime_s, (5) ctime, (6) ctime_s, (7) wctime, (8) wctime_s, and (9) fstat, trigger an assertion error instead of a NULL pointer or EINVAL when processing a time argument later than Jan 1, 3000, which might allow context-dependent attackers to cause a denial of service (application exit) via large time values. NOTE: it could be argued that this is a design limitation of the functions, and the vulnerability lies with any application that does not validate arguments to these functions. However, this behavior is inconsistent with documentation, which does not list assertions as a possible result of an error condition.
8632| [CVE-2007-0811] Microsoft Internet Explorer 6.0 SP1 on Windows 2000, and 6.0 SP2 on Windows XP, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an HTML document containing a certain JavaScript for loop with an empty loop body, possibly involving getElementById.
8633| [CVE-2007-0612] Multiple ActiveX controls in Microsoft Windows 2000, XP, 2003, and Vista allows remote attackers to cause a denial of service (Internet Explorer crash) by accessing the bgColor, fgColor, linkColor, alinkColor, vlinkColor, or defaultCharset properties in the (1) giffile, (2) htmlfile, (3) jpegfile, (4) mhtmlfile, (5) ODCfile, (6) pjpegfile, (7) pngfile, (8) xbmfile, (9) xmlfile, (10) xslfile, or (11) wdfile objects in (a) mshtml.dll
8634| [CVE-2007-0562] Windows Explorer (explorer.exe) 6.0.2900.2180 in Microsoft Windows XP SP2 allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted .avi file, which triggers the crash when the user right clicks on the file.
8635| [CVE-2007-0515] Unspecified vulnerability in Microsoft Word allows user-assisted remote attackers to execute arbitrary code on Word 2000, and cause a denial of service on Word 2003, via unknown attack vectors that trigger memory corruption, as exploited by Trojan.Mdropper.W and later by Trojan.Mdropper.X, a different issue than CVE-2006-6456, CVE-2006-5994, and CVE-2006-6561.
8636| [CVE-2007-0221] Integer overflow in the IMAP (IMAP4) support in Microsoft Exchange Server 2000 SP3 allows remote attackers to cause a denial of service (service hang) via crafted literals in an IMAP command, aka the "IMAP Literal Processing Vulnerability."
8637| [CVE-2007-0210] The Window Image Acquisition (WIA) Service in Microsoft Windows XP SP2 allows local users to gain privileges via unspecified vectors involving an "unchecked buffer," probably a buffer overflow.
8638| [CVE-2007-0108] nwgina.dll in Novell Client 4.91 SP3 for Windows 2000/XP/2003 does not delete user profiles during a Terminal Service or Citrix session, which allows remote authenticated users to invoke alternate user profiles.
8639| [CVE-2007-0099] Race condition in the msxml3 module in Microsoft XML Core Services 3.0, as used in Internet Explorer 6 and other applications, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via many nested tags in an XML document in an IFRAME, when synchronous document rendering is frequently disrupted with asynchronous events, as demonstrated using a JavaScript timer, which can trigger NULL pointer dereferences or memory corruption, aka "MSXML Memory Corruption Vulnerability."
8640| [CVE-2007-0087] ** DISPUTED ** Microsoft Internet Information Services (IIS), when accessed through a TCP connection with a large window size, allows remote attackers to cause a denial of service (network bandwidth consumption) via a Range header that specifies multiple copies of the same fragment. NOTE: the severity of this issue has been disputed by third parties, who state that the large window size required by the attack is not normally supported or configured by the server, or that a DDoS-style attack would accomplish the same goal.
8641| [CVE-2007-0069] Unspecified vulnerability in the kernel in Microsoft Windows XP SP2, Server 2003, and Vista allows remote attackers to cause a denial of service (CPU consumption) and possibly execute arbitrary code via crafted (1) IGMPv3 and (2) MLDv2 packets that trigger memory corruption, aka "Windows Kernel TCP/IP/IGMPv3 and MLDv2 Vulnerability."
8642| [CVE-2007-0066] The kernel in Microsoft Windows 2000 SP4, XP SP2, and Server 2003, when ICMP Router Discovery Protocol (RDP) is enabled, allows remote attackers to cause a denial of service via fragmented router advertisement ICMP packets that trigger an out-of-bounds read, aka "Windows Kernel TCP/IP/ICMP Vulnerability."
8643| [CVE-2007-0064] Heap-based buffer overflow in Windows Media Format Runtime 7.1, 9, 9.5, 9.5 x64 Edition, 11, and Windows Media Services 9.1 for Microsoft Windows 2000, XP, Server 2003, and Vista allows user-assisted remote attackers to execute arbitrary code via a crafted Advanced Systems Format (ASF) file.
8644| [CVE-2007-0043] The Just In Time (JIT) Compiler service in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows user-assisted remote attackers to execute arbitrary code via unspecified vectors involving an "unchecked buffer," probably a buffer overflow, aka ".NET JIT Compiler Vulnerability".
8645| [CVE-2007-0041] The PE Loader service in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows remote attackers to execute arbitrary code via unspecified vectors involving an "unchecked buffer" and unvalidated message lengths, probably a buffer overflow.
8646| [CVE-2007-0040] The LDAP service in Windows Active Directory in Microsoft Windows 2000 Server SP4, Server 2003 SP1 and SP2, Server 2003 x64 Edition and SP2, and Server 2003 for Itanium-based Systems SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted LDAP request with an unspecified number of "convertible attributes."
8647| [CVE-2007-0039] The Exchange Collaboration Data Objects (EXCDO) functionality in Microsoft Exchange Server 2000 SP3, 2003 SP1 and SP2, and 2007 allows remote attackers to cause a denial of service (crash) via an Internet Calendar (iCal) file containing multiple X-MICROSOFT-CDO-MODPROPS (MODPROPS) properties in which the second MODPROPS is longer than the first, which triggers a NULL pointer dereference and an unhandled exception.
8648| [CVE-2007-0038] Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a large length value in the second (or later) anih block of a RIFF .ANI, cur, or .ico file, which results in memory corruption when processing cursors, animated cursors, and icons, a variant of CVE-2005-0416, as originally demonstrated using Internet Explorer 6 and 7. NOTE: this might be a duplicate of CVE-2007-1765
8649| [CVE-2006-7210] Microsoft Windows 2000, XP, and Server 2003 allows remote attackers to cause a denial of service (cpu consumption) via a PNG image with crafted (1) Width and (2) Height values in the IHDR block.
8650| [CVE-2006-7206] Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) by creating a ADODB.Recordset object and making a series of calls to the NextRecordset method with a long string argument, which causes an "invalid memory access" in the SysFreeString function, a different issue than CVE-2006-3510 and CVE-2006-3899.
8651| [CVE-2006-7192] Microsoft ASP .NET Framework 2.0.50727.42 does not properly handle comment (/* */) enclosures, which allows remote attackers to bypass request filtering and conduct cross-site scripting (XSS) attacks, or cause a denial of service, as demonstrated via an xss:expression STYLE attribute in a closing XSS HTML tag.
8652| [CVE-2006-7066] Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) by creating an object inside an iframe, deleting the frame by setting its location.href to about:blank, then accessing a property of the object within the deleted frame, which triggers a NULL pointer dereference. NOTE: it was later reported that 7.0.6000.16473 and earlier are also affected.
8653| [CVE-2006-7065] Microsoft Internet Explorer allows remote attackers to cause a denial of service (crash) via an IFRAME with a certain XML file and XSL stylesheet that triggers a crash in mshtml.dll when a refresh is called, probably a null pointer dereference.
8654| [CVE-2006-7031] Microsoft Internet Explorer 6.0.2900 SP2 and earlier allows remote attackers to cause a denial of service (crash) via a table element with a CSS attribute that sets the position, which triggers an "unhandled exception" in mshtml.dll.
8655| [CVE-2006-7030] Microsoft Internet Explorer 6 SP2 and earlier allows remote attackers to cause a denial of service (crash) via certain malformed HTML, possibly involving applet and base tags without required arguments, which triggers a null pointer dereference in mshtml.dll.
8656| [CVE-2006-7029] Microsoft Internet Explorer 6 SP2 and earlier allows remote attackers to cause a denial of service (crash) via a frameset with only one frame that calls resizeTo with certain arguments. NOTE: this issue might be related to CVE-2006-3637.
8657| [CVE-2006-6956] Microsoft Internet Explorer allows remote attackers to cause a denial of service (crash) via a web page that contains a large number of nested marquee tags, a related issue to CVE-2006-2723.
8658| [CVE-2006-6797] The Client Server Run-Time Subsystem (CSRSS) in Microsoft Windows allows local users to cause a denial of service (crash) or read arbitrary memory from csrss.exe via crafted arguments to the NtRaiseHardError function with status 0x50000018, a different vulnerability than CVE-2006-6696.
8659| [CVE-2006-6723] The Workstation service in Microsoft Windows 2000 SP4 and XP SP2 allows remote attackers to cause a denial of service (memory consumption) via a large maxlen value in an NetrWkstaUserEnum RPC request.
8660| [CVE-2006-6696] Double free vulnerability in Microsoft Windows 2000, XP, 2003, and Vista allows local users to gain privileges by calling the MessageBox function with a MB_SERVICE_NOTIFICATION message with crafted data, which sends a HardError message to Client/Server Runtime Server Subsystem (CSRSS) process, which is not properly handled when invoking the UserHardError and GetHardErrorText functions in WINSRV.DLL.
8661| [CVE-2006-6659] The Microsoft Office Outlook Recipient ActiveX control (ole32.dll) in Windows XP SP2 allows remote attackers to cause a denial of service (Internet Explorer 7 hang) via crafted HTML.
8662| [CVE-2006-6602] explorer.exe in Windows Explorer 6.00.2900.2180 in Microsoft Windows XP SP2 allows user-assisted remote attackers to cause a denial of service via a crafted WMV file.
8663| [CVE-2006-6601] Windows Media Player 10.00.00.4036 in Microsoft Windows XP SP2 allows user-assisted remote attackers to cause a denial of service via a .MID (MIDI) file with a malformed header chunk without any track chunks, possibly involving (1) number of tracks of (2) time division fields that are set to 0.
8664| [CVE-2006-6578] Microsoft Internet Information Services (IIS) 5.1 permits the IUSR_Machine account to execute non-EXE files such as .COM files, which allows attackers to execute arbitrary commands via arguments to any .COM file that executes those arguments, as demonstrated using win.com when it is in a web directory with certain permissions.
8665| [CVE-2006-6311] Microsoft Internet Explorer 6.0.2900.2180 allows remote attackers to cause a denial of service via a style attribute in an HTML table tag with a width value that is dynamically calculated using JavaScript.
8666| [CVE-2006-6310] Microsoft Internet Explorer 6.0 SP1 and earlier allows remote attackers to cause a denial of service (crash) via an invalid src attribute value ("?") in an HTML frame tag that is in a frameset tag with a large rows attribute. NOTE: The provenance of this information is unknown
8667| [CVE-2006-6296] The RpcGetPrinterData function in the Print Spooler (spoolsv.exe) service in Microsoft Windows 2000 SP4 and earlier, and possibly Windows XP SP1 and earlier, allows remote attackers to cause a denial of service (memory consumption) via an RPC request that specifies a large 'offered' value (output buffer size), a variant of CVE-2005-3644.
8668| [CVE-2006-6252] Microsoft Windows Live Messenger 8.0 and earlier, when gestual emoticons are enabled, allows remote attackers to cause a denial of service (CPU consumption) via a long string composed of ":D" sequences, which are interpreted as emoticons.
8669| [CVE-2006-6134] Heap-based buffer overflow in the WMCheckURLScheme function in WMVCORE.DLL in Microsoft Windows Media Player (WMP) 10.00.00.4036 on Windows XP SP2, Server 2003, and Server 2003 SP1 allows remote attackers to cause a denial of service (application crash) and execute arbitrary code via a long HREF attribute, using an unrecognized protocol, in a REF element in an ASX PlayList file.
8670| [CVE-2006-5758] The Graphics Rendering Engine in Microsoft Windows 2000 through 2000 SP4 and Windows XP through SP2 maps GDI Kernel structures on a global shared memory section that is mapped with read-only permissions, but can be remapped by other processes as read-write, which allows local users to cause a denial of service (memory corruption and crash) and gain privileges by modifying the kernel structures.
8671| [CVE-2006-5745] Unspecified vulnerability in the setRequestHeader method in the XMLHTTP (XML HTTP) ActiveX Control 4.0 in Microsoft XML Core Services 4.0 on Windows, when accessed by Internet Explorer, allows remote attackers to execute arbitrary code via crafted arguments that lead to memory corruption, a different vulnerability than CVE-2006-4685. NOTE: some of these details are obtained from third party information.
8672| [CVE-2006-5614] Microsoft Windows NAT Helper Components (ipnathlp.dll) on Windows XP SP2, when Internet Connection Sharing is enabled, allows remote attackers to cause a denial of service (svchost.exe crash) via a malformed DNS query, which results in a null pointer dereference.
8673| [CVE-2006-5584] The Remote Installation Service (RIS) in Microsoft Windows 2000 SP4 uses a TFTP server that allows anonymous access, which allows remote attackers to upload and overwrite arbitrary files to gain privileges on systems that use RIS.
8674| [CVE-2006-5583] Buffer overflow in the SNMP Service in Microsoft Windows 2000 SP4, XP SP2, Server 2003, Server 2003 SP1, and possibly other versions allows remote attackers to execute arbitrary code via a crafted SNMP packet, aka "SNMP Memory Corruption Vulnerability."
8675| [CVE-2006-5559] The Execute method in the ADODB.Connection 2.7 and 2.8 ActiveX control objects (ADODB.Connection.2.7 and ADODB.Connection.2.8) in the Microsoft Data Access Components (MDAC) 2.5 SP3, 2.7 SP1, 2.8, and 2.8 SP1 does not properly track freed memory when the second argument is a BSTR, which allows remote attackers to cause a denial of service (Internet Explorer crash) and possibly execute arbitrary code via certain strings in the second and third arguments.
8676| [CVE-2006-5448] The drmstor.dll ActiveX object in Microsoft Windows Digital Rights Management System (DRM) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long parameter to the StoreLicense function, which triggers "memory corruption" and possibly a buffer overflow.
8677| [CVE-2006-5296] PowerPoint in Microsoft Office 2003 does not properly handle a container object whose position value exceeds the record length, which allows user-assisted attackers to cause a denial of service (NULL dereference and application crash) via a crafted PowerPoint (.PPT) file, as demonstrated by Nanika.ppt, and a different vulnerability than CVE-2006-3435, CVE-2006-3876, CVE-2006-3877, and CVE-2006-4694. NOTE: the impact of this issue was originally claimed to be arbitrary code execution, but later analysis demonstrated that this was erroneous.
8678| [CVE-2006-5265] Unspecified vulnerability in Microsoft Dynamics GP (formerly Great Plains) 9.0 and earlier allows remote attackers to cause a denial of service (crash) via an invalid magic number in a Distributed Process Server (DPS) message.
8679| [CVE-2006-5162] wininet.dll in Microsoft Internet Explorer 6.0 SP2 and earlier allows remote attackers to cause a denial of service (unhandled exception and crash) via a long Content-Type header, which triggers a stack overflow.
8680| [CVE-2006-4888] Microsoft Internet Explorer 6 and earlier allows remote attackers to cause a denial of service (application hang) via a CSS-formatted HTML INPUT element within a DIV element that has a larger size than the INPUT.
8681| [CVE-2006-4696] Unspecified vulnerability in the Server service in Microsoft Windows 2000 SP4, Server 2003 SP1 and earlier, and XP SP2 and earlier allows remote attackers to execute arbitrary code via a crafted packet, aka "SMB Rename Vulnerability."
8682| [CVE-2006-4691] Stack-based buffer overflow in the NetpManageIPCConnect function in the Workstation service (wkssvc.dll) in Microsoft Windows 2000 SP4 and XP SP2 allows remote attackers to execute arbitrary code via NetrJoinDomain2 RPC messages with a long hostname.
8683| [CVE-2006-4689] Unspecified vulnerability in the driver for the Client Service for NetWare (CSNW) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 allows remote attackers to cause a denial of service (hang and reboot) via has unknown attack vectors, aka "NetWare Driver Denial of Service Vulnerability."
8684| [CVE-2006-4688] Buffer overflow in Client Service for NetWare (CSNW) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 allows remote attackers to execute arbitrary code via crafted messages, aka "Client Service for NetWare Memory Corruption Vulnerability."
8685| [CVE-2006-4686] Buffer overflow in the Extensible Stylesheet Language Transformations (XSLT) processing in Microsoft XML Parser 2.6 and XML Core Services 3.0 through 6.0 allows remote attackers to execute arbitrary code via a crafted Web page.
8686| [CVE-2006-4685] The XMLHTTP ActiveX control in Microsoft XML Parser 2.6 and XML Core Services 3.0 through 6.0 does not properly handle HTTP server-side redirects, which allows remote user-assisted attackers to access content from other domains.
8687| [CVE-2006-4627] System Information ActiveX control (msinfo.dll), when accessed via Microsoft Internet Explorer, allows remote attackers to cause a denial of service (crash) via a SaveFile function with a long (1) computer and possibly (2) filename and (3) category argument.
8688| [CVE-2006-4495] Microsoft Internet Explorer allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code by instantiating certain Windows 2000 ActiveX COM Objects including (1) ciodm.dll, (2) myinfo.dll, (3) msdxm.ocx, and (4) creator.dll.
8689| [CVE-2006-4494] Microsoft Visual Studio 6.0 allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code by instantiating certain Visual Studio 6.0 ActiveX COM Objects in Internet Explorer, including (1) tcprops.dll, (2) fp30wec.dll, (3) mdt2db.dll, (4) mdt2qd.dll, and (5) vi30aut.dll.
8690| [CVE-2006-4465] ** DISPUTED ** Microsoft Terminal Server, when running an application session with the "Start program at logon" and "Override settings from user profile and Client Connection Manager wizard" options, allows local users to execute arbitrary code by forcing an Explorer error. NOTE: a third-party researcher has stated that the options are "a convenience to users" and were not intended to restrict execution of arbitrary code.
8691| [CVE-2006-4446] Heap-based buffer overflow in DirectAnimation.PathControl COM object (daxctle.ocx) in Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a Spline function call whose first argument specifies a large number of points.
8692| [CVE-2006-4301] Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service (crash) via a long Color attribute in multiple DirectX Media Image DirectX Transforms ActiveX COM Objects from (a) dxtmsft.dll and (b) dxtmsft3.dll, including (1) DXImageTransform.Microsoft.MaskFilter.1, (2) DXImageTransform.Microsoft.Chroma.1, and (3) DX3DTransform.Microsoft.Shapes.1.
8693| [CVE-2006-4193] Microsoft Internet Explorer 6.0 SP1 and possibly other versions allows remote attackers to cause a denial of service and possibly execute arbitrary code by instantiating COM objects as ActiveX controls, including (1) imskdic.dll (Microsoft IME), (2) chtskdic.dll (Microsoft IME), and (3) msoe.dll (Outlook), which leads to memory corruption. NOTE: it is not certain whether the issue is in Internet Explorer or the individual DLL files.
8694| [CVE-2006-4071] Sign extension vulnerability in the createBrushIndirect function in the GDI library (gdi32.dll) in Microsoft Windows XP, Server 2003, and possibly other versions, allows user-assisted attackers to cause a denial of service (application crash) via a crafted WMF file.
8695| [CVE-2006-4066] The Graphical Device Interface Plus library (gdiplus.dll) in Microsoft Windows XP SP2 allows context-dependent attackers to cause a denial of service (application crash) via certain images that trigger a divide-by-zero error, as demonstrated by a (1) .ico file, (2) .png file that crashes MSN Messenger, and (3) .jpg file that crashes Internet Explorer. NOTE: another researcher has not been able to reproduce this issue.
8696| [CVE-2006-3944] Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) via a (1) Forms.ListBox.1 or (2) Forms.ListBox.1 object with the ListWidth property set to (a) 0x7fffffff, which triggers an integer overflow exception, or to (b) 0x7ffffffe, which triggers a null dereference.
8697| [CVE-2006-3943] Stack-based buffer overflow in NDFXArtEffects in Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) via long (1) RGBExtraColor, (2) RGBForeColor, and (3) RGBBackColor properties.
8698| [CVE-2006-3942] The server driver (srv.sys) in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause a denial of service (system crash) via an SMB_COM_TRANSACTION SMB message that contains a string without null character termination, which leads to a NULL dereference in the ExecuteTransaction function, possibly related to an "SMB PIPE," aka the "Mailslot DOS" vulnerability. NOTE: the name "Mailslot DOS" was derived from incomplete initial research
8699| [CVE-2006-3915] Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) by iterating over any native function, as demonstrated with the window.alert function, which triggers a null dereference.
8700| [CVE-2006-3899] Microsoft Internet Explorer 6.0 on Windows XP SP2 allows remote attackers to cause a denial of service (application crash) by calling the stringToBinary function of the CEnroll.CEnroll.2 ActiveX object with a long second argument, which triggers an invalid memory access inside the SysAllocStringLen function.
8701| [CVE-2006-3898] Microsoft Internet Explorer 6.0 on Windows XP SP2 allows remote attackers to cause a denial of service (application crash) by calling the Click method of the Internet.HHCtrl.1 ActiveX object before initializing the URL, which triggers a null dereference.
8702| [CVE-2006-3897] Stack overflow in Microsoft Internet Explorer 6 on Windows 2000 allows remote attackers to cause a denial of service (application crash) by creating an NMSA.ASFSourceMediaDescription.1 ActiveX object with a long dispValue property.
8703| [CVE-2006-3880] ** DISPUTED ** Microsoft Windows NT 4.0, Windows 2000, Windows XP, and Windows Small Business Server 2003 allow remote attackers to cause a denial of service (IP stack hang) via a continuous stream of packets on TCP port 135 that have incorrect TCP header checksums and random numbers in certain TCP header fields, as demonstrated by the Achilles Windows Attack Tool. NOTE: the researcher reports that the Microsoft Security Response Center has stated "Our investigation which has included code review, review of the TCPDump, and attempts on reproing the issue on multiple fresh installs of various Windows Operating Systems have all resulted in non confirmation."
8704| [CVE-2006-3873] Heap-based buffer overflow in URLMON.DLL in Microsoft Internet Explorer 6 SP1 on Windows 2000 and XP SP1, with versions the MS06-042 patch before 20060912, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long URL in a GZIP-encoded website that was the target of an HTTP redirect, due to an incomplete fix for CVE-2006-3869.
8705| [CVE-2006-3869] Heap-based buffer overflow in URLMON.DLL in Microsoft Internet Explorer 6 SP1 on Windows 2000 and XP SP1, with versions the MS06-042 patch before 20060824, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long URL on a website that uses HTTP 1.1 compression.
8706| [CVE-2006-3730] Integer overflow in Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a 0x7fffffff argument to the setSlice method on a WebViewFolderIcon ActiveX object, which leads to an invalid memory copy.
8707| [CVE-2006-3659] Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by setting the location or URL property of a MHTMLFile ActiveX object.
8708| [CVE-2006-3658] Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by accessing the object references of a FolderItem ActiveX object, which triggers a null dereference in the security check.
8709| [CVE-2006-3657] Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (stack overflow exception) via a DXImageTransform.Microsoft.Gradient ActiveX object with a long (1) StartColorStr or (2) EndColorStr property.
8710| [CVE-2006-3654] Buffer overflow in wksss.exe 8.4.702.0 in Microsoft Works Spreadsheet 8.0 allows remote attackers to cause a denial of service (CPU consumption or crash) via crafted Excel files.
8711| [CVE-2006-3653] wksss.exe 8.4.702.0 in Microsoft Works Spreadsheet 8.0 allows remote attackers to cause a denial of service (CPU consumption or crash) via crafted (1) Works, (2) Excel, and (3) Lotus 1-2-3 files.
8712| [CVE-2006-3638] Microsoft Internet Explorer 5.01 and 6 does not properly handle uninitialized COM objects, which allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code, as demonstrated by the Nth function in the DirectAnimation.DATuple ActiveX control, aka "COM Object Instantiation Memory Corruption Vulnerability."
8713| [CVE-2006-3605] Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by setting the Transition property on an uninitialized DXImageTransform.Microsoft.RevealTrans.1 ActiveX Object, which triggers a null dereference.
8714| [CVE-2006-3591] Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (application crash) by accessing the URL property of a TriEditDocument.TriEditDocument object before it has been initialized, which triggers a NULL pointer dereference.
8715| [CVE-2006-3545] ** DISPUTED ** Microsoft Internet Explorer 7.0 Beta allows remote attackers to cause a denial of service (application crash) via a web page with multiple empty APPLET start tags. NOTE: a third party has disputed this issue, stating that the crash does not occur with Microsoft Internet Explorer 7.0 Beta3.
8716| [CVE-2006-3513] danim.dll in Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (application crash) by accessing the Data property of a DirectAnimation DAUserData object before it is initialized, which triggers a NULL pointer dereference.
8717| [CVE-2006-3510] The Remote Data Service Object (RDS.DataControl) in Microsoft Internet Explorer 6 on Windows 2000 allows remote attackers to cause a denial of service (crash) via a series of operations that result in an invalid length calculation when using SysAllocStringLen, then triggers a buffer over-read.
8718| [CVE-2006-3493] Buffer overflow in LsCreateLine function (mso_203) in mso.dll and mso9.dll, as used by Microsoft Word and possibly other products in Microsoft Office 2003, 2002, and 2000, allows remote user-assisted attackers to cause a denial of service (crash) via a crafted Word DOC or other Office file type. NOTE: this issue was originally reported to allow code execution, but on 20060710 Microsoft stated that code execution is not possible, and the original researcher agrees.
8719| [CVE-2006-3472] Microsoft Internet Explorer 6.0 and 6.0 SP1 allows remote attackers to cause a denial of service via an HTML page with an A tag containing a long title attribute. NOTE: the provenance of this information is unknown
8720| [CVE-2006-3471] Microsoft Internet Explorer 6 on Windows XP allows remote attackers to cause a denial of service (crash) via a table with a frameset as a child, which triggers a null dereference, as demonstrated using the appendChild method.
8721| [CVE-2006-3441] Buffer overflow in the DNS Client service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted record response. NOTE: while MS06-041 implies that there is a single issue, there are multiple vectors, and likely multiple vulnerabilities, related to (1) a heap-based buffer overflow in a DNS server response to the client, (2) a DNS server response with malformed ATMA records, and (3) a length miscalculation in TXT, HINFO, X25, and ISDN records.
8722| [CVE-2006-3439] Buffer overflow in the Server Service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers, including anonymous users, to execute arbitrary code via a crafted RPC message, a different vulnerability than CVE-2006-1314.
8723| [CVE-2006-3427] Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by declaring the sourceURL attribute on an uninitialized DirectAnimation.StructuredGraphicsControl ActiveX Object, which triggers a null dereference.
8724| [CVE-2006-3357] Heap-based buffer overflow in HTML Help ActiveX control (hhctrl.ocx) in Microsoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code by repeatedly setting the Image field of an Internet.HHCtrl.1 object to certain values, possibly related to improper escaping and long strings.
8725| [CVE-2006-3354] Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by setting the Filter property of an ADODB.Recordset ActiveX object to certain values multiple times, which triggers a null dereference.
8726| [CVE-2006-3086] Stack-based buffer overflow in the HrShellOpenWithMonikerDisplayName function in Microsoft Hyperlink Object Library (hlink.dll) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long hyperlink, as demonstrated using an Excel worksheet with a long link in Unicode, aka "Hyperlink COM Object Buffer Overflow Vulnerability." NOTE: this is a different issue than CVE-2006-3059.
8727| [CVE-2006-2919] Unspecified vulnerability in Microsoft NetMeeting 3.01 allows remote attackers to cause a denial of service (crash or CPU consumption) and possibly execute arbitrary code via crafted inputs that trigger memory corruption.
8728| [CVE-2006-2838] Buffer overflow in the web console in F-Secure Anti-Virus for Microsoft Exchange 6.40, and Internet Gatekeeper 6.40 through 6.42 and 6.50 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown attack vectors. NOTE: By default, the connections are only allowed from the local host.
8729| [CVE-2006-2766] Buffer overflow in INETCOMM.DLL, as used in Microsoft Internet Explorer 6.0 through 6.0 SP2, Windows Explorer, Outlook Express 6, and possibly other programs, allows remote user-assisted attackers to cause a denial of service (application crash) via a long mhtml URI in the URL value in a URL file.
8730| [CVE-2006-2374] The Server Message Block (SMB) driver (MRXSMB.SYS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows local users to cause a denial of service (hang) by calling the MrxSmbCscIoctlCloseForCopyChunk with the file handle of the shadow device, which results in a deadlock, aka the "SMB Invalid Handle Vulnerability."
8731| [CVE-2006-2372] Buffer overflow in the DHCP Client service for Microsoft Windows 2000 SP4, Windows XP SP1 and SP2, and Server 2003 up to SP1 allows remote attackers to execute arbitrary code via a crafted DHCP response.
8732| [CVE-2006-2371] Buffer overflow in the Remote Access Connection Manager service (RASMAN) service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote unauthenticated or authenticated attackers to execute arbitrary code via certain crafted "RPC related requests," that lead to registry corruption and stack corruption, aka the "RASMAN Registry Corruption Vulnerability."
8733| [CVE-2006-2370] Buffer overflow in the Routing and Remote Access service (RRAS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote unauthenticated or authenticated attackers to execute arbitrary code via certain crafted "RPC related requests," aka the "RRAS Memory Corruption Vulnerability."
8734| [CVE-2006-2094] Microsoft Internet Explorer before Windows XP Service Pack 2 and Windows Server 2003 Service Pack 1, when Prompt is configured in Security Settings, uses modal dialogs to verify that a user wishes to run an ActiveX control or perform other risky actions, which allows user-assisted remote attackers to construct a race condition that tricks a user into clicking an object or pressing keys that are actually applied to a "Yes" approval for executing the control.
8735| [CVE-2006-1992] mshtml.dll 6.00.2900.2873, as used in Microsoft Internet Explorer, allows remote attackers to cause a denial of service (crash) via nested OBJECT tags, which trigger invalid pointer dereferences including NULL dereferences. NOTE: the possibility of code execution was originally theorized, but Microsoft has stated that this issue is non-exploitable.
8736| [CVE-2006-1540] MSO.DLL in Microsoft Office 2000, Office XP (2002), and Office 2003 allows user-assisted attackers to cause a denial of service and execute arbitrary code via multiple attack vectors, as originally demonstrated using a crafted document record with a malformed string, as demonstrated by replacing a certain "01 00 00 00" byte sequence with an "FF FF FF FF" byte sequence, possibly causing an invalid array index, in (1) an Excel .xls document, which triggers an access violation in ole32.dll
8737| [CVE-2006-1364] Microsoft w3wp (aka w3wp.exe) does not properly handle when the AspCompat directive is not used when referencing COM components in ASP.NET, which allows remote attackers to cause a denial of service (resource consumption or crash) by repeatedly requesting each of several documents that refer to COM components, or are restricted documents located under the ASP.NET application path.
8738| [CVE-2006-1359] Microsoft Internet Explorer 6 and 7 Beta 2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a certain createTextRange call on a checkbox object, which results in a dereference of an invalid table pointer.
8739| [CVE-2006-1315] The Server Service (SRV.SYS driver) in Microsoft Windows 2000 SP4, XP SP1 and SP2, Server 2003 up to SP1, and other products, allows remote attackers to obtain sensitive information via crafted requests that leak information in SMB buffers, which are not properly initialized, aka "SMB Information Disclosure Vulnerability."
8740| [CVE-2006-1314] Heap-based buffer overflow in the Server Service (SRV.SYS driver) in Microsoft Windows 2000 SP4, XP SP1 and SP2, Server 2003 up to SP1, and other products, allows remote attackers to execute arbitrary code via crafted first-class Mailslot messages that triggers memory corruption and bypasses size restrictions on second-class Mailslot messages.
8741| [CVE-2006-1305] Microsoft Outlook 2000, 2002, and 2003 allows user-assisted remote attackers to cause a denial of service (memory exhaustion and interrupted mail recovery) via malformed e-mail header information, possibly related to (1) long subject lines or (2) large numbers of recipients in To or CC headers.
8742| [CVE-2006-1184] Microsoft Distributed Transaction Coordinator (MSDTC) for Windows NT 4.0, 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote attackers to cause a denial of service (crash) via a BuildContextW request with a large (1) UuidString or (2) GuidIn of a certain length, which causes an out-of-range memory access, aka the MSDTC Denial of Service Vulnerability. NOTE: this is a variant of CVE-2005-2119.
8743| [CVE-2006-0988] The default configuration of the DNS Server service on Windows Server 2003 and Windows 2000, and the Microsoft DNS Server service on Windows NT 4.0, allows recursive queries and provides additional delegation information to arbitrary IP addresses, which allows remote attackers to cause a denial of service (traffic amplification) via DNS queries with spoofed source IP addresses.
8744| [CVE-2006-0935] Microsoft Word 2003 allows remote attackers to cause a denial of service (application crash) via a crafted file, as demonstrated by 101_filefuzz.
8745| [CVE-2006-0761] Buffer overflow in BlackBerry Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server 2.2 and 4.0 before SP3 Hotfix 4 for IBM Lotus Domino, 3.6 before SP7 and 5.0 before SP3 Hotfix 3 for Microsoft Exchangem, and 4.0 for Novell GroupWise before SP3 Hotfix 1 might allow user-assisted remote attackers to execute arbitrary code on the server via a crafted Microsoft Word document that is opened on a wireless device.
8746| [CVE-2006-0753] Memory leak in Microsoft Internet Explorer 6 for Windows XP Service Pack 2 allows remote attackers to cause a denial of service (memory consumption) via JavaScript that uses setInterval to repeatedly call a function to set the value of window.status.
8747| [CVE-2006-0585] jscript.dll in Microsoft Internet Explorer 6.0 SP1 and earlier allows remote attackers to cause a denial of service (application crash) via a Shockwave Flash object that contains ActionScript code that calls VBScript, which in turn calls the Javascript document.write function, which triggers a null dereference.
8748| [CVE-2006-0544] urlmon.dll in Microsoft Internet Explorer 7.0 beta 2 (aka 7.0.5296.0) allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a BGSOUND element with its SRC attribute set to "file://" followed by a large number of "-" (dash of hyphen) characters.
8749| [CVE-2006-0143] Microsoft Windows Graphics Rendering Engine (GRE) allows remote attackers to corrupt memory and cause a denial of service (crash) via a WMF file containing (1) ExtCreateRegion or (2) ExtEscape function calls with arguments with inconsistent lengths.
8750| [CVE-2006-0032] Cross-site scripting (XSS) vulnerability in the Indexing Service in Microsoft Windows 2000, XP, and Server 2003, when the Encoding option is set to Auto Select, allows remote attackers to inject arbitrary web script or HTML via a UTF-7 encoded URL, which is injected into an error message whose charset is set to UTF-7.
8751| [CVE-2006-0026] Buffer overflow in Microsoft Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows local and possibly remote attackers to execute arbitrary code via crafted Active Server Pages (ASP).
8752| [CVE-2006-0023] Microsoft Windows XP SP1 and SP2 before August 2004, and possibly other operating systems and versions, uses insecure default ACLs that allow the Authenticated Users group to gain privileges by modifying critical configuration information for the (1) Simple Service Discovery Protocol (SSDP), (2) Universal Plug and Play Device Host (UPnP), (3) NetBT, (4) SCardSvr, (5) DHCP, and (6) DnsCache services, aka "Permissive Windows Services DACLs." NOTE: the NetBT, SCardSvr, DHCP, DnsCache already require privileged access to exploit.
8753| [CVE-2006-0021] Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote attackers to cause a denial of service (hang) via an IGMP packet with an invalid IP option, aka the "IGMP v3 DoS Vulnerability."
8754| [CVE-2006-0020] An unspecified Microsoft WMF parsing application, as used in Internet Explorer 5.01 SP4 on Windows 2000 SP4, and 5.5 SP2 on Windows Millennium, and possibly other versions, allows attackers to cause a denial of service (crash) and possibly execute code via a crafted WMF file with a manipulated WMF header size, possibly involving an integer overflow, a different vulnerability than CVE-2005-4560, and aka "WMF Image Parsing Memory Corruption Vulnerability."
8755| [CVE-2006-0015] Cross-site scripting (XSS) vulnerability in _vti_bin/_vti_adm/fpadmdll.dll in Microsoft FrontPage Server Extensions 2002 and SharePoint Team Services allows remote attackers to inject arbitrary web script or HTML, then leverage the attack to execute arbitrary programs or create new accounts, via the (1) operation, (2) command, and (3) name parameters.
8756| [CVE-2006-0013] Buffer overflow in the Web Client service (WebClnt.dll) for Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote authenticated users or Guests to execute arbitrary code via crafted RPC requests, a different vulnerability than CVE-2005-1207.
8757| [CVE-2005-4810] Microsoft Internet Explorer 7.0 Beta3 and earlier allows remote attackers to cause a denial of service (crash) via a "text/html" HTML Content-type header sent in response to an XMLHttpRequest (AJAX).
8758| [CVE-2005-4717] Microsoft Internet Explorer 6.0 on Windows NT 4.0 SP6a, Windows 2000 SP4, Windows XP SP1, Windows XP SP2, and Windows Server 2003 SP1 allows remote attackers to cause a denial of service (client crash) via a certain combination of a malformed HTML file and a CSS file that triggers a null dereference, probably related to rendering of a DIV element that contains a malformed IMG tag, as demonstrated by IEcrash.htm and IEcrash.rar.
8759| [CVE-2005-4360] The URL parser in Microsoft Internet Information Services (IIS) 5.1 on Windows XP Professional SP2 allows remote attackers to execute arbitrary code via multiple requests to ".dll" followed by arguments such as "~0" through "~9", which causes ntdll.dll to produce a return value that is not correctly handled by IIS, as demonstrated using "/_vti_bin/.dll/*/~0". NOTE: the consequence was originally believed to be only a denial of service (application crash and reboot).
8760| [CVE-2005-4269] mshtml.dll in Microsoft Windows XP, Server 2003, and Internet Explorer 6.0 SP1 allows attackers to cause a denial of service (access violation) by causing mshtml.dll to process button-focus events at the same time that a document is reloading, as seen in Microsoft Office InfoPath 2003 by repeatedly clicking the "Delete" button in a repeating section in a form. NOTE: the normal operation of InfoPath appears to involve a local user without any privilege boundaries, so this might not be a vulnerability in InfoPath. If no realistic scenarios exist for this problem in other products, then perhaps it should be excluded from CVE.
8761| [CVE-2005-3983] Unknown vulnerability in the login page for HP Systems Insight Manager (SIM) 4.0 and 4.1, when accessed by Microsoft Internet Explorer with the MS04-025 patch, leads to a denial of service (browser hang). NOTE: although the advisory is vague, this issue does not appear to involve an attacker at all. If not, then this issue is not a vulnerability.
8762| [CVE-2005-3945] The SynAttackProtect protection in Microsoft Windows 2003 before SP1 and Windows 2000 before SP4 with Update Roll-up uses a hash of predictable data, which allows remote attackers to cause a denial of service (CPU consumption) via a flood of SYN packets that produce identical hash values, which slows down the hash table lookups.
8763| [CVE-2005-3644] PNP_GetDeviceList (upnp_getdevicelist) in UPnP for Microsoft Windows 2000 SP4 and earlier, and possibly Windows XP SP1 and earlier, allows remote attackers to cause a denial of service (memory consumption) via a DCE RPC request that specifies a large output buffer size, a variant of CVE-2006-6296, and a different vulnerability than CVE-2005-2120.
8764| [CVE-2005-3589] Buffer overflow in FileZilla Server Terminal 0.9.4d may allow remote attackers to cause a denial of service (terminal crash) via a long USER ftp command.
8765| [CVE-2005-3568] db2fmp process in IBM DB2 Content Manager before 8.2 Fix Pack 10 allows local users to cause a denial of service (CPU consumption) by importing a corrupted Microsoft Excel file, aka "CORRUPTED EXEL FILE WILL CAUSE TEXT SEARCH PROCESS LOOPING."
8766| [CVE-2005-3169] Microsoft Windows 2000 before Update Rollup 1 for SP4, when the "audit directory service access" policy is enabled, does not record a 565 event message for File Delete Child operations on an Active Directory object in the security event log, which could allow attackers to conduct unauthorized activities without detection.
8767| [CVE-2005-3077] Microsoft Internet Explorer 5.2.3 for Mac OS allows remote attackers to cause a denial of service (crash) via a web page with malformed attributes in a BGSOUND tag, possibly involving double-quotes in an about: URI.
8768| [CVE-2005-2831] Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, aka a variant of the "COM Object Instantiation Memory Corruption Vulnerability," a different vulnerability than CVE-2005-2127.
8769| [CVE-2005-2308] The JPEG decoder in Microsoft Internet Explorer allows remote attackers to cause a denial of service (CPU consumption or crash) and possibly execute arbitrary code via certain crafted JPEG images, as demonstrated using (1) mov_fencepost.jpg, (2) cmp_fencepost.jpg, (3) oom_dos.jpg, or (4) random.jpg.
8770| [CVE-2005-2307] netman.dll in Microsoft Windows Connections Manager Library allows local users to cause a denial of service (Network Connections Service crash) via a large integer argument to a particular function, aka "Network Connection Manager Vulnerability."
8771| [CVE-2005-2304] Microsoft MSN Messenger 9.0 and Internet Explorer 6.0 allows remote attackers to cause a denial of service (crash) via an image with an ICC Profile with a large Tag Count.
8772| [CVE-2005-2225] Microsoft MSN Messenger allows remote attackers to cause a denial of service via a plaintext message containing the ".pif" string, which is interpreted as a malicious file extension and causes users to be kicked from a group conversation. NOTE: it has been reported that Gaim is also affected, so this may be an issue in the protocol or MSN servers.
8773| [CVE-2005-2224] aspnet_wp.exe in Microsoft ASP.NET web services allows remote attackers to cause a denial of service (CPU consumption from infinite loop) via a crafted SOAP message to an RPC/Encoded method.
8774| [CVE-2005-2143] Microsoft Front Page allows attackers to cause a denial of service (crash) via a crafted style tag in a web page.
8775| [CVE-2005-2127] Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, as originally demonstrated using the (1) DDS Library Shape Control (Msdds.dll) COM object, and other objects including (2) Blnmgrps.dll, (3) Ciodm.dll, (4) Comsvcs.dll, (5) Danim.dll, (6) Htmlmarq.ocx, (7) Mdt2dd.dll (as demonstrated using a heap corruption attack with uninitialized memory), (8) Mdt2qd.dll, (9) Mpg4ds32.ax, (10) Msadds32.ax, (11) Msb1esen.dll, (12) Msb1fren.dll, (13) Msb1geen.dll, (14) Msdtctm.dll, (15) Mshtml.dll, (16) Msoeacct.dll, (17) Msosvfbr.dll, (18) Mswcrun.dll, (19) Netshell.dll, (20) Ole2disp.dll, (21) Outllib.dll, (22) Psisdecd.dll, (23) Qdvd.dll, (24) Repodbc.dll, (25) Shdocvw.dll, (26) Shell32.dll, (27) Soa.dll, (28) Srchui.dll, (29) Stobject.dll, (30) Vdt70.dll, (31) Vmhelper.dll, and (32) Wbemads.dll, aka a variant of the "COM Object Instantiation Memory Corruption vulnerability."
8776| [CVE-2005-2120] Stack-based buffer overflow in the Plug and Play (PnP) service (UMPNPMGR.DLL) in Microsoft Windows 2000 SP4, and XP SP1 and SP2, allows remote or local authenticated attackers to execute arbitrary code via a large number of "\" (backslash) characters in a registry key name, which triggers the overflow in a wsprintfW function call.
8777| [CVE-2005-1985] The Client Service for NetWare (CSNW) on Microsoft Windows 2000 SP4, XP SP1 and Sp2, and Server 2003 SP1 and earlier, allows remote attackers to execute arbitrary code due to an "unchecked buffer" when processing certain crafted network messages.
8778| [CVE-2005-1984] Buffer overflow in the Print Spooler service (Spoolsv.exe) for Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via a malicious message.
8779| [CVE-2005-1983] Stack-based buffer overflow in the Plug and Play (PnP) service for Microsoft Windows 2000 and Windows XP Service Pack 1 allows remote attackers to execute arbitrary code via a crafted packet, and local users to gain privileges via a malicious application, as exploited by the Zotob (aka Mytob) worm.
8780| [CVE-2005-1981] Unknown vulnerability in Microsoft Windows 2000 Server and Windows Server 2003 domain controllers allows remote authenticated users to cause a denial of service (system crash) via a crafted Kerberos message.
8781| [CVE-2005-1980] Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC service hang) via a crafted Transaction Internet Protocol (TIP) message that causes DTC to repeatedly connect to a target IP and port number after an error occurs, aka the "Distributed TIP Vulnerability."
8782| [CVE-2005-1979] Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC service exception and exit) via an "unexpected protocol command during the reconnection request," which is not properly handled by the Transaction Internet Protocol (TIP) functionality.
8783| [CVE-2005-1907] The ISA Firewall service in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service (Wspsrv.exe crash) via a large amount of SecureNAT network traffic.
8784| [CVE-2005-1829] Microsoft Internet Explorer 6 SP2 allows remote attackers to cause a denial of service (infinite loop and application crash) via two embedded files that call each other.
8785| [CVE-2005-1794] Microsoft Terminal Server using Remote Desktop Protocol (RDP) 5.2 stores an RSA private key in mstlsapi.dll and uses it to sign a certificate, which allows remote attackers to spoof public keys of legitimate servers and conduct man-in-the-middle attacks.
8786| [CVE-2005-1793] User32.DLL in Microsoft Windows 98SE, and possibly other operating systems, allows local and remote attackers to cause a denial of service (crash) via an icon (.ico) bitmap file with large width and height values.
8787| [CVE-2005-1790] Microsoft Internet Explorer 6 SP2 6.0.2900.2180 and 6.0.2800.1106, and earlier versions, allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a Javascript BODY onload event that calls the window function, aka "Mismatched Document Object Model Objects Memory Corruption Vulnerability."
8788| [CVE-2005-1683] Buffer overflow in winword.exe 10.2627.6714 and earlier in Microsoft Word for the Macintosh, before SP3 for Word 2002, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted mcw file.
8789| [CVE-2005-1665] The __VIEWSTATE functionality in Microsoft ASP.NET 1.x, when not cryptographically signed, allows remote attackers to cause a denial of service (CPU consumption) via deeply nested markup.
8790| [CVE-2005-1218] The Microsoft Windows kernel in Microsoft Windows 2000 Server, Windows XP, and Windows Server 2003 allows remote attackers to cause a denial of service (crash) via crafted Remote Desktop Protocol (RDP) requests.
8791| [CVE-2005-1216] Microsoft ISA Server 2000 allows remote attackers to connect to services utilizing the NetBIOS protocol via a NetBIOS connection with an ISA Server that uses the NetBIOS (all) predefined packet filter.
8792| [CVE-2005-1207] Buffer overflow in the Web Client service in Microsoft Windows XP and Windows Server 2003 allows remote authenticated users to execute arbitrary code via a crafted WebDAV request containing special parameters.
8793| [CVE-2005-1205] The Telnet client for Microsoft Windows XP, Windows Server 2003, and Windows Services for UNIX allows remote attackers to read sensitive environment variables via the NEW-ENVIRON option with a SEND ENV_USERVAR command.
8794| [CVE-2005-0852] Microsoft Windows XP SP1 allows local users to cause a denial of service (system crash) via an empty datagram to a raw IP over IP socket (IP protocol 4), as originally demonstrated using code in Python 2.3.
8795| [CVE-2005-0738] Stack consumption vulnerability in Microsoft Exchange Server 2003 SP1 allows users to cause a denial of service (hang) by deleting or moving a folder with deeply nested subfolders, which causes Microsoft Exchange Information Store service (Store.exe) to hang as a result of a large number of recursive calls.
8796| [CVE-2005-0554] Buffer overflow in the URL processor of Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a URL with a long hostname, aka "URL Parsing Memory Corruption Vulnerability."
8797| [CVE-2005-0550] Buffer overflow in Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to cause a denial of service (i.e., system crash) via a malformed request, aka "Object Management Vulnerability".
8798| [CVE-2005-0048] Microsoft Windows XP SP2 and earlier, 2000 SP3 and SP4, Server 2003, and older operating systems allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted IP packets with malformed options, aka the "IP Validation Vulnerability."
8799| [CVE-2004-2527] The local and remote desktop login screens in Microsoft Windows XP before SP2 and 2003 allow remote attackers to cause a denial of service (CPU and memory consumption) by repeatedly using the WinKey+"U" key combination, which causes multiple copies of Windows Utility Manager to be loaded more quickly than they can be closed when the copies detect that another instance is running.
8800| [CVE-2004-2476] Microsoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (infinite loop and crash) via an IFRAME with "?" as the file source.
8801| [CVE-2004-2434] Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service (browser crash) via a link with "::{" (colon colon left brace), which triggers a null dereference when the user attempts to save the link using "Save As" and Internet Explorer prepares an error message with an attacker-controlled format string.
8802| [CVE-2004-2382] The PerfectNav plugin for Microsoft Internet Explorer allows remote attackers to cause a denial of service (browser crash) via a malformed URL such as "?".
8803| [CVE-2004-2365] Memory leak in Microsoft Windows XP and Windows Server 2003 allows local users to cause a denial of service (memory exhaustion) by repeatedly creating and deleting directories using a non-standard tool such as smbmount.
8804| [CVE-2004-2307] Microsoft Internet Explorer 6.0.2600 on Windows XP allows remote attackers to cause a denial of service (browser crash) via a shell: URI with double backslashes (\\) in an HTML tag such as IFRAME or A.
8805| [CVE-2004-2179] asycpict.dll, as used in Microsoft products such as Front Page 97 and 98, allows remote attackers to cause a denial of service (hang) via a JPEG image with maximum height and width values.
8806| [CVE-2004-2147] Unknown versions of Symantec Norton AntiVirus and Microsoft Outlook allow attackers to cause a denial of service (crash) via malformed e-mail messages (1) without a body or (2) without a carriage return ("\n") separating the headers from the body.
8807| [CVE-2004-1922] Microsoft Internet Explorer 5.5 and 6.0 allocates memory based on the memory size written in the BMP file instead of the actual BMP file size, which allows remote attackers to cause a denial of service (memory consumption) via a small BMP file with has a large memory size.
8808| [CVE-2004-1889] Unknown vulnerability in ftpd in SGI IRIX 6.5.20 through 6.5.23 allows remote attackers to cause a denial of service (hang) via a link failure with Microsoft Windows.
8809| [CVE-2004-1560] Microsoft SQL Server 7.0 allows remote attackers to cause a denial of service (mssqlserver service halt) via a long request to TCP port 1433, possibly triggering a buffer overflow.
8810| [CVE-2004-1464] Cisco IOS 12.2(15) and earlier allows remote attackers to cause a denial of service (refused VTY (virtual terminal) connections), via a crafted TCP connection to the Telnet or reverse Telnet port.
8811| [CVE-2004-1312] A bug in the HTML parser in a certain Microsoft HTML library, as used in various third party products, may allow remote attackers to cause a denial of service via certain strings, as reported in GFI MailEssentials for Exchange 9 and 10, and GFI MailSecurity for Exchange 8, which causes emails to remain in IIS or Exchange mail queues.
8812| [CVE-2004-1198] Microsoft Internet Explorer allows remote attackers to cause a denial of service (application crash from memory consumption), as demonstrated using Javascript code that continuously creates nested arrays and then sorts the newly created arrays.
8813| [CVE-2004-1134] Buffer overflow in the Microsoft W3Who ISAPI (w3who.dll) allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long query string.
8814| [CVE-2004-1080] The WINS service (wins.exe) on Microsoft Windows NT Server 4.0, Windows 2000 Server, and Windows Server 2003 allows remote attackers to write to arbitrary memory locations and possibly execute arbitrary code via a modified memory pointer in a WINS replication packet to TCP port 42, aka the "Association Context Vulnerability."
8815| [CVE-2004-0963] Buffer overflow in Microsoft Word 2002 (10.6612.6714) SP3, and possibly other versions, allows remote attackers to cause a denial of service (application exception) and possibly execute arbitrary code in winword.exe via certain unexpected values in a .doc file, including (1) an offset that triggers an out-of-bounds memory access, (2) a certain value that causes a large memory copy as triggered by an integer conversion error, and other values.
8816| [CVE-2004-0897] The Indexing Service for Microsoft Windows XP and Server 2003 does not properly validate the length of a message, which allows remote attackers to execute arbitrary code via a buffer overflow attack.
8817| [CVE-2004-0830] The Content Scanner Server in F-Secure Anti-Virus for Microsoft Exchange 6.21 and earlier, F-Secure Anti-Virus for Microsoft Exchange 6.01 and earlier, and F-Secure Internet Gatekeeper 6.32 and earlier allow remote attackers to cause a denial of service (service crash due to unhandled exception) via a certain malformed packet.
8818| [CVE-2004-0814] Multiple race conditions in the terminal layer in Linux 2.4.x, and 2.6.x before 2.6.9, allow (1) local users to obtain portions of kernel data via a TIOCSETD ioctl call to a terminal interface that is being accessed by another thread, or (2) remote attackers to cause a denial of service (panic) by switching from console to PPP line discipline, then quickly sending data that is received during the switch.
8819| [CVE-2004-0728] The Remote Control Client service in Microsoft's Systems Management Server (SMS) 2.50.2726.0 allows remote attackers to cause a denial of service (crash) via a data packet to TCP port 2702 that causes the server to read or write to an invalid memory address.
8820| [CVE-2004-0610] The Web administration interface in Microsoft MN-500 Wireless Router allows remote attackers to cause a denial of service (connection refusal) via a large number of open HTTP connections.
8821| [CVE-2004-0569] The RPC Runtime Library for Microsoft Windows NT 4.0 allows remote attackers to read active memory or cause a denial of service (system crash) via a malicious message, possibly related to improper length values.
8822| [CVE-2004-0567] The Windows Internet Naming Service (WINS) in Windows NT Server 4.0 SP 6a, NT Terminal Server 4.0 SP 6, Windows 2000 Server SP3 and SP4, and Windows Server 2003 does not properly validate the computer name value in a WINS packet, which allows remote attackers to execute arbitrary code or cause a denial of service (server crash), which results in an "unchecked buffer" and possibly triggers a buffer overflow, aka the "Name Validation Vulnerability."
8823| [CVE-2004-0484] mshtml.dll in Microsoft Internet Explorer 6.0.2800 allows remote attackers to cause a denial of service (crash) via a table containing a form that crosses multiple td elements, and whose "float: left" class is defined in a link to a CSS stylesheet after the end of the table, which may trigger a null dereference.
8824| [CVE-2004-0284] Microsoft Internet Explorer 6.0, Outlook 2002, and Outlook 2003 allow remote attackers to cause a denial of service (CPU consumption), if "Do not save encrypted pages to disk" is disabled, via a web site or HTML e-mail that contains two null characters (%00) after the host name.
8825| [CVE-2004-0215] Microsoft Outlook Express 5.5 and 6 allows attackers to cause a denial of service (application crash) via a malformed e-mail header.
8826| [CVE-2004-0214] Buffer overflow in Microsoft Internet Explorer and Explorer on Windows XP SP1, WIndows 2000, Windows 98, and Windows Me may allow remote malicious servers to cause a denial of service (application crash) and possibly execute arbitrary code via long share names, as demonstrated using Samba.
8827| [CVE-2004-0211] The kernel for Microsoft Windows Server 2003 does not reset certain values in CPU data structures, which allows local users to cause a denial of service (system crash) via a malicious program.
8828| [CVE-2004-0206] Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to remotely execute arbitrary code or locally gain privileges via a malicious message or application that involves an "unchecked buffer," possibly a buffer overflow.
8829| [CVE-2004-0202] IDirectPlay4 Application Programming Interface (API) of Microsoft DirectPlay 7.0a thru 9.0b, as used in Windows Server 2003 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed packet.
8830| [CVE-2004-0120] The Microsoft Secure Sockets Layer (SSL) library, as used in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service via malformed SSL messages.
8831| [CVE-2004-0116] An Activation function in the RPCSS Service involved with DCOM activation for Microsoft Windows 2000, XP, and 2003 allows remote attackers to cause a denial of service (memory consumption) via an activation request with a large length field.
8832| [CVE-2004-0115] VirtualPC_Services in Microsoft Virtual PC for Mac 6.0 through 6.1 allows local attackers to truncate and overwrite arbitrary files, and execute arbitrary code, via a symlink attack on the VPCServices_Log temporary file.
8833| [CVE-2003-1582] Microsoft Internet Information Services (IIS) 6.0, when DNS resolution is enabled for client IP addresses, allows remote attackers to inject arbitrary text into log files via an HTTP request in conjunction with a crafted DNS response, as demonstrated by injecting XSS sequences, related to an "Inverse Lookup Log Corruption (ILLC)" issue.
8834| [CVE-2003-1567] The undocumented TRACK method in Microsoft Internet Information Services (IIS) 5.0 returns the content of the original request in the body of the response, which makes it easier for remote attackers to steal cookies and authentication credentials, or bypass the HttpOnly protection mechanism, by using TRACK to read the contents of the HTTP headers that are returned in the response, a technique that is similar to cross-site tracing (XST) using HTTP TRACE.
8835| [CVE-2003-1566] Microsoft Internet Information Services (IIS) 5.0 does not log requests that use the TRACK method, which allows remote attackers to obtain sensitive information without detection.
8836| [CVE-2003-1544] Unrestricted critical resource lock in Terminal Services for Windows 2000 before SP4 and Windows XP allows remote authenticated users to cause a denial of service (reboot) by obtaining a read lock on msgina.dll, which prevents msgina.dll from being loaded.
8837| [CVE-2003-1505] Microsoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (crash) by creating a web page or HTML e-mail with a textarea in a div element whose scrollbar-base-color is modified by a CSS style, which is then moved.
8838| [CVE-2003-1484] Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service (crash) by creating a DHTML link that uses the AnchorClick "A" object with a blank href attribute.
8839| [CVE-2003-1305] Microsoft Internet Explorer allows remote attackers to cause a denial of service (resource consumption) via a Javascript src attribute that recursively loads the current web page.
8840| [CVE-2003-1106] The SMTP service in Microsoft Windows 2000 before SP4 allows remote attackers to cause a denial of service (crash or hang) via an e-mail message with a malformed time stamp in the FILETIME attribute.
8841| [CVE-2003-0995] Buffer overflow in the Microsoft Message Queue Manager (MSQM) allows remote attackers to cause a denial of service (RPC service crash) via a queue registration request.
8842| [CVE-2003-0904] Microsoft Exchange 2003 and Outlook Web Access (OWA), when configured to use NTLM authentication, does not properly reuse HTTP connections, which can cause OWA users to view mailboxes of other users when Kerberos has been disabled as an authentication method for IIS 6.0, e.g. when SharePoint Services 2.0 is installed.
8843| [CVE-2003-0825] The Windows Internet Naming Service (WINS) for Microsoft Windows Server 2003, and possibly Windows NT and Server 2000, does not properly validate the length of certain packets, which allows attackers to cause a denial of service and possibly execute arbitrary code.
8844| [CVE-2003-0824] Unknown vulnerability in the SmartHTML interpreter (shtml.dll) in Microsoft FrontPage Server Extensions 2000 and 2002, and Microsoft SharePoint Team Services 2002, allows remote attackers to cause a denial of service (response failure) via a certain request.
8845| [CVE-2003-0819] Buffer overflow in the H.323 filter of Microsoft Internet Security and Acceleration Server 2000 allows remote attackers to execute arbitrary code in the Microsoft Firewall Service via certain H.323 traffic, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.
8846| [CVE-2003-0533] Stack-based buffer overflow in certain Active Directory service functions in LSASRV.DLL of the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via a packet that causes the DsRolerUpgradeDownlevelServer function to create long debug entries for the DCPROMO.LOG log file, as exploited by the Sasser worm.
8847| [CVE-2003-0506] Microsoft NetMeeting 3.01 2000 before SP4 allows remote attackers to cause a denial of service (shutdown of NetMeeting conference) via malformed packets, as demonstrated via the chat conversation.
8848| [CVE-2003-0349] Buffer overflow in the streaming media component for logging multicast requests in the ISAPI for the logging capability of Microsoft Windows Media Services (nsiislog.dll), as installed in IIS 5.0, allows remote attackers to execute arbitrary code via a large POST request to nsiislog.dll.
8849| [CVE-2003-0345] Buffer overflow in the SMB capability for Microsoft Windows XP, 2000, and NT allows remote attackers to cause a denial of service and possibly execute arbitrary code via an SMB packet that specifies a smaller buffer length than is required.
8850| [CVE-2003-0231] Microsoft SQL Server 7, 2000, and MSDE allows local or remote authenticated users to cause a denial of service (crash or hang) via a long request to a named pipe.
8851| [CVE-2003-0227] The logging capability for unicast and multicast transmissions in the ISAPI extension for Microsoft Windows Media Services in Microsoft Windows NT 4.0 and 2000, nsiislog.dll, allows remote attackers to cause a denial of service in Internet Information Server (IIS) and execute arbitrary code via a certain network request.
8852| [CVE-2003-0226] Microsoft Internet Information Services (IIS) 5.0 and 5.1 allows remote attackers to cause a denial of service via a long WebDAV request with a (1) PROPFIND or (2) SEARCH method, which generates an error condition that is not properly handled.
8853| [CVE-2003-0225] The ASP function Response.AddHeader in Microsoft Internet Information Server (IIS) 4.0 and 5.0 does not limit memory requests when constructing headers, which allow remote attackers to generate a large header to cause a denial of service (memory consumption) with an ASP page.
8854| [CVE-2003-0224] Buffer overflow in ssinc.dll for Microsoft Internet Information Services (IIS) 5.0 allows local users to execute arbitrary code via a web page with a Server Side Include (SSI) directive with a long filename, aka "Server Side Include Web Pages Buffer Overrun."
8855| [CVE-2003-0110] The Winsock Proxy service in Microsoft Proxy Server 2.0 and the Microsoft Firewall service in Internet Security and Acceleration (ISA) Server 2000 allow remote attackers to cause a denial of service (CPU consumption or packet storm) via a spoofed, malformed packet to UDP port 1745.
8856| [CVE-2003-0109] Buffer overflow in ntdll.dll on Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute arbitrary code, as demonstrated via a WebDAV request to IIS 5.0.
8857| [CVE-2003-0079] The DEC UDK processing feature in the hanterm (hanterm-xf) terminal emulator before 2.0.5 allows attackers to cause a denial of service via a certain character escape sequence that causes the terminal to enter a tight loop.
8858| [CVE-2003-0071] The DEC UDK processing feature in the xterm terminal emulator in XFree86 4.2.99.4 and earlier allows attackers to cause a denial of service via a certain character escape sequence that causes the terminal to enter a tight loop.
8859| [CVE-2003-0011] Unknown vulnerability in the DNS intrusion detection application filter for Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service (blocked traffic to DNS servers) via a certain type of incoming DNS request that is not properly handled.
8860| [CVE-2002-2164] Buffer overflow in Microsoft Outlook Express 5.0, 5.5, and 6.0 allows remote attackers to cause a denial of service (crash) via a long <A HREF> link.
8861| [CVE-2002-2117] Microsoft Windows XP allows remote attackers to cause a denial of service (CPU consumption) by flooding UDP port 500 (ISAKMP).
8862| [CVE-2002-2081] cphost.dll in Microsoft Site Server 3.0 allows remote attackers to cause a denial of service (disk consumption) via an HTTP POST of a file with a long TargetURL parameter, which causes Site Server to abort and leaves the uploaded file in c:\temp.
8863| [CVE-2002-1984] Microsoft Internet Explorer 5.0.1 through 6.0 on Windows 2000 or Windows XP allows remote attackers to cause a denial of service (crash) via an OBJECT tag that contains a crafted CLASSID (CLSID) value of "CLSID:00022613-0000-0000-C000-000000000046".
8864| [CVE-2002-1973] Buffer overflow in CHttpServer::OnParseError in the ISAPI extension (Isapi.cpp) when built using Microsoft Foundation Class (MFC) static libraries in Visual C++ 5.0, and 6.0 before SP3, as used in multiple products including BadBlue, allows remote attackers to cause a denial of service (access violation and crash) and possibly execute arbitrary code via a long query string that causes a parsing error.
8865| [CVE-2002-1908] Microsoft IIS 5.0 and 5.1 allows remote attackers to cause a denial of service (CPU consumption) via an HTTP request with a Host header that contains a large number of "/" (forward slash) characters.
8866| [CVE-2002-1876] Microsoft Exchange 2000 allows remote authenticated attackers to cause a denial of service via a large number of rapid requests, which consumes all of the licenses that are granted to Exchange by IIS.
8867| [CVE-2002-1873] Microsoft Exchange 2000, when used with Microsoft Remote Procedure Call (MSRPC), allows remote attackers to cause a denial of service (crash or memory consumption) via malformed MSRPC calls.
8868| [CVE-2002-1831] Microsoft MSN Messenger Service 1.0 through 4.6 allows remote attackers to cause a denial of service (crash) via an invite request that contains hex-encoded spaces (%20) in the Invitation-Cookie field.
8869| [CVE-2002-1790] The SMTP service in Microsoft Internet Information Services (IIS) 4.0 and 5.0 allows remote attackers to bypass anti-relaying rules and send spam or spoofed messages via encapsulated SMTP addresses, a similar vulnerability to CVE-1999-0682.
8870| [CVE-2002-1749] Windows 2000 Terminal Services, when using the disconnect feature of the client, does not properly lock itself if it is left idle until the screen saver activates and the user disconnects, which could allow attackers to gain administrator privileges.
8871| [CVE-2002-1714] Microsoft Internet Explorer 5.0 through 6.0 allows remote attackers to cause a denial of service (crash) via an object of type "text/html" with the DATA field that identifies the HTML document that contains the object, which may cause infinite recursion.
8872| [CVE-2002-1712] Microsoft Windows 2000 allows remote attackers to cause a denial of service (memory consumption) by sending a flood of empty TCP/IP packets with the ACK and FIN bits set to the NetBIOS port (TCP/139), as demonstrated by stream3.
8873| [CVE-2002-1705] Microsoft Internet Explorer 5.5 through 6.0 allows remote attackers to cause a denial of service (crash) via a Cascading Style Sheet (CSS) with the p{cssText} element declared and a bold font weight.
8874| [CVE-2002-1698] Buffer overflow in Microsoft MSN Messenger Service 1.0 through 4.6 allows remote attackers to cause a denial of service (crash) via a long FN (font) argument in the message header.
8875| [CVE-2002-1295] The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to cause a denial of service (crash) and possibly conduct other unauthorized activities via applet tags in HTML that bypass Java class restrictions (such as private constructors) by providing the class name in the code parameter, aka "Incomplete Java Object Instantiation Vulnerability."
8876| [CVE-2002-1294] The Microsoft Java implementation, as used in Internet Explorer, can provide HTML object references to applets via Javascript, which allows remote attackers to cause a denial of service (crash due to illegal memory accesses) and possibly conduct other unauthorized activities via an applet that uses those references to access proprietary Microsoft methods.
8877| [CVE-2002-1292] The Microsoft Java virtual machine (VM) build 5.0.3805 and earlier, as used in Internet Explorer, allows remote attackers to extend the Standard Security Manager (SSM) class (com.ms.security.StandardSecurityManager) and bypass intended StandardSecurityManager restrictions by modifying the (1) deniedDefinitionPackages or (2) deniedAccessPackages settings, causing a denial of service by adding Java applets to the list of applets that are prevented from running.
8878| [CVE-2002-1290] The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to read and modify the contents of the Clipboard via an applet that accesses the (1) ClipBoardGetText and (2) ClipBoardSetText methods of the INativeServices class.
8879| [CVE-2002-1289] The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to read restricted process memory, cause a denial of service (crash), and possibly execute arbitrary code via the getNativeServices function, which creates an instance of the com.ms.awt.peer.INativeServices (INativeServices) class, whose methods do not verify the memory addresses that are passed as parameters.
8880| [CVE-2002-1287] Stack-based buffer overflow in the Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to cause a denial of service via a long class name through (1) Class.forName or (2) ClassLoader.loadClass.
8881| [CVE-2002-1255] Microsoft Outlook 2002 allows remote attackers to cause a denial of service (repeated failure) via an email message with a certain invalid header field that is accessed using POP3, IMAP, or WebDAV, aka "E-mail Header Processing Flaw Could Cause Outlook 2002 to Fail."
8882| [CVE-2002-1214] Buffer overflow in Microsoft PPTP Service on Windows XP and Windows 2000 allows remote attackers to cause a denial of service (hang) and possibly execute arbitrary code via a certain PPTP packet with malformed control data.
8883| [CVE-2002-1142] Heap-based buffer overflow in the Remote Data Services (RDS) component of Microsoft Data Access Components (MDAC) 2.1 through 2.6, and Internet Explorer 5.01 through 6.0, allows remote attackers to execute code via a malformed HTTP request to the Data Stub.
8884| [CVE-2002-1141] An input validation error in the Sun Microsystems RPC library Services for Unix 3.0 Interix SD, as implemented on Microsoft Windows NT4, 2000, and XP, allows remote attackers to cause a denial of service via malformed fragmented RPC client packets, aka "Denial of service by sending an invalid RPC request."
8885| [CVE-2002-1140] The Sun Microsystems RPC library Services for Unix 3.0 Interix SD, as implemented on Microsoft Windows NT4, 2000, and XP, allows remote attackers to cause a denial of service (service hang) via malformed packet fragments, aka "Improper parameter size check leading to denial of service."
8886| [CVE-2002-0867] Microsoft Virtual Machine (VM) up to and including build 5.0.3805 allows remote attackers to cause a denial of service (crash) in Internet Explorer via invalid handle data in a Java applet, aka "Handle Validation Flaw."
8887| [CVE-2002-0864] The Remote Data Protocol (RDP) version 5.1 in Microsoft Windows XP allows remote attackers to cause a denial of service (crash) when Remote Desktop is enabled via a PDU Confirm Active data packet that does not set the Pattern BLT command, aka "Denial of Service in Remote Desktop."
8888| [CVE-2002-0729] Microsoft SQL Server 2000 allows remote attackers to cause a denial of service via a malformed 0x08 packet that is missing a colon separator.
8889| [CVE-2002-0724] Buffer overflow in SMB (Server Message Block) protocol in Microsoft Windows NT, Windows 2000, and Windows XP allows attackers to cause a denial of service (crash) via a SMB_COM_TRANSACTION packet with a request for the (1) NetShareEnum, (2) NetServerEnum2, or (3) NetServerEnum3, aka "Unchecked Buffer in Network Share Provider Can Lead to Denial of Service".
8890| [CVE-2002-0719] SQL injection vulnerability in the function that services for Microsoft Content Management Server (MCMS) 2001 allows remote attackers to execute arbitrary commands via an MCMS resource request for image files or other files.
8891| [CVE-2002-0697] Microsoft Metadirectory Services (MMS) 2.2 allows remote attackers to bypass authentication and modify sensitive data by using an LDAP client to directly connect to MMS and bypass the checks for MMS credentials.
8892| [CVE-2002-0694] The HTML Help facility in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP uses the Local Computer Security Zone when opening .chm files from the Temporary Internet Files folder, which allows remote attackers to execute arbitrary code via HTML mail that references or inserts a malicious .chm file containing shortcuts that can be executed, aka "Code Execution via Compiled HTML Help File."
8893| [CVE-2002-0693] Buffer overflow in the HTML Help ActiveX Control (hhctrl.ocx) in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute code via (1) a long parameter to the Alink function, or (2) script containing a long argument to the showHelp function.
8894| [CVE-2002-0692] Buffer overflow in SmartHTML Interpreter (shtml.dll) in Microsoft FrontPage Server Extensions (FPSE) 2000 and 2002 allows remote attackers to cause a denial of service (CPU consumption) or run arbitrary code, respectively, via a certain type of web file request.
8895| [CVE-2002-0650] The keep-alive mechanism for Microsoft SQL Server 2000 allows remote attackers to cause a denial of service (bandwidth consumption) via a "ping" style packet to the Resolution Service (UDP port 1434) with a spoofed IP address of another SQL Server system, which causes the two servers to exchange packets in an infinite loop.
8896| [CVE-2002-0649] Multiple buffer overflows in the Resolution Service for Microsoft SQL Server 2000 and Microsoft Desktop Engine 2000 (MSDE) allow remote attackers to cause a denial of service or execute arbitrary code via UDP packets to port 1434 in which (1) a 0x04 byte that causes the SQL Monitor thread to generate a long registry key name, or (2) a 0x08 byte with a long string causes heap corruption, as exploited by the Slammer/Sapphire worm.
8897| [CVE-2002-0642] The registry key containing the SQL Server service account information in Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, has insecure permissions, which allows local users to gain privileges, aka "Incorrect Permission on SQL Server Service Account Registry Key."
8898| [CVE-2002-0620] Buffer overflow in the Profile Service of Microsoft Commerce Server 2000 allows remote attackers to cause the server to fail or run arbitrary code in the LocalSystem security context via an input field using an affected API.
8899| [CVE-2002-0597] LANMAN service on Microsoft Windows 2000 allows remote attackers to cause a denial of service (CPU/memory exhaustion) via a stream of malformed data to microsoft-ds port 445.
8900| [CVE-2002-0444] Microsoft Windows 2000 running the Terminal Server 90-day trial version, and possibly other versions, does not apply group policies to incoming users when the number of connections to the SYSVOL share exceeds the maximum, e.g. with a maximum number of licenses, which can allow remote authenticated users to bypass group policies.
8901| [CVE-2002-0373] The Windows Media Device Manager (WMDM) Service in Microsoft Windows Media Player 7.1 on Windows 2000 systems allows local users to obtain LocalSystem rights via a program that calls the WMDM service to connect to an invalid local storage device, aka "Privilege Elevation through Windows Media Device Manager Service".
8902| [CVE-2002-0370] Buffer overflow in the ZIP capability for multiple products allows remote attackers to cause a denial of service or execute arbitrary code via ZIP files containing entries with long filenames, including (1) Microsoft Windows 98 with Plus! Pack, (2) Windows XP, (3) Windows ME, (4) Lotus Notes R4 through R6 (pre-gold), (5) Verity KeyView, and (6) Stuffit Expander before 7.0.
8903| [CVE-2002-0368] The Store Service in Microsoft Exchange 2000 allows remote attackers to cause a denial of service (CPU consumption) via a mail message with a malformed RFC message attribute, aka "Malformed Mail Attribute can Cause Exchange 2000 to Exhaust CPU Resources."
8904| [CVE-2002-0224] The MSDTC (Microsoft Distributed Transaction Service Coordinator) for Microsoft Windows 2000, Microsoft IIS 5.0 and SQL Server 6.5 through SQL 2000 0.0 allows remote attackers to cause a denial of service (crash or hang) via malformed (random) input.
8905| [CVE-2002-0154] Buffer overflows in extended stored procedures for Microsoft SQL Server 7.0 and 2000 allow remote attackers to cause a denial of service or execute arbitrary code via a database query with certain long arguments.
8906| [CVE-2002-0152] Buffer overflow in various Microsoft applications for Macintosh allows remote attackers to cause a denial of service (crash) or execute arbitrary code by invoking the file:// directive with a large number of / characters, which affects Internet Explorer 5.1, Outlook Express 5.0 through 5.0.2, Entourage v. X and 2001, PowerPoint v. X, 2001, and 98, and Excel v. X and 2001 for Macintosh.
8907| [CVE-2002-0151] Buffer overflow in Multiple UNC Provider (MUP) in Microsoft Windows operating systems allows local users to cause a denial of service or possibly gain SYSTEM privileges via a long UNC request.
8908| [CVE-2002-0147] Buffer overflow in the ASP data transfer mechanism in Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to cause a denial of service or execute code, aka "Microsoft-discovered variant of Chunked Encoding buffer overrun."
8909| [CVE-2002-0136] Microsoft Internet Explorer 5.5 on Windows 98 allows remote web pages to cause a denial of service (hang) via extremely long values for form fields such as INPUT and TEXTAREA, which can be automatically filled via Javascript.
8910| [CVE-2002-0101] Microsoft Internet Explorer 6.0 and earlier allows local users to cause a denial of service via an infinite loop for modeless dialogs showModelessDialog, which causes CPU usage while the focus for the dialog is not released.
8911| [CVE-2002-0057] XMLHTTP control in Microsoft XML Core Services 2.6 and later does not properly handle IE Security Zone settings, which allows remote attackers to read arbitrary files by specifying a local file as an XML Data Source.
8912| [CVE-2002-0055] SMTP service in Microsoft Windows 2000, Windows XP Professional, and Exchange 2000 allows remote attackers to cause a denial of service via a command with a malformed data transfer (BDAT) request.
8913| [CVE-2002-0054] SMTP service in (1) Microsoft Windows 2000 and (2) Internet Mail Connector (IMC) in Exchange Server 5.5 does not properly handle responses to NTLM authentication, which allows remote attackers to perform mail relaying via an SMTP AUTH command using null session credentials.
8914| [CVE-2002-0021] Network Product Identification (PID) Checker in Microsoft Office v. X for Mac allows remote attackers to cause a denial of service (crash) via a malformed product announcement.
8915| [CVE-2001-1533] ** DISPUTED * Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service via a flood of fragmented UDP packets. NOTE: the vendor disputes this issue, saying that it requires high bandwidth to exploit, and the server does not experience any instability. Therefore this "laws of physics" issue might not be included in CVE.
8916| [CVE-2001-1518] RunAs (runas.exe) in Windows 2000 only creates one session instance at a time, which allows local users to cause a denial of service (RunAs hang) by creating a named pipe session with the authentication server without any request for service. NOTE: the vendor disputes this vulnerability, however the vendor also presents a scenario in which other users could be affected if running on a Terminal Server. Therefore this is a vulnerability.
8917| [CVE-2001-1489] Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via a web page with a large number of images.
8918| [CVE-2001-1451] Memory leak in the SNMP LAN Manager (LANMAN) MIB extension for Microsoft Windows 2000 before SP3, when the Print Spooler is not running, allows remote attackers to cause a denial of service (memory consumption) via a large number of GET or GETNEXT requests.
8919| [CVE-2001-1450] Microsoft Internet Explorer 5.0 through 6.0 allows attackers to cause a denial of service (browser crash) via a crafted FTP URL such as "/.#./".
8920| [CVE-2001-1319] Microsoft Exchange 5.5 2000 allows remote attackers to cause a denial of service (hang) via exceptional BER encodings for the LDAP filter type field, as demonstrated by the PROTOS LDAPv3 test suite.
8921| [CVE-2001-1243] Scripting.FileSystemObject in asp.dll for Microsoft IIS 4.0 and 5.0 allows local or remote attackers to cause a denial of service (crash) via (1) creating an ASP program that uses Scripting.FileSystemObject to open a file with an MS-DOS device name, or (2) remotely injecting the device name into ASP programs that internally use Scripting.FileSystemObject.
8922| [CVE-2001-1219] Microsoft Internet Explorer 6.0 and earlier allows malicious website operators to cause a denial of service (client crash) via JavaScript that continually refreshes the window via self.location.
8923| [CVE-2001-1218] Microsoft Internet Explorer for Unix 5.0SP1 allows local users to possibly cause a denial of service (crash) in CDE or the X server on Solaris 2.6 by rapidly scrolling Chinese characters or maximizing the window.
8924| [CVE-2001-1186] Microsoft IIS 5.0 allows remote attackers to cause a denial of service via an HTTP request with a content-length value that is larger than the size of the request, which prevents IIS from timing out the connection.
8925| [CVE-2001-1055] The Microsoft Windows network stack allows remote attackers to cause a denial of service (CPU consumption) via a flood of malformed ARP request packets with random source IP and MAC addresses, as demonstrated by ARPNuke.
8926| [CVE-2001-0860] Terminal Services Manager MMC in Windows 2000 and XP trusts the Client Address (IP address) that is provided by the client instead of obtaining it from the packet headers, which allows clients to spoof their public IP address, e.g. through a Network Address Translation (NAT).
8927| [CVE-2001-0666] Outlook Web Access (OWA) in Microsoft Exchange 2000 allows an authenticated user to cause a denial of service (CPU consumption) via a malformed OWA request for a deeply nested folder within the user's mailbox.
8928| [CVE-2001-0663] Terminal Server in Windows NT and Windows 2000 allows remote attackers to cause a denial of service via a sequence of invalid Remote Desktop Protocol (RDP) packets.
8929| [CVE-2001-0547] Memory leak in the proxy service in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows local attackers to cause a denial of service (resource exhaustion).
8930| [CVE-2001-0546] Memory leak in H.323 Gatekeeper Service in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service (resource exhaustion) via a large amount of malformed H.323 data.
8931| [CVE-2001-0540] Memory leak in Terminal servers in Windows NT and Windows 2000 allows remote attackers to cause a denial of service (memory exhaustion) via a large number of malformed Remote Desktop Protocol (RDP) requests to port 3389.
8932| [CVE-2001-0509] Vulnerabilities in RPC servers in (1) Microsoft Exchange Server 2000 and earlier, (2) Microsoft SQL Server 2000 and earlier, (3) Windows NT 4.0, and (4) Windows 2000 allow remote attackers to cause a denial of service via malformed inputs.
8933| [CVE-2001-0505] Multiple memory leaks in Microsoft Services for Unix 2.0 allow remote attackers to cause a denial of service (memory exhaustion) via a large number of malformed requests to (1) the Telnet service, or (2) the NFS service.
8934| [CVE-2001-0504] Vulnerability in authentication process for SMTP service in Microsoft Windows 2000 allows remote attackers to use incorrect credentials to gain privileges and conduct activites such as mail relaying.
8935| [CVE-2001-0503] Microsoft NetMeeting 3.01 with Remote Desktop Sharing enabled allows remote attackers to cause a denial of service via a malformed string to the NetMeeting service port, aka a variant of the "NetMeeting Desktop Sharing" vulnerability.
8936| [CVE-2001-0351] Microsoft Windows 2000 telnet service allows a local user to make a certain system call that allows the user to terminate a Telnet session and cause a denial of service.
8937| [CVE-2001-0350] Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, which allows local users to execute arbitrary commands by creating a named pipe with the predictable name and associating a malicious program with it, the second of two variants of this vulnerability.
8938| [CVE-2001-0349] Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, which allows local users to execute arbitrary commands by creating a named pipe with the predictable name and associating a malicious program with it, the first of two variants of this vulnerability.
8939| [CVE-2001-0348] Microsoft Windows 2000 telnet service allows attackers to cause a denial of service (crash) via a long logon command that contains a backspace.
8940| [CVE-2001-0347] Information disclosure vulnerability in Microsoft Windows 2000 telnet service allows remote attackers to determine the existence of user accounts such as Guest, or log in to the server without specifying the domain name, via a malformed userid.
8941| [CVE-2001-0346] Handle leak in Microsoft Windows 2000 telnet service allows attackers to cause a denial of service by starting a large number of sessions and terminating them.
8942| [CVE-2001-0345] Microsoft Windows 2000 telnet service allows attackers to prevent idle Telnet sessions from timing out, causing a denial of service by creating a large number of idle sessions.
8943| [CVE-2001-0340] An interaction between the Outlook Web Access (OWA) service in Microsoft Exchange 2000 Server and Internet Explorer allows attackers to execute malicious script code against a user's mailbox via a message attachment that contains HTML code, which is executed automatically.
8944| [CVE-2001-0337] The Microsoft MS01-014 and MS01-016 patches for IIS 5.0 and earlier introduce a memory leak which allows attackers to cause a denial of service via a series of requests.
8945| [CVE-2001-0336] The Microsoft MS00-060 patch for IIS 5.0 and earlier introduces an error which allows attackers to cause a denial of service via a malformed request.
8946| [CVE-2001-0245] Microsoft Index Server 2.0 in Windows NT 4.0, and Indexing Service in Windows 2000, allows remote attackers to read server-side include files via a malformed search request, aka a new variant of the "Malformed Hit-Highlighting" vulnerability.
8947| [CVE-2001-0239] Microsoft Internet Security and Acceleration (ISA) Server 2000 Web Proxy allows remote attackers to cause a denial of service via a long web request with a specific type.
8948| [CVE-2001-0237] Memory leak in Microsoft 2000 domain controller allows remote attackers to cause a denial of service by repeatedly connecting to the Kerberos service and then disconnecting without sending any data.
8949| [CVE-2001-0146] IIS 5.0 and Microsoft Exchange 2000 allow remote attackers to cause a denial of service (memory allocation error) by repeatedly sending a series of specially formatted URL's.
8950| [CVE-2001-0048] The "Configure Your Server" tool in Microsoft 2000 domain controllers installs a blank password for the Directory Service Restore Mode, which allows attackers with physical access to the controller to install malicious programs, aka the "Directory Service Restore Mode Password" vulnerability.
8951| [CVE-2001-0014] Remote Data Protocol (RDP) in Windows 2000 Terminal Service does not properly handle certain malformed packets, which allows remote attackers to cause a denial of service, aka the "Invalid RDP Data" vulnerability.
8952| [CVE-2000-1217] Microsoft Windows 2000 before Service Pack 2 (SP2), when running in a non-Windows 2000 domain and using NTLM authentication, and when credentials of an account are locally cached, allows local users to bypass account lockout policies and make an unlimited number of login attempts, aka the "Domain Account Lockout" vulnerability.
8953| [CVE-2000-1089] Buffer overflow in Microsoft Phone Book Service allows local users to execute arbitrary commands, aka the "Phone Book Service Buffer Overflow" vulnerability.
8954| [CVE-2000-1088] The xp_SetSQLSecurity function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.
8955| [CVE-2000-1087] The xp_proxiedmetadata function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.
8956| [CVE-2000-1086] The xp_printstatements function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.
8957| [CVE-2000-1085] The xp_peekqueue function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.
8958| [CVE-2000-1084] The xp_updatecolvbm function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.
8959| [CVE-2000-1083] The xp_showcolv function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.
8960| [CVE-2000-1082] The xp_enumresultset function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.
8961| [CVE-2000-1081] The xp_displayparamstmt function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.
8962| [CVE-2000-1006] Microsoft Exchange Server 5.5 does not properly handle a MIME header with a blank charset specified, which allows remote attackers to cause a denial of service via a charset="" command, aka the "Malformed MIME Header" vulnerability.
8963| [CVE-2000-0983] Microsoft NetMeeting with Remote Desktop Sharing enabled allows remote attackers to cause a denial of service (CPU utilization) via a sequence of null bytes to the NetMeeting port, aka the "NetMeeting Desktop Sharing" vulnerability.
8964| [CVE-2000-0942] The CiWebHitsFile component in Microsoft Indexing Services for Windows 2000 allows remote attackers to conduct a cross site scripting (CSS) attack via a CiRestriction parameter in a .htw request, aka the "Indexing Services Cross Site Scripting" vulnerability.
8965| [CVE-2000-0929] Microsoft Windows Media Player 7 allows attackers to cause a denial of service in RTF-enabled email clients via an embedded OCX control that is not closed properly, aka the "OCX Attachment" vulnerability.
8966| [CVE-2000-0858] Vulnerability in Microsoft Windows NT 4.0 allows remote attackers to cause a denial of service in IIS by sending it a series of malformed requests which cause INETINFO.EXE to fail, aka the "Invalid URL" vulnerability.
8967| [CVE-2000-0849] Race condition in Microsoft Windows Media server allows remote attackers to cause a denial of service in the Windows Media Unicast Service via a malformed request, aka the "Unicast Service Race Condition" vulnerability.
8968| [CVE-2000-0771] Microsoft Windows 2000 allows local users to cause a denial of service by corrupting the local security policy via malformed RPC traffic, aka the "Local Security Policy Corruption" vulnerability.
8969| [CVE-2000-0756] Microsoft Outlook 2000 does not properly process long or malformed fields in vCard (.vcf) files, which allows attackers to cause a denial of service.
8970| [CVE-2000-0742] The IPX protocol implementation in Microsoft Windows 95 and 98 allows remote attackers to cause a denial of service by sending a ping packet with a source IP address that is a broadcast address, aka the "Malformed IPX Ping Packet" vulnerability.
8971| [CVE-2000-0709] The shtml.exe component of Microsoft FrontPage 2000 Server Extensions 1.1 allows remote attackers to cause a denial of service in some components by requesting a URL whose name includes a standard DOS device name.
8972| [CVE-2000-0654] Microsoft Enterprise Manager allows local users to obtain database passwords via the Data Transformation Service (DTS) package Registered Servers Dialog dialog, aka a variant of the "DTS Password" vulnerability.
8973| [CVE-2000-0524] Microsoft Outlook and Outlook Express allow remote attackers to cause a denial of service by sending email messages with blank fields such as BCC, Reply-To, Return-Path, or From.
8974| [CVE-2000-0495] Microsoft Windows Media Encoder allows remote attackers to cause a denial of service via a malformed request, aka the "Malformed Windows Media Encoder Request" vulnerability.
8975| [CVE-2000-0485] Microsoft SQL Server allows local users to obtain database passwords via the Data Transformation Service (DTS) package Properties dialog, aka the "DTS Password" vulnerability.
8976| [CVE-2000-0402] The Mixed Mode authentication capability in Microsoft SQL Server 7.0 stores the System Administrator (sa) account in plaintext in a log file which is readable by any user, aka the "SQL Server 7.0 Service Pack Password" vulnerability.
8977| [CVE-2000-0331] Buffer overflow in Microsoft command processor (CMD.EXE) for Windows NT and Windows 2000 allows a local user to cause a denial of service via a long environment variable, aka the "Malformed Environment Variable" vulnerability.
8978| [CVE-2000-0305] Windows 95, Windows 98, Windows 2000, Windows NT 4.0, and Terminal Server systems allow a remote attacker to cause a denial of service by sending a large number of identical fragmented IP packets, aka jolt2 or the "IP Fragment Reassembly" vulnerability.
8979| [CVE-2000-0304] Microsoft IIS 4.0 and 5.0 with the IISADMPWD virtual directory installed allows a remote attacker to cause a denial of service via a malformed request to the inetinfo.exe program, aka the "Undelimited .HTR Request" vulnerability.
8980| [CVE-2000-0260] Buffer overflow in the dvwssr.dll DLL in Microsoft Visual Interdev 1.0 allows users to cause a denial of service or execute commands, aka the "Link View Server-Side Component" vulnerability.
8981| [CVE-2000-0232] Microsoft TCP/IP Printing Services, aka Print Services for Unix, allows an attacker to cause a denial of service via a malformed TCP/IP print request.
8982| [CVE-2000-0228] Microsoft Windows Media License Manager allows remote attackers to cause a denial of service by sending a malformed request that causes the manager to halt, aka the "Malformed Media License Request" Vulnerability.
8983| [CVE-2000-0212] InterAccess TelnetID Server 4.0 allows remote attackers to conduct a denial of service via malformed terminal client configuration information.
8984| [CVE-2000-0200] Buffer overflow in Microsoft Clip Art Gallery allows remote attackers to cause a denial of service or execute commands via a malformed CIL (clip art library) file, aka the "Clip Art Buffer Overrun" vulnerability.
8985| [CVE-2000-0168] Microsoft Windows 9x operating systems allow an attacker to cause a denial of service via a pathname that includes file device names, aka the "DOS Device in Path Name" vulnerability.
8986| [CVE-2000-0089] The rdisk utility in Microsoft Terminal Server Edition and Windows NT 4.0 stores registry hive information in a temporary file with permissions that allow local users to read it, aka the "RDISK Registry Enumeration File" vulnerability.
8987| [CVE-2000-0073] Buffer overflow in Microsoft Rich Text Format (RTF) reader allows attackers to cause a denial of service via a malformed control word.
8988| [CVE-2000-0053] Microsoft Commercial Internet System (MCIS) IMAP server allows remote attackers to cause a denial of service via a malformed IMAP request.
8989| [CVE-1999-1591] Microsoft Internet Information Services (IIS) server 4.0 SP4, without certain hotfixes released for SP4, does not require authentication credentials under certain conditions, which allows remote attackers to bypass authentication requirements, as demonstrated by connecting via Microsoft Visual InterDev 6.0.
8990| [CVE-1999-1579] The Cenroll ActiveX control (xenroll.dll) for Terminal Server Editions of Windows NT 4.0 and Windows NT Server 4.0 before SP6 allows remote attackers to cause a denial of service (resource consumption) by creating a large number of arbitrary files on the target machine.
8991| [CVE-1999-1544] Buffer overflow in FTP server in Microsoft IIS 3.0 and 4.0 allows local and sometimes remote attackers to cause a denial of service via a long NLST (ls) command.
8992| [CVE-1999-1164] Microsoft Outlook client allows remote attackers to cause a denial of service by sending multiple email messages with the same X-UIDL headers, which causes Outlook to hang.
8993| [CVE-1999-1070] Buffer overflow in ping CGI program in Xylogics Annex terminal service allows remote attackers to cause a denial of service via a long query parameter.
8994| [CVE-1999-1043] Microsoft Exchange Server 5.5 and 5.0 does not properly handle (1) malformed NNTP data, or (2) malformed SMTP data, which allows remote attackers to cause a denial of service (application error).
8995| [CVE-1999-1016] Microsoft HTML control as used in (1) Internet Explorer 5.0, (2) FrontPage Express, (3) Outlook Express 5, and (4) Eudora, and possibly others, allows remote malicious web site or HTML emails to cause a denial of service (100% CPU consumption) via large HTML form fields such as text inputs in a table cell.
8996| [CVE-1999-1011] The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x exposes unsafe methods, which allows remote attackers to execute arbitrary commands.
8997| [CVE-1999-0999] Microsoft SQL 7.0 server allows a remote attacker to cause a denial of service via a malformed TDS packet.
8998| [CVE-1999-0945] Buffer overflow in Internet Mail Service (IMS) for Microsoft Exchange 5.5 and 5.0 allows remote attackers to conduct a denial of service via AUTH or AUTHINFO commands.
8999| [CVE-1999-0681] Buffer overflow in Microsoft FrontPage Server Extensions (PWS) 3.0.2.926 on Windows 95, and possibly other versions, allows remote attackers to cause a denial of service via a long URL.
9000| [CVE-1999-0680] Windows NT Terminal Server performs extra work when a client opens a new connection but before it is authenticated, allowing for a denial of service.
9001| [CVE-1999-0419] When the Microsoft SMTP service attempts to send a message to a server and receives a 4xx error code, it quickly and repeatedly attempts to redeliver the message, causing a denial of service.
9002| [CVE-1999-0288] The WINS server in Microsoft Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service (process termination) via invalid UDP frames to port 137 (NETBIOS Name Service), as demonstrated via a flood of random packets.
9003|
9004| SecurityFocus - https://www.securityfocus.com/bid/:
9005| [23899] Microsoft Windows Terminal Services Remote Security Restriction Bypass Vulnerability
9006| [10325] Microsoft Windows Terminal Server Patch Unspecified Denial Of Service Vulnerability
9007| [8102] Microsoft Windows Terminal Service Kerberos Double Authorization Data Entry Vulnerability
9008| [8098] Microsoft Windows 2000 Terminal Services Named Pipe System Account Access Vulnerability
9009| [5535] Microsoft Terminal Services Inactive Console Screensaver Lock Failure Weakness
9010| [5376] Microsoft Windows Terminal Services Denial Of Service Vulnerability
9011| [4095] Microsoft Windows 2000 Server Terminal Services Failure To Lock Terminal Vulnerability
9012| [3541] Microsoft Windows Terminal Services False IP Address Vulnerability
9013| [3445] Microsoft Windows 2000/NT Terminal Server Service RDP DoS Vulnerability
9014| [3099] Microsoft Windows Terminal Server Service DoS Vulnerability
9015| [104402] Microsoft Windows Hyper-V CVE-2018-8218 Remote Denial of Service Vulnerability
9016| [104391] Microsoft Windows CVE-2018-8205 Local Denial of Service Vulnerability
9017| [104389] Microsoft Windows Code Integrity Module CVE-2018-1040 Denial of Service Vulnerability
9018| [104361] Microsoft Windows 'HTTP.sys' CVE-2018-8226 Denial of Service Vulnerability
9019| [104359] Microsoft Windows WebDAV CVE-2018-8175 Denial of Service Vulnerability
9020| [104061] Microsoft Windows Host Compute Service Shim CVE-2018-8115 Remote Code Execution Vulnerability
9021| [104060] Microsoft .NET CVE-2018-0765 Denial Of Service Vulnerability
9022| [103705] Microsoft Windows Graphics Component CVE-2018-8116 Denial of Service Vulnerability
9023| [103652] Microsoft Windows SNMP Service CVE-2018-0967 Denial of Service Vulnerability
9024| [103651] Microsoft Windows Remote Desktop Protocol CVE-2018-0976 Denial of Service Vulnerability
9025| [103650] Microsoft Windows 'HTTP.sys' CVE-2018-0956 Denial of Service Vulnerability
9026| [103381] Microsoft Windows Storage Services CVE-2018-0983 Local Privilege Escalation Vulnerability
9027| [103261] Microsoft Windows Hyper-V CVE-2018-0885 Remote Denial of Service Vulnerability
9028| [103226] Microsoft ASP.NET CVE-2018-0808 Denial Of Service Vulnerability
9029| [103225] Microsoft .NET CVE-2018-0875 Denial Of Service Vulnerability
9030| [102924] Microsoft Windows SMB Server CVE-2018-0833 Denial of Service Vulnerability
9031| [102387] Microsoft .NET Framework CVE-2018-0764 Remote Denial of Service Vulnerability
9032| [102361] Microsoft Windows IPSec CVE-2018-0753 Denial of Service Vulnerability
9033| [101835] Microsoft ASP.NET Core CVE-2017-11883 Denial of Service Vulnerability
9034| [101711] Microsoft Windows Search CVE-2017-11788 Remote Denial of Service Vulnerability
9035| [101710] Microsoft ASP.NET Core CVE-2017-11770 Denial of Service Vulnerability
9036| [101192] Microsoft Windows WAV File Handling Denial of Service Vulnerability
9037| [101164] Microsoft Windows Subsystem for Linux CVE-2017-8703 Local Denial of Service Vulnerability
9038| [101140] Microsoft Windows SMB Server CVE-2017-11781 Denial of Service Vulnerability
9039| [100787] Microsoft Windows Hyper-V CVE-2017-8704 Remote Denial of Service Vulnerability
9040| [100079] Microsoft Windows Remote Desktop Protocol CVE-2017-8673 Denial of Service Vulnerability
9041| [100065] Microsoft Windows CVE-2017-8627 Local Denial of Service Vulnerability
9042| [100042] Microsoft Windows Hyper-V CVE-2017-8623 Remote Denial of Service Vulnerability
9043| [100038] Microsoft Windows NetBIOS CVE-2017-0174 Denial of Service Vulnerability
9044| [99432] Microsoft .NET CVE-2017-8585 Denial of Service Vulnerability
9045| [99413] Microsoft Windows Explorer CVE-2017-8587 Denial of Service Vulnerability
9046| [98833] Microsoft Windows CVE-2017-8515 Denial of Service Vulnerability
9047| [98729] Microsoft Windows NTFS File System Denial of Service Vulnerability
9048| [98708] Microsoft Malware Protection Engine CVE-2017-8536 Remote Denial of Service Vulnerability
9049| [98707] Microsoft Malware Protection Engine CVE-2017-8542 Remote Denial of Service Vulnerability
9050| [98705] Microsoft Malware Protection Engine CVE-2017-8537 Remote Denial of Service Vulnerability
9051| [98704] Microsoft Malware Protection Engine CVE-2017-8539 Remote Denial of Service Vulnerability
9052| [98702] Microsoft Malware Protection Engine CVE-2017-8535 Remote Denial of Service Vulnerability
9053| [98658] Microsoft Windows Type 1 Fonts Remote Denial of Service Vulnerability
9054| [98274] Microsoft Windows SMB Server CVE-2017-0273 Remote Denial of Service Vulnerability
9055| [98273] Microsoft Windows SMB Server CVE-2017-0280 Remote Denial of Service Vulnerability
9056| [98263] Microsoft Windows SMB Server CVE-2017-0269 Remote Denial of Service Vulnerability
9057| [98116] Microsoft ASP.NET Core CVE-2017-0247 Denial of Service Vulnerability
9058| [98097] Microsoft Windows CVE-2017-0171 Denial of Service Vulnerability
9059| [97466] Microsoft Windows CVE-2017-0191 Denial of Service Vulnerability
9060| [97448] Microsoft Windows Active Directory CVE-2017-0164 Denial of Service Vulnerability
9061| [97438] Microsoft Windows Hyper-V CVE-2017-0186 Remote Denial of Service Vulnerability
9062| [97437] Microsoft Windows Hyper-V CVE-2017-0185 Remote Denial of Service Vulnerability
9063| [97435] Microsoft Windows Hyper-V CVE-2017-0184 Remote Denial of Service Vulnerability
9064| [97428] Microsoft Windows Hyper-V CVE-2017-0183 Remote Denial of Service Vulnerability
9065| [97427] Microsoft Windows Hyper-V CVE-2017-0182 Remote Denial of Service Vulnerability
9066| [97426] Microsoft Windows Hyper-V CVE-2017-0179 Remote Denial of Service Vulnerability
9067| [97416] Microsoft Windows Hyper-V CVE-2017-0178 Remote Denial of Service Vulnerability
9068| [97127] Microsoft Internet Information Services CVE-2017-7269 Buffer Overflow Vulnerability
9069| [96925] Palo Alto Networks Terminal Services CVE-2017-6356 Information Disclosure Vulnerability
9070| [96642] Microsoft Windows Hyper-V CVE-2017-0098 Remote Denial of Service Vulnerability
9071| [96641] Microsoft Windows Hyper-V CVE-2017-0074 Remote Denial of Service Vulnerability
9072| [96640] Microsoft Windows Hyper-V CVE-2017-0099 Remote Denial of Service Vulnerability
9073| [96639] Microsoft Windows Hyper-V CVE-2017-0097 Remote Denial of Service Vulnerability
9074| [96636] Microsoft Windows Hyper-V CVE-2017-0076 Remote Denial of Service Vulnerability
9075| [96069] Microsoft XML Core Services CVE-2017-0022 Information Disclosure Vulnerability
9076| [96045] Microsoft Office CVE-2017-0029 Denial of Service Vulnerability
9077| [96026] Microsoft Windows Hyper-V CVE-2017-0051 Remote Denial of Service Vulnerability
9078| [95834] Microsoft ASP.NET Core MVC Denial of Service Vulnerability
9079| [95823] Terminal Services Agent CVE-2017-5328 Spoofing Vulnerability
9080| [95818] Palo Alto Networks Terminal Services Agent CVE-2017-5329 Local Privilege Escalation Vulnerability
9081| [95318] Microsoft Windows LSASS CVE-2017-0004 Denial of Service Vulnerability
9082| [94043] Microsoft SQL Server Master Data Services CVE-2016-7251 Cross Site Scripting Vulnerability
9083| [94040] Microsoft Windows CVE-2016-7237 Denial of Service Vulnerability
9084| [94029] Microsoft Office CVE-2016-7244 Denial of Service Vulnerability
9085| [93481] Microsoft Windows 'Cryptography API: Next Generation' Denial of Service Vulnerability
9086| [92850] Microsoft Windows CVE-2016-3369 Denial of Service Vulnerability
9087| [91118] Microsoft Windows Active Directory CVE-2016-3226 Denial of Service Vulnerability
9088| [91113] Microsoft Windows StructuredQuery Component CVE-2016-3230 Denial of Service Vulnerability
9089| [90065] Microsoft Windows Kernel 'Win32k.sys' CVE-2016-0174 Local Privilege Escalation Vulnerability
9090| [89764] Microsoft Internet Explorer CVE-2001-1539 Denial-Of-Service Vulnerability
9091| [87122] Microsoft Outlook Express CVE-2003-0301 Denial-Of-Service Vulnerability
9092| [86214] Microsoft Atlas framework CVE-2007-2380 Denial-Of-Service Vulnerability
9093| [85909] Microsoft XML Core Services CVE-2016-0147 Remote Code Execution Vulnerability
9094| [85908] Microsoft Windows 'HTTP.sys' CVE-2016-0150 Denial of Service Vulnerability
9095| [84758] Microsoft Windows CVE-2008-4323 Denial-Of-Service Vulnerability
9096| [84563] Microsoft Windows DNS CVE-2008-6194 Denial-Of-Service Vulnerability
9097| [84071] Microsoft Windows OpenType Fonts CVE-2016-0120 Remote Denial of Service Vulnerability
9098| [82717] Microsoft .NET Framework CVE-2016-0033 Stack Overflow Denial of Service Vulnerability
9099| [82513] Microsoft Network Policy Server RADIUS Implementation CVE-2016-0050 Denial of Service Vulnerability
9100| [82511] Microsoft Windows CVE-2016-0044 DLL Loading Denial of Service Vulnerability
9101| [82507] Microsoft Active Directory Federation Services CVE-2016-0037 Denial of Service Vulnerability
9102| [82492] Microsoft SMTP Service CVE-1999-0419 Denial-Of-Service Vulnerability
9103| [81429] Microsoft Internet Explorer CVE-2006-3200 Denial-Of-Service Vulnerability
9104| [80383] Microsoft Internet Information Services CVE-2003-1566 Information Disclosure Vulnerability
9105| [79431] Microsoft Internet Explorer CVE-2009-2668 Denial-Of-Service Vulnerability
9106| [79383] Microsoft Internet Explorer CVE-2009-3019 Denial-Of-Service Vulnerability
9107| [78309] Microsoft Internet Explorer CVE-2003-1305 Denial-Of-Service Vulnerability
9108| [77481] Microsoft Windows IPSec CVE-2015-6111 Denial of Service Vulnerability
9109| [76651] Microsoft Internet Explorer Stack Overflow Condition Denial of Service Vulnerability
9110| [76567] Microsoft .NET Framework Model View Controller CVE-2015-2526 Remote Denial of Service Vulnerability
9111| [76559] Microsoft Windows Journal CVE-2015-2516 Denial of Service Vulnerability
9112| [76554] Microsoft Active Directory CVE-2015-2535 Denial of Service Vulnerability
9113| [76259] Microsoft Windows UDDI Services CVE-2015-2475 Cross Site Scripting Vulnerability
9114| [76257] Microsoft XML Core Services CVE-2015-2471 Man in the Middle Information Disclosure Vulnerability
9115| [76232] Microsoft XML Core Services CVE-2015-2440 Information Disclosure Vulnerability
9116| [76229] Microsoft XML Core Services CVE-2015-2434 Man in the Middle Information Disclosure Vulnerability
9117| [75633] Microsoft Windows 'Netlogon' Service CVE-2015-2374 Remote Privilege Escalation Vulnerability
9118| [75023] Microsoft Active Directory Federation Services CVE-2015-1757 Privilege Escalation Vulnerability
9119| [74492] Microsoft Windows Service Control Manager CVE-2015-1702 Remote Privilege Escalation Vulnerability
9120| [74486] Microsoft Windows CVE-2015-1681 Denial of Service Vulnerability
9121| [74482] Microsoft .NET Framework CVE-2015-1672 Remote Denial of Service Vulnerability
9122| [74015] Microsoft Windows Hyper-V CVE-2015-1647 Remote Denial of Service Vulnerability
9123| [74009] Microsoft XML Core Services CVE-2015-1646 Same Origin Policy Security Bypass Vulnerability
9124| [74002] Microsoft Active Directory Federation Services CVE-2015-1638 Information Disclosure Vulnerability
9125| [72921] Microsoft Remote Desktop Protocol CVE-2015-0079 Denial of Service Vulnerability
9126| [72892] Microsoft Windows Adobe Font Driver CVE-2015-0074 Denial of Service Vulnerability
9127| [72886] Microsoft Windows Text Services CVE-2015-0081 Remote Code Execution Vulnerability
9128| [72472] Microsoft Windows Kernel Font Driver CVE-2015-0060 Denial of Service Vulnerability
9129| [71968] Microsoft Windows CVE-2015-0014 Telnet Service Buffer Overflow Vulnerability
9130| [71933] Microsoft Windows Network Policy Server CVE-2015-0015 Remote Denial of Service Vulnerability
9131| [70957] Microsoft XML Core Services CVE-2014-4118 Remote Code Execution Vulnerability
9132| [70949] Microsoft Windows Kernel TrueType Font Parsing CVE-2014-6317 Denial of Service Vulnerability
9133| [70938] Microsoft Active Directory Federation Services CVE-2014-6331 Information Disclosure Vulnerability
9134| [70937] Microsoft Internet Information Services CVE-2014-4078 Security Bypass Vulnerability
9135| [69603] Microsoft .NET Framework CVE-2014-4072 Remote Denial of Service Vulnerability
9136| [69592] Microsoft Lync Server CVE-2014-4071 Remote Denial of Service Vulnerability
9137| [69586] Microsoft Lync Server CVE-2014-4068 Remote Denial of Service Vulnerability
9138| [69112] Microsoft Windows Installer Service CVE-2014-1814 Local Privilege Escalation Vulnerability
9139| [69088] Microsoft SQL Server CVE-2014-4061 Local Denial of Service Vulnerability
9140| [69071] Microsoft SQL Server Master Data Services CVE-2014-1820 Cross Site Scripting Vulnerability
9141| [68393] Microsoft Service Bus AMQP Message Handling Remote Denial of Service Vulnerability
9142| [68076] Microsoft Malware Protection Engine CVE-2014-2779 Remote Denial of Service Vulnerability
9143| [67895] Microsoft XML Core Services CVE-2014-1816 Information Disclosure Vulnerability
9144| [67888] Microsoft Windows TCP/IP Protocol CVE-2014-1811 Remote Denial of Service Vulnerability
9145| [67758] Microsoft Internet Explorer 'TryGetValueAndRemove()' Method Remote Denial of Service Vulnerability
9146| [67743] Microsoft Windows 'GreSetPaletteEntries()' Local Denial of Service Vulnerability
9147| [67742] Microsoft Windows Touch Injection API Local Denial of Service Vulnerability
9148| [67281] Microsoft Windows iSCSI Connections Handling CVE-2014-0256 Remote Denial of Service Vulnerability
9149| [67280] Microsoft Windows iSCSI Packets Handling CVE-2014-0255 Remote Denial of Service Vulnerability
9150| [65854] Microsoft XMLDOM ActiveX Control CVE-2013-7332 Remote Denial of Service Vulnerability
9151| [65415] Microsoft .NET Framework CVE-2014-0253 Remote Denial of Service Vulnerability
9152| [65409] Microsoft Windows TCP/IP IPv6 Router Advertisement Remote Denial of Service Vulnerability
9153| [65407] Microsoft XML Core Services CVE-2014-0266 Information Disclosure Vulnerability
9154| [64724] Microsoft Dynamics AX CVE-2014-0261 Remote Denial of Service Vulnerability
9155| [64091] Microsoft Windows Kernel 'Win32k.sys' CVE-2013-5058 Local Denial of Service Vulnerability
9156| [64057] Microsoft Windows Kernel 'IsHandleEntrySecure()' Function Local Denial of Service Vulnerability
9157| [63777] Microsoft Word '.doc' File Remote Denial of Service Vulnerability
9158| [63561] Microsoft Windows XML Digital Signatures CVE-2013-3869 Remote Denial of Service Vulnerability
9159| [62820] Microsoft .NET Framework CVE-2013-3860 Remote Denial of Service Vulnerability
9160| [62807] Microsoft .NET Framework CVE-2013-3861 Remote Denial of Service Vulnerability
9161| [62205] Microsoft SharePoint CVE-2013-0081 Denial of Service Vulnerability
9162| [62184] Microsoft Windows Active Directory CVE-2013-3868 Denial of Service Vulnerability
9163| [62182] Microsoft Windows Service Control Manager CVE-2013-3862 Local Privilege Escalation Vulnerability
9164| [61685] Microsoft NAT Driver CVE-2013-3182 Denial of Service Vulnerability
9165| [61672] Microsoft Active Directory Federation Services CVE-2013-3185 Information Disclosure Vulnerability
9166| [61666] Microsoft Windows TCP/IP ICMPv6 CVE-2013-3183 Remote Denial of Service Vulnerability
9167| [61334] Microsoft Windows Movie Maker '.wav' File Denial of Service Vulnerability
9168| [60951] Microsoft Windows Kernel 'Win32k.sys' CVE-2013-3172 Local Denial of Service Vulnerability
9169| [60407] Microsoft Windows Print Spooler Service CVE-2013-1339 Local Privilege Escalation Vulnerability
9170| [60358] Microsoft Windows TCP/IP Driver CVE-2013-3138 Remote Denial of Service Vulnerability
9171| [60159] Microsoft Windows Kernel 'Win32k.sys' CVE-2013-3661 Local Denial Of Service Vulnerability
9172| [59784] Microsoft Windows 'HTTP.sys' Remote Denial of Service Vulnerability
9173| [58853] Microsoft Windows CVE-2013-1291 OpenType Font Parsing Remote Denial of Service Vulnerability
9174| [58848] Microsoft Windows Active Directory CVE-2013-1282 Denial of Service Vulnerability
9175| [58560] Microsoft Windows CVE-2013-2558 Denial of Service Vulnerability
9176| [58372] Microsoft SharePoint CVE-2013-0085 Denial of Service Vulnerability
9177| [57961] Microsoft Windows 'ZwSetInformationProcess()' Local Denial of Service Vulnerability
9178| [57858] Microsoft Windows TCP/IP TCP FIN WAIT CVE-2013-0075 Remote Denial of Service Vulnerability
9179| [57853] Microsoft Windows NFS Server NULL Pointer Dereference Remote Denial of Service Vulnerability
9180| [57142] Microsoft Windows Print Spooler Service CVE-2013-0011 Code Execution Vulnerability
9181| [57141] Microsoft OData CVE-2013-0005 Denial of Service Vulnerability
9182| [57122] Microsoft XML Core Services CVE-2013-0007 Remote Code Execution Vulnerability
9183| [57116] Microsoft XML Core Services CVE-2013-0006 Remote Code Execution Vulnerability
9184| [57002] Microsoft Internet Explorer Crafted HTML Stack Overflow Denial of Service Vulnerability
9185| [56836] Microsoft Exchange Server RSS Feed Remote Denial of Service Vulnerability
9186| [56440] Microsoft IIS FTP Service CVE-2012-2532 Remote Command Injection Vulnerability
9187| [56312] Microsoft Office Publisher '.pub' File Denial of Service Vulnerability
9188| [56311] Microsoft Paint '.bmp' Denial of Service Vulnerability
9189| [56309] Microsoft Office Excel CVE-2012-5672 Denial of Service Vulnerability
9190| [56304] Microsoft Office Excel 2010 Memory Corruption Denial of Service Vulnerability
9191| [56303] RETIRED: Microsoft Windows Help Viewer Memory Corruption Denial of Service Vulnerability
9192| [56239] Microsoft Office Picture Manager Memory Corruption Denial of Service Vulnerability
9193| [56235] Microsoft Word Stack Overflow Denial Of Service Vulnerability
9194| [55778] Microsoft Windows Kerberos CVE-2012-2551 Denial of Service Vulnerability
9195| [55202] Microsoft Indexing Service 'ixsso.dll' ActiveX Control Denial of Service Vulnerability
9196| [54921] Microsoft Windows Remote Administration Protocol (RAP) Remote Denial of Service Vulnerability
9197| [54276] Microsoft IIS Multiple FTP Command Request Denial of Service Vulnerability
9198| [54012] Microsoft Windows OpenType 'atmfd.dll' Denial of Service Vulnerability
9199| [53934] Microsoft XML Core Services CVE-2012-1889 Remote Code Execution Vulnerability
9200| [53751] Microsoft Wordpad '.doc' File NULL Pointer Dereference Denial Of Service Vulnerability
9201| [53363] Microsoft .NET Framework Index Comparison Denial Of Service Vulnerability
9202| [53343] Microsoft Windows Kernel 'Win32k.sys' Local Denial of Service Vulnerability
9203| [52374] Microsoft Windows DNS Server (CVE-2012-0006) Remote Denial of Service Vulnerability
9204| [52354] Microsoft Remote Desktop Protocol Service CVE-2012-0152 Denial of Service Vulnerability
9205| [52332] Microsoft Windows 'DirectWrite' API Denial of Service Vulnerability
9206| [51527] Microsoft Internet Information Services DOS Device Request Security Bypass Vulnerability
9207| [51186] Microsoft ASP.NET Hash Collision Denial Of Service Vulnerability
9208| [51179] Microsoft Windows Phone Messages Processing Denial of Service Vulnerability
9209| [50510] Microsoft Windows Kernel TrueType Font Parsing (CVE-2011-2004) Denial of Service Vulnerability
9210| [49998] Microsoft Host Integration Server CVE-2011-2008 Remote Denial Of Service Vulnerability
9211| [49997] Microsoft Host Integration Server CVE-2011-2007 Remote Denial Of Service Vulnerability
9212| [49980] Microsoft Forefront Unified Access Gateway Null Session Cookie Denial of Service Vulnerability
9213| [49973] Microsoft Windows Kernel 'Win32k.sys' TrueType Font File Remote Denial of Service Vulnerability
9214| [49489] Microsoft Windows stdout/stdin Local Denial of Service Vulnerability
9215| [49165] Microsoft Internet Explorer 9 'Iedvtool.dll' Malformed HTML Denial of Service Vulnerability
9216| [49164] Microsoft Windows DHCPv6 Packets Remote Denial Of Service Vulnerability
9217| [49019] Microsoft Windows DNS Server Uninitialized Memory Remote Denial of Service Vulnerability
9218| [48997] Microsoft Windows Kernel CVE-2011-1971 Remote Denial of Service Vulnerability
9219| [48995] Microsoft Remote Desktop Protocol CVE-2011-1968 Denial of Service Vulnerability
9220| [48990] Microsoft Windows TCP/IP QOS CVE-2011-1965 Remote Denial Of Service Vulnerability
9221| [48987] Microsoft Windows TCP/IP ICMP CVE-2011-1871 Remote Denial Of Service Vulnerability
9222| [48187] Microsoft Windows Distributed File System Remote Denial of Service Vulnerability
9223| [48185] Microsoft Windows SMB Server Remote Denial of Service Vulnerability
9224| [48179] Microsoft Hyper-V VMBus 'vmswitch.sys' Denial of Service Vulnerability
9225| [48175] Microsoft Active Directory Certificate Services Web Enrollment Cross-Site Scripting Vulnerability
9226| [47897] Microsoft Windows 'nsiproxy.sys' Driver Local Denial of Service Vulnerability
9227| [47730] Microsoft Windows Internet Name Service (WINS) Failed Response Remote Code Execution Vulnerability
9228| [47724] Microsoft Silverlight Prior to 4.0.60310 Multiple Remote Denial Of Service Vulnerabilities
9229| [47413] Microsoft Windows Media Player '.ogg' File Remote Denial Of Service Vulnerability
9230| [47315] Microsoft Host Integration Server Multiple Remote Denial Of Service Vulnerabilities
9231| [47279] Microsoft Windows 'AFD.sys' Driver Local Denial of Service Vulnerability
9232| [46773] Microsoft .NET Runtime Optimization Service Local Privilege Escalation Vulnerability
9233| [46145] Microsoft Active Directory Service Principal Names (CVE-2011-0040) Denial Of Service Vulnerability
9234| [46099] Terminal Server Client '.rdp' File Processing Remote Denial of Service Vulnerability
9235| [45542] Microsoft IIS FTP Service Remote Buffer Overflow Vulnerability
9236| [45297] Microsoft Exchange Server 2007 Infinite Loop Remote Denial of Service Vulnerability
9237| [45293] Microsoft Hyper-V VMBus Denial of Service Vulnerability
9238| [45271] Microsoft 'Netlogon' RPC Null Pointer Dereference Remote Denial of Service Vulnerability
9239| [45065] Microsoft Outlook File Attachment Denial Of Service Vulnerability
9240| [44357] Microsoft Windows Kernel Task Scheduler Service Local Privilege Escalation Vulnerability
9241| [44287] Microsoft Windows Mobile Overly Long vCard Name Field Denial of Service Vulnerability
9242| [43780] Microsoft Windows SChannel TLSv1 Remote Denial of Service Vulnerability
9243| [43561] Microsoft Internet Information Services Remote Script Code Execution Vulnerability
9244| [43465] Microsoft MPEG Layer-3 Audio Decoder Divide-By-Zero Denial of Service Vulnerability
9245| [43322] Microsoft Paint Memory Corruption Denial Of Service Vulnerability
9246| [43140] Microsoft IIS Repeated Parameter Request Denial of Service Vulnerability
9247| [43073] Microsoft Windows Print Spooler Service Remote Code Execution Vulnerability
9248| [42606] Microsoft Windows 'IcmpSendEcho()' Local Denial Of Service Vulnerability
9249| [42496] Microsoft Windows 'win32k!GreStretchBltInternal()' Local Denial Of Service Vulnerability
9250| [42300] Microsoft XML Core Service Msxml2.XMLHTTP.3.0 Response Handling Memory Corruption Vulnerability
9251| [42278] Microsoft Windows Service Isolation Bypass Local Privilege Escalation Vulnerability
9252| [42267] Microsoft Windows SMB Stack Exhaustion Denial of Service Vulnerability
9253| [42263] Microsoft Windows SMB Variable Validation Denial of Service Vulnerability
9254| [42251] Microsoft Windows TCP/IP IPv6 Extension Header Remote Denial of Service Vulnerability
9255| [42250] Microsoft Windows 'xxxRealDrawMenuItem()' Function Local Denial Of Service Vulnerability
9256| [42221] Microsoft Windows Kernel Access Control Lists Local Denial of Service Vulnerability
9257| [41990] Microsoft Internet Explorer Frame Border Property Denial of Service Vulnerability
9258| [41794] Microsoft DirectX DirectPlay Multiple Denial Of Service Vulnerabilities
9259| [40559] Microsoft SharePoint Help Page Remote Denial of Service Vulnerability
9260| [40487] Microsoft Internet Explorer CSS 'expression' Remote Denial of Service Vulnerability
9261| [39631] Microsoft Windows 'SfnINSTRING' Local Denial Of Service Vulnerability
9262| [39356] Microsoft Windows Media Service Transport Information Packet Stack Buffer Overflow Vulnerability
9263| [39322] Microsoft Windows Kernel Exception Handling Local Denial Of Service Vulnerability
9264| [39320] Microsoft Windows Kernel Image File Relocation Local Denial Of Service Vulnerability
9265| [39319] Microsoft Windows Kernel Virtual Path Local Denial Of Service Vulnerability
9266| [39318] Microsoft Windows Kernel Invalid Registry Key Local Denial Of Service Vulnerability
9267| [39309] Microsoft Windows Kernel Symbolic Link Local Denial Of Service Vulnerability
9268| [39308] Microsoft Windows SMTP Server MX Record Denial of Service Vulnerability
9269| [39297] Microsoft Windows Kernel NULL Pointer Local Denial Of Service Vulnerability
9270| [39221] Microsoft Office Communicator SIP Remote Denial of Service Vulnerability
9271| [38579] Microsoft Windows '.ani' File 'tagBITMAPINFOHEADER' Denial of Service Vulnerability
9272| [38420] Microsoft Windows Unspecified Denial of Service Vulnerability
9273| [38113] Microsoft Hyper-V Local Denial of Service Vulnerability
9274| [38110] Microsoft Windows Kerberos 'Ticket-Granting-Ticket' Remote Denial of Service Vulnerability
9275| [38064] Microsoft Windows TCP/IP Selective Acknowledgement Remote Denial of Service Vulnerability
9276| [38054] Microsoft Windows SMB Memory Corruption Remote Denial of Service Vulnerability
9277| [38051] Microsoft Windows SMB Null Pointer Remote Denial of Service Vulnerability
9278| [37877] Microsoft Internet Explorer Null Pointer Dereference Denial of Service Vulnerabilities
9279| [37218] Microsoft Windows LSASS ISAKMP Message Remote Denial of Service Vulnerability
9280| [37214] Microsoft Active Directory Federation Services Header Validation Remote Code Execution Vulnerability
9281| [36989] Microsoft Windows SMB Packet Remote Denial of Service Vulnerability
9282| [36919] Microsoft Windows Web Services on Devices API Remote Code Execution Vulnerability
9283| [36918] Microsoft Active Directory LDAP Request Stack Exhaustion Denial Of Service Vulnerability
9284| [36817] Microsoft SharePoint Team Services Download Feature Source Code Information Disclosure Vulnerability
9285| [36629] Microsoft Indexing Service ActiveX Control Remote Code Execution Vulnerability
9286| [36625] Microsoft Windows Kernel Exception Handler Local Denial Of Service Vulnerability
9287| [36595] Microsoft Windows SMB2 Field Validation Remote Denial of Service Vulnerability
9288| [36593] Microsoft Windows LSASS NTLM Implementation Remote Denial of Service Vulnerability
9289| [36276] RETIRED: Microsoft IIS FTPd Globbing Functionality Remote Denial of Service Vulnerability
9290| [36273] Microsoft IIS FTPd Globbing Functionality Remote Denial of Service Vulnerability
9291| [36269] Microsoft Windows TCP/IP Orphaned Connection Remote Denial of Service Vulnerability
9292| [36070] Microsoft Internet Explorer 'li' Element Denial of Service Vulnerability
9293| [35985] Microsoft ASP.NET Request Scheduling Denial Of Service Vulnerability
9294| [35972] Microsoft Windows Workstation Service Double Free Remote Code Execution Vulnerability
9295| [35969] Microsoft Message Queuing Service NULL Pointer Dereference Local Privilege Escalation Vulnerability
9296| [35941] Microsoft Internet Explorer 8 Denial of Service Vulnerability
9297| [35799] Microsoft Internet Explorer 'findText()' Unicode Parsing Denial of Service Vulnerability
9298| [35620] Microsoft Internet Explorer 'AddFavorite' Method Denial of Service Vulnerability
9299| [35225] Microsoft Active Directory Memory Leak Denial Of Service Vulnerability
9300| [34587] Microsoft Windows Media Player WAV File Multiple Denial of Service Vulnerabilities
9301| [34586] Microsoft GDI+ Plugin PNG File Infinite Loop Denial of Service Vulnerability
9302| [34585] Microsoft Windows Media Player MIDI File Denial of Service Vulnerability
9303| [34478] Microsoft Internet Explorer File Download Denial of Service Vulnerability
9304| [34443] Microsoft Windows RPCSS Service Isolation Local Privilege Escalation Vulnerability
9305| [34442] Microsoft Windows WMI Service Isolation Local Privilege Escalation Vulnerability
9306| [34414] Microsoft ISA Server and Forefront Threat Management Gateway Denial of Service Vulnerability
9307| [34258] Microsoft Windows Services for UNIX / Subsystem for UNIX-based Applications Multiple Vulnerabilities
9308| [33803] Microsoft XML Core Services XMLHttpRequest 'SetCookie2' Header Information Disclosure Vulnerability
9309| [33494] Microsoft Internet Explorer HTML Form Value Denial of Service Vulnerability
9310| [33406] Sun Solaris Pseudo-terminal Driver (pty(7D)) Local Denial Of Service Vulnerability
9311| [33149] Microsoft Internet Explorer 'screen[]' Remote Denial of Service Vulnerability
9312| [33136] Microsoft Exchange Server EMSMDB2 MAPI Command Remote Denial of Service Vulnerability
9313| [32702] Microsoft Outlook Express Malformed MIME Message Denial Of Service Vulnerability
9314| [32653] Microsoft Windows Media Components 'Service Principle Name' Remote Code Execution Vulnerability
9315| [32341] Microsoft Communicator RTCP Unspecified Remote Denial of Service Vulnerability
9316| [32206] Microsoft Windows 'UnhookWindowsHookEx' Local Denial Of Service Vulnerability
9317| [32204] Microsoft XML Core Services Transfer Encoding Cross Domain Information Disclosure Vulnerability
9318| [32155] Microsoft XML Core Services DTD Cross Domain Information Disclosure Vulnerability
9319| [32077] Microsoft Windows Media Player MIDI File MThd Header Parsing Denial of Service Vulnerability
9320| [31996] Microsoft DebugDiag 'CrashHangExt.dll' ActiveX Control Remote Denial of Service Vulnerability
9321| [31874] Microsoft Windows Server Service RPC Handling Remote Code Execution Vulnerability
9322| [31682] Microsoft Windows Internet Printing Service Integer Overflow Vulnerability
9323| [31637] Microsoft Message Queuing Service RPC Query Heap Corruption Vulnerability
9324| [31570] Microsoft Windows Vista Local Denial Of Service Vulnerability
9325| [31432] Microsoft GDI+ 'GDIPLUS.dll' ICO File Divide-By-Zero Denial of Service Vulnerability
9326| [31420] Microsoft Windows Mobile Overly Long Bluetooth Device Name Denial of Service Vulnerability
9327| [31399] Microsoft WordPad '.doc' File Remote Denial of Service Vulnerability
9328| [31215] Microsoft Internet Explorer Malfromed PNG File Remote Denial of Service Vulnerability
9329| [31179] Microsoft Windows WRITE_ANDX SMB Processing Remote Denial Of Service Vulnerability
9330| [30881] PureMessage for Microsoft Exchange RTF Multiple Denial Of Service Vulnerabilities
9331| [30814] Microsoft Windows Media Services 'nskey.dll' ActiveX Control Remote Buffer Overflow Vulnerability
9332| [30357] Minix Psuedo Terminal Denial of Service Vulnerability
9333| [29991] Microsoft Dynamics GP Denial of Service and Multiple Remote Buffer Overflow Vulnerabilities
9334| [29584] Microsoft Windows Active Directory LDAP Request Validation Remote Denial Of Service Vulnerability
9335| [29509] Microsoft Windows PGM Invalid Fragment Remote Denial Of Service Vulnerability
9336| [29508] Microsoft Windows PGM Invalid Length Remote Denial Of Service Vulnerability
9337| [29073] Microsoft Malware Protection Engine Disk Space Exhaustion Remote Denial Of Service Vulnerability
9338| [29060] Microsoft Malware Protection Engine File Processing Remote Denial Of Service Vulnerability
9339| [28946] Microsoft Excel JavaScript Code Remote Denial Of Service Vulnerability
9340| [28580] Microsoft Internet Explorer XDR Prototype Hijacking Denial of Service Vulnerability
9341| [28553] Microsoft Windows DNS Client Service Response Spoofing Vulnerability
9342| [27676] Microsoft Internet Information Services ASP Remote Code Execution Vulnerability
9343| [27638] Microsoft Windows Active Directory LDAP Request Validation Remote Denial Of Service Vulnerability
9344| [27634] Microsoft Windows Vista DHCP Remote Denial Of Service Vulnerability
9345| [27139] Microsoft Windows TCP/IP ICMP Remote Denial Of Service Vulnerability
9346| [26982] Microsoft Office Publisher Multiple Denial Of Service Vulnerabilities
9347| [26981] Microsoft Word Wordart Doc Denial Of Service Vulnerability
9348| [26797] Microsoft Message Queuing Service Stack Buffer Overflow Vulnerability
9349| [26648] Microsoft Windows Media Player AIFF Parsing Divide-By-Zero Denial of Service Vulnerability
9350| [26414] Microsoft Forms 2.0 ActiveX Control Memory Access Violation Denial of Service Vulnerabilities
9351| [26405] Microsoft Office Web Component Memory Access Violation Denial of Service Vulnerability
9352| [25974] Microsoft Windows RPC NTLMSSP Remote Denial Of Service Vulnerability
9353| [25816] Microsoft Windows Explorer PNG Image Local Denial Of Service Vulnerability
9354| [25795] Microsoft Live Messenger Shared Files Denial of Service Vulnerability
9355| [25620] Microsoft Windows Services for UNIX Local Privilege Escalation Vulnerability
9356| [25301] Microsoft XML Core Services SubstringData Integer Overflow Vulnerability
9357| [25236] Microsoft Windows Media Player AU Divide-By-Zero Denial of Service Vulnerability
9358| [25222] Microsoft Internet Explorer Position:Relative Denial of Service Vulnerability
9359| [25207] Microsoft Windows Explorer JPG File Denial of Service Vulnerability
9360| [25201] Microsoft Windows Calendar ICS File Denial of Service Vulnerability
9361| [25066] Microsoft Windows ARP Request Denial of Service Vulnerability
9362| [25013] Microsoft Windows Explorer GIF File Denial of Service Vulnerability
9363| [24816] Microsoft Windows Vista Kernel Unspecified Remote Denial Of Service Vulnerability
9364| [24796] Microsoft Windows Active Directory LDAP Request Validation Remote Denial Of Service Vulnerability
9365| [24744] Microsoft Internet Explorer Zone Denial of Service Vulnerability
9366| [24691] Microsoft Excel Sheet Name Remote Denial Of Service Vulnerability
9367| [24469] Microsoft Windows CE POP3 Remote Denial of Service Vulnerability
9368| [24424] Microsoft Windows CE TCP/IP Requests Denial of Service Vulnerability
9369| [24420] Microsoft Windows CE Pocket Internet Explorer PNG Denial of Service Vulnerability
9370| [24395] Microsoft Windows CE Internet Explorer Remote Denial of Service Vulnerability
9371| [24394] Microsoft Windows CE Internet Explorer SSL Unspecified Denial Of Service Vulnerability
9372| [24393] Microsoft Windows CE Internet Explorer Content-Type Denial of Service Vulnerability
9373| [24391] Microsoft Windows CE Malformed RNDIS Packet Remote Denial of Service Vulnerability
9374| [24346] Microsoft Windows GDI+ ICO File Remote Denial of Service Vulnerability
9375| [24188] Microsoft DirectX Media DXTMSFT.DLL ActiveX Control Multiple Denial of Service Vulnerabilities
9376| [24129] Microsoft Visual Basic 6.0 Project Company Name Denial of Service Vulnerability
9377| [23810] Microsoft Exchange IMAP Command Processing Remote Denial of Service Vulnerability
9378| [23808] Microsoft Exchange iCal Request Remote Denial of Service Vulnerability
9379| [23566] OpenAFS for Microsoft Windows Local Denial of Service Vulnerability
9380| [23373] Microsoft Windows Explorer ANI File Denial of Service Vulnerability
9381| [23321] Microsoft Windows Explorer BMP Image Denial of Service Vulnerability
9382| [23275] Microsoft Windows GDI WMF Remote Denial of Service Vulnerability
9383| [23271] Microsoft Windows Vista LLTD Mapper EMIT Packet Remote Denial Of Service Vulnerability
9384| [23266] Microsoft Windows Vista ARP Table Entries Denial of Service Vulnerability
9385| [23178] Microsoft Internet Explorer HTML Denial of Service Vulnerability
9386| [22938] Microsoft Windows WinMM.DLL WAV Files Remote Denial of Service Vulnerability
9387| [22847] Microsoft Windows OLE32.DLL Word Document Handling Denial Of Service Vulnerability
9388| [22724] Microsoft Office Publisher Remote Denial of Service Vulnerability
9389| [22717] Microsoft Excel NULL Pointer Dereference Denial Of Service Vulnerability
9390| [22716] Microsoft Office 2003 Denial of Service Vulnerability
9391| [22715] Microsoft Windows Explorer WMF File Handling Denial of Service Vulnerability
9392| [22500] Microsoft Internet Explorer for Windows Mobile Remote WML Content Denial of Service Vulnerability
9393| [22499] Microsoft Windows Image Acquisition Service Privilege Escalation Vulnerability
9394| [22481] Microsoft Windows Shell Hardware Detection Service Privilege Escalation Vulnerability
9395| [22408] Microsoft Internet Explorer Malformed HTML For Script Denial of Service Vulnerability
9396| [22343] Microsoft Windows Mobile Multiple Remote Denial of Service Vulnerabilities
9397| [22288] Microsoft Internet Explorer Multiple ActiveX Controls Denial of Service Vulnerabilities
9398| [21992] Microsoft Windows Explorer WMF File Denial of Service Vulnerability
9399| [21937] Microsoft Outlook Malformed Email Header Remote Denial of Service Vulnerability
9400| [21872] Microsoft XML Core Services Race Condition Memory Corruption Vulnerability
9401| [21865] Apache And Microsoft IIS Range Denial of Service Vulnerability
9402| [21688] Microsoft Windows CSRSS HardError Messages Denial of Service Vulnerability
9403| [21649] Microsoft Outlook ActiveX Control Remote Internet Explorer Denial of Service Vulnerability
9404| [21537] Microsoft Windows SNMP Service Remote Code Execution Vulnerability
9405| [21495] Microsoft Windows 2000 Remote Installation Service Remote Code Execution Vulnerability
9406| [21466] Microsoft Internet Explorer CSS Width Element Denial of Service Vulnerability
9407| [21447] Microsoft Internet Explorer Frame Src Denial Of Service Vulnerability
9408| [21401] Microsoft Windows Print Spooler GetPrinterData Denial of Service Vulnerability
9409| [21262] Microsoft Office HTMLMARQ.OCX Library Denial of Service Vulnerability
9410| [21083] Microsoft Active Directory Unspecified Denial of Service Vulnerability
9411| [21023] Microsoft Windows Client Service For Netware Remote Code Execution Vulnerability
9412| [20985] Microsoft Windows Workstation Service NetpManageIPCConnect Remote Code Execution Vulnerability
9413| [20984] Microsoft Client Service for Netware Denial of Service Vulnerability
9414| [20915] Microsoft XML Core Service XMLHTTP ActiveX Control Remote Code Execution Vulnerability
9415| [20875] Microsoft Internet Explorer MHTML Denial of Service Vulnerability
9416| [20812] Microsoft Internet Explorer RemoveChild Denial of Service Vulnerability
9417| [20804] Microsoft Windows NAT Helper Remote Denial of Service Vulnerability
9418| [20495] Microsoft PowerPoint Remote Denial of Service Vulnerability
9419| [20373] Microsoft Windows SMB Rename Remote Denial of Service Vulnerability
9420| [20339] Microsoft XML Core Services Information Disclosure Vulnerability
9421| [20338] Microsoft Windows XML Core Services XSLT Buffer Overrun Vulnerability
9422| [19927] Microsoft Indexing Service Query Validation Cross-Site Scripting Vulnerability
9423| [19640] Microsoft Internet Explorer Multiple COM Object Color Property Denial of Service Vulnerabilities
9424| [19572] Microsoft Internet Explorer Visual Studio COM Object Instantiation Denial of Service Vulnerability
9425| [19530] Microsoft Internet Explorer MSOE.DLL Denial Of Service Vulnerability
9426| [19521] Microsoft Internet Explorer IMSKDIC.DLL Denial Of Service Vulnerability
9427| [19520] Microsoft Windows PNG File IHDR Block Denial of Service Vulnerability
9428| [19409] Microsoft Windows Server Service Remote Buffer Overflow Vulnerability
9429| [19365] Microsoft Windows GDI32.DLL WMF Remote Denial of Service Vulnerability
9430| [19364] Microsoft Internet Explorer IFrame Refresh Denial of Service Vulnerability
9431| [19301] RETIRED: Microsoft Windows GDI Plus Library Remote Denial Of Service Vulnerability
9432| [19300] Microsoft Windows Routing and Remote Access Denial of Service Vulnerability
9433| [19228] Microsoft Internet Explorer Deleted Frame Object Denial Of Service Vulnerability
9434| [19227] Microsoft Internet Explorer ADODB.Recordset NextRecordset Denial of Service Vulnerability
9435| [19221] Microsoft Windows Graphical Device Interface Plus Library Denial Of Service Vulnerability
9436| [19215] Microsoft Windows SMB PIPE Remote Denial of Service Vulnerability
9437| [19140] Microsoft Internet Explorer Native Function Iterator Denial Of Service Vulnerability
9438| [19135] Microsoft Windows Remote Denial of Service Vulnerability
9439| [19113] Microsoft Internet Explorer Multiple Object ListWidth Property Denial Of Service Vulnerability
9440| [19109] Microsoft Internet Explorer Internet.HHCtrl Click Denial Of Service Vulnerability
9441| [19102] Microsoft Internet Explorer String To Binary Function Denial Of Service Vulnerability
9442| [19092] Microsoft Internet Explorer Content-Type Denial Of Service Vulnerability
9443| [19079] Microsoft Internet Explorer OVCtl Denial Of Service Vulnerability
9444| [19069] Microsoft Internet Explorer DataSourceControl Denial of Service Vulnerability
9445| [19029] Microsoft Internet Explorer DXImageTransform Properties Denial Of Service Vulnerability
9446| [19013] Microsoft Internet Explorer MHTMLFile Denial Of Service Vulnerability
9447| [18995] Microsoft Windows Registry Access Local Denial of Service Vulnerability
9448| [18960] Microsoft Internet Explorer RevealTrans Denial Of Service Vulnerability
9449| [18946] Microsoft Internet Explorer TriEditDocument Denial Of Service Vulnerability
9450| [18929] Microsoft Internet Explorer HtmlDlgSafeHelper Remote Denial Of Service Vulnerability
9451| [18923] Microsoft Windows DHCP Client Service Remote Code Execution Vulnerability
9452| [18903] Microsoft Internet Explorer Object.Microsoft.DXTFilter Denial Of Service Vulnerability
9453| [18902] Microsoft Internet Explorer DirectAnimation.DAUserData Denial Of Service Vulnerability
9454| [18900] Microsoft Internet Explorer 6 RDS.DataControl Denial of Service Vulnerability
9455| [18873] Microsoft Internet Explorer Table Frameset Denial Of Service Vulnerability
9456| [18855] Microsoft Internet Explorer Structured Graphics Control Denial Of Service Vulnerability
9457| [18820] Microsoft Internet Explorer Href Title Denial Of Service Vulnerability
9458| [18773] Microsoft Internet Explorer ADODB.Recordset Filter Property Denial of Service Vulnerability
9459| [18771] Microsoft Internet Explorer OutlookExpress.AddressBook Denial of Service Vulnerability
9460| [18736] Microsoft Internet Explorer 7 Denial of Service Vulnerability
9461| [18639] Microsoft Windows Live Messenger Contact List Processing Remote Denial of Service Vulnerability
9462| [18389] Microsoft Windows RPC Mutual Authentication Service Spoofing Vulnerability
9463| [18357] Microsoft SMB Driver Local Denial Of Service Vulnerability
9464| [18311] Microsoft NetMeeting Remote Memory Corruption Denial of Service Vulnerability
9465| [18112] Microsoft Internet Explorer Malformed HTML Parsing Denial of Service Vulnerability
9466| [17932] Microsoft Internet Explorer Position CSS Denial of Service Vulnerability
9467| [17906] Microsoft Windows MSDTC Invalid Memory Access Denial Of Service Vulnerability
9468| [17252] Microsoft Office XP Array Index Denial of Service Vulnerability
9469| [17188] Microsoft ASP.NET COM Components W3WP Remote Denial Of Service Vulnerability
9470| [16978] Microsoft Internet Explorer Java Applet Handling Denial of Service Vulnerability
9471| [16782] Microsoft Word Malformed Document Denial Of Service Vulnerability
9472| [16645] Microsoft Windows IGMPv3 Denial of Service Vulnerability
9473| [16463] Microsoft Internet Explorer URLMon.DLL Denial Of Service Vulnerability
9474| [16441] Microsoft Internet Explorer Flash ActionScript JScript Handling Denial of Service Vulnerability
9475| [16240] Microsoft Internet Explorer Malformed IMG and XML Parsing Denial of Service Vulnerability
9476| [16079] Microsoft Internet Explorer MSHTML.DLL HTML Parsing Denial of Service Vulnerability
9477| [16070] Microsoft Internet Explorer HTML Parsing Denial of Service Vulnerabilities
9478| [15671] Microsoft Windows CreateRemoteThread Local Denial of Service Vulnerability
9479| [15613] Microsoft Windows SynAttackProtect Predictable Hash Remote Denial of Service Vulnerability
9480| [15460] Microsoft Windows Plug and Play Denial of Service Vulnerability
9481| [15268] Microsoft Internet Explorer Malformed HTML Parsing Denial of Service Vulnerability
9482| [15208] Microsoft Internet Explorer Java Applet Denial of Service Vulnerability
9483| [15066] Microsoft Windows Client Service For Netware Buffer Overflow Vulnerability
9484| [15059] Microsoft MSDTC TIP Distributed Denial Of Service Vulnerability
9485| [15058] Microsoft MSDTC TIP Denial Of Service Vulnerability
9486| [15008] Microsoft Windows Wireless Zero Configuration Service Information Disclosure Vulnerability
9487| [14899] Microsoft Internet Explorer for Mac OS Denial of Service Vulnerability
9488| [14772] Microsoft Exchange Server 2003 Exchange Information Store Denial Of Service Vulnerability
9489| [14519] Microsoft Windows Kerberos Denial Of Service Vulnerability
9490| [14518] Microsoft Windows Telephony Service Buffer Overflow Vulnerability
9491| [14515] Microsoft Internet Explorer Unspecified SharePoint Portal Services Log Sink ActiveX Vulnerability
9492| [14286] Microsoft Internet Explorer JPEG Image Rendering Unspecified Denial Of Service Vulnerability
9493| [14285] Microsoft Internet Explorer JPEG Image Rendering Memory Consumption Denial Of Service Vulnerability
9494| [14284] Microsoft Internet Explorer JPEG Image Rendering CMP Fencepost Denial Of Service Vulnerability
9495| [14260] Microsoft Windows Network Connections Manager Library Local Denial of Service Vulnerability
9496| [14259] Microsoft Windows Kernel Unspecified Remote Desktop Protocol Denial Of Service Vulnerability
9497| [14217] Microsoft ASP.NET RPC/Encoded Remote Denial Of Service Vulnerability
9498| [14177] Microsoft Windows MSRPC SVCCTL Service Enumeration Vulnerability
9499| [13955] Microsoft ISA Server HTTP/HTTPS Service Basic Auth Information Disclosure Vulnerability
9500| [13950] Microsoft Windows Web Client Service Remote Code Execution Vulnerability
9501| [13947] Microsoft Internet Explorer Unspecified GIF And BMP Denial Of Service Vulnerability
9502| [13846] Microsoft ISA Server SecureNAT Unspecified Denial Of Service Vulnerability
9503| [13801] Microsoft Windows XP Windows Management Instrumentation Denial of Service Vulnerability
9504| [13798] Microsoft Internet Explorer Restricted Sites Malformed URI Denial of Service Vulnerability
9505| [13791] Microsoft Windows User32.DLL Icon Handling Denial Of Service Vulnerability
9506| [13658] Microsoft IPv6 TCP/IP Loopback LAND Denial of Service Vulnerability
9507| [13110] Microsoft Windows Kernel Object Management Denial Of Service Vulnerability
9508| [13008] Microsoft Windows Server 2003 SMB Redirector Local Denial Of Service Vulnerability
9509| [12972] Microsoft Windows Server 2003 Service Pack 1 Released - Multiple Vulnerabilities Fixed
9510| [12889] Microsoft Windows XP TSShutdn.exe Remote Denial of Service Vulnerability
9511| [12870] Microsoft Windows Local Denial Of Service Vulnerability
9512| [12834] Microsoft Windows Graphical Device Interface Library Denial Of Service Vulnerability
9513| [12764] Microsoft Exchange Server Mail Box Sub Folder Denial Of Service Vulnerability
9514| [12565] Microsoft Internet Explorer Malformed File URI Denial of Service Vulnerability
9515| [12481] Microsoft Windows License Logging Service Buffer Overflow Vulnerability
9516| [12476] Microsoft Windows SharePoint Services Cross-Site Scripting and Spoofing Vulnerability
9517| [12228] Microsoft Windows Indexing Service Buffer Overflow Vulnerability
9518| [12141] Microsoft FrontPage 2000 Internet Publishing Service Provider DAV File Upload Vulnerability
9519| [12121] Hilgraeve HyperTerminal Remote Denial of Service Vulnerability
9520| [12094] Microsoft Windows ANI File Denial of Service Vulnerability
9521| [11919] Microsoft Windows DHCP Server Logging Remote Denial Of Service Vulnerability
9522| [11751] Microsoft Internet Explorer Infinite Array Sort Denial Of Service Vulnerability
9523| [11536] Microsoft Internet Explorer Font Tag Denial Of Service Vulnerability
9524| [11503] Microsoft Windows XP WAV File Handler Denial Of Service Vulnerability
9525| [11412] Microsoft Frontpage Asycpict.DLL JPEG Handling Remote Denial of Service Vulnerabilities
9526| [11387] Microsoft Windows 2003 Services Default SACL Access Right Weakness
9527| [11384] Microsoft XML Parser Remote Denial of Service Vulnerability
9528| [11380] Microsoft RPC Runtime Library Remote Denial Of Service And Information Disclosure Vulnerability
9529| [11374] Microsoft SMTP Service and Exchange Routing Engine Buffer Overflow Vulnerability
9530| [11365] Microsoft Windows Kernel Local Denial of Service Vulnerability
9531| [11350] Microsoft Word Multiple Remote Denial Of Service Vulnerabilities
9532| [11265] Microsoft SQL Server Remote Denial Of Service Vulnerability
9533| [11251] Microsoft GDI+ Library Malformed JPEG Handling Unspecified Denial of Service Vulnerability
9534| [11202] Microsoft Windows XP Explorer.EXE TIFF Image Denial of Service Vulnerability
9535| [10913] Microsoft Windows Large Image Processing Remote Denial Of Service Vulnerability
9536| [10901] Microsoft Windows 2000/XP CRL File Failed Integrity Check Denial Of Service Vulnerability
9537| [10726] Microsoft Systems Management Server Remote Denial Of Service Vulnerability
9538| [10711] Microsoft Outlook Express Malformed Email Header Denial Of Service Vulnerability
9539| [10694] Microsoft Internet Explorer JavaScript Null Pointer Exception Denial Of Service Vulnerability
9540| [10552] Microsoft Internet Explorer HREF Save As Denial of Service Vulnerability
9541| [10487] Microsoft DirectX DirectPlay Remote Malformed Packet Denial Of Service Vulnerability
9542| [10482] Microsoft ISA Server Redirect URI Handler Web Proxy Service Remote Denial Of Service Vulnerability
9543| [10477] Microsoft ISA Server Web Proxy Malformed SSL Packet Remote Denial of Service Vulnerability
9544| [10351] Microsoft Internet Explorer http-equiv Meta Tag Denial of Service Vulnerability
9545| [10318] Microsoft Internet Explorer XML Parsing Denial Of Service Vulnerability
9546| [10167] Microsoft Internet Explorer Object Element Data Denial Of Service Vulnerability
9547| [10144] Microsoft Outlook/Outlook Express Remote Denial Of Service Vulnerability
9548| [10127] Microsoft Windows RPCSS Service Remote Denial Of Service Vulnerability
9549| [10123] Microsoft Windows COM Internet Service/RPC Over HTTP Remote Denial Of Service Vulnerability
9550| [10115] Microsoft Windows SSL Library Denial of Service Vulnerability
9551| [10114] Microsoft Windows 2000 Domain Controller LDAP Denial Of Service Vulnerability
9552| [10098] Microsoft Outlook Express Malformed EML File Denial of Service Vulnerability
9553| [10097] Microsoft Internet Explorer Bitmap File Processing Denial of Service Vulnerability
9554| [10073] Microsoft Internet Explorer Remote IFRAME Denial Of Service Vulnerability
9555| [10057] Microsoft Internet Explorer Macromedia Flash Player Plug-in Remote Denial of Service Vulnerability
9556| [10056] Microsoft Internet Explorer MSWebDVD Object Denial of Service Vulnerability
9557| [9963] Microsoft Visual C++ MFC ISAPI Extension Denial Of Service Vulnerability
9558| [9924] Microsoft Windows XP Explorer.EXE Remote Denial of Service Vulnerability
9559| [9892] Microsoft Windows XP explorer.exe Remote Denial of Service Vulnerability
9560| [9825] Microsoft Windows Media Services Remote Denial of Service Vulnerability
9561| [9660] Microsoft IIS Unspecified Remote Denial Of Service Vulnerability
9562| [9629] Microsoft Internet Explorer Double-Null URI Denial Of Service Vulnerability
9563| [9624] Microsoft Windows Internet Naming Service Buffer Overflow Vulnerability
9564| [9011] Microsoft Windows Workstation Service Remote Buffer Overflow Vulnerability
9565| [9008] Microsoft FrontPage Server Extensions SmartHTML Interpreter Denial Of Service Vulnerability
9566| [8874] Microsoft Internet Explorer Scrollbar-Base-Color Partial Denial Of Service Vulnerability
9567| [8826] Microsoft Windows Messenger Service Buffer Overrun Vulnerability
9568| [8783] Microsoft Windows Message Queuing Service Heap Overflow Vulnerability
9569| [8761] Microsoft Word Malformed Document Denial of Service Vulnerability
9570| [8758] Microsoft Internet Explorer Absolute Position Block Denial Of Service Vulnerability
9571| [8543] Microsoft Windows 98 Fragmented UDP Flood Denial Of Service Vulnerability
9572| [8532] Microsoft Windows NetBIOS Name Service Reply Information Leakage Weakness
9573| [8274] Microsoft SQL Server / MSDE Named Pipe Denial Of Service Vulnerability
9574| [8259] Microsoft Windows NT File Management Function Denial Of Service Vulnerability
9575| [8234] Microsoft Windows RPCSS DCOM Interface Denial of Service Vulnerability
9576| [8221] Microsoft MSN Messenger Image File Transfer Denial of Service Vulnerability
9577| [8195] Microsoft SMTP Service Invalid FILETIME Denial of Service Vulnerability
9578| [8087] Microsoft Windows Security Accounts Manager API Denial Of Service Vulnerability
9579| [8085] Microsoft Windows 2000 ModifyDN Request Denial of Service Vulnerability
9580| [8035] Microsoft Windows Media Services NSIISlog.DLL Remote Buffer Overflow Vulnerability
9581| [7789] Microsoft Windows XP Nested Directory Denial of Service Vulnerability
9582| [7788] Microsoft Windows 2000/XP/2003 IPV6 ICMP Flood Denial Of Service Vulnerability
9583| [7735] Microsoft IIS WebDAV PROPFIND and SEARCH Method Denial of Service Vulnerability
9584| [7733] Microsoft IIS ASP Header Denial Of Service Vulnerability
9585| [7728] Microsoft Internet Information Service Multiple Vulnerabilities
9586| [7727] Microsoft Windows Media Services Logging ISAPI Buffer Overflow Vulnerability
9587| [7706] Microsoft Internet Explorer Malformed JavaScript Denial of Service Vulnerability
9588| [7502] Microsoft Internet Explorer DHTML AnchorClick Partial Denial Of Service Vulnerability
9589| [7402] Microsoft Shlwapi.dll Malformed HTML Form Tag Denial of Service Vulnerability
9590| [7384] Microsoft Internet Explorer CLASSID Variant Denial Of Service Vulnerability
9591| [7358] Microsoft Windows EngTextOut Non-ASCII Character Denial Of Service Vulnerability
9592| [7314] Microsoft Winsock Proxy Service Remote Denial Of Service Vulnerability
9593| [7150] Microsoft ActiveSync Null Pointer Dereference Denial Of Service Vulnerability
9594| [7145] Microsoft ISA Server DNS Intrusion Filter Denial of Service Vulnerability
9595| [6843] Microsoft Exchange Server 5.5 IMAP NOOP Denial of Service Vulnerability
9596| [6789] Microsoft IIS Malformed HTTP Get Request Denial Of Service Vulnerability
9597| [6769] Microsoft Windows 2000 RPC Service Privilege Escalation Vulnerability
9598| [6742] Microsoft Windows NT Win32k.sys Denial of Service Vulnerability
9599| [6672] Microsoft Windows MSGINA.DLL Read-Lock Denial Of Service Vulnerability
9600| [6666] Microsoft Windows Locator Service Buffer Overflow Vulnerability
9601| [6536] Microsoft Windows Fontview Denial of Service Vulnerability
9602| [6507] Microsoft Pocket Internet Explorer Denial Of Service Vulnerability
9603| [6382] Microsoft Java Virtual Machine Java Object Instantiation Denial Of Service Vulnerability
9604| [6319] Microsoft Outlook 2002 Email Header Processing Denial of Service Vulnerability
9605| [6140] Microsoft JVM INativeServices Unauthorized Memory Access Vulnerability
9606| [6135] Microsoft JVM Passed HTML Object Reference Denial Of Service Vulnerability
9607| [6070] Microsoft IIS WebDAV Denial Of Service Vulnerability
9608| [6030] Microsoft Windows 2000 SNMP Printer Query Denial of Service Vulnerability
9609| [6005] Microsoft Windows RPC Service Denial of Service Vulnerability
9610| [5907] Microsoft IIS Malformed HTTP HOST Header Field Denial Of Service Vulnerability
9611| [5880] Microsoft Invalid RPC Request Denial Of Service Vulnerability
9612| [5869] Multiple Microsoft Services for Unix 3.0 Interix SDK Vulnerabilities
9613| [5713] Microsoft Windows XP Professional Remote Desktop Denial Of Service Vulnerability
9614| [5413] Microsoft Exchange 2000 Post Authorization License Exhaustion Denial Of Service Vulnerability
9615| [5412] Microsoft Exchange 2000 Multiple MSRPC Denial Of Service Vulnerabilities
9616| [5312] Microsoft SQL Server 2000 Resolution Service Denial of Service Vulnerability
9617| [5311] Microsoft SQL Server 2000 Resolution Service Stack Overflow Vulnerability
9618| [5310] Microsoft SQL Server 2000 Resolution Service Heap Overflow Vulnerability
9619| [5308] Microsoft Metadirectory Services Remote LDAP Client Administration Vulnerability
9620| [5213] Microsoft IIS SMTP Service Encapsulated SMTP Address Vulnerability
9621| [5094] Microsoft Internet Explorer CLASSID Denial of Service Vulnerability
9622| [5027] Microsoft Internet Explorer CSSText Bold Font Denial Of Service Vulnerability
9623| [4853] Microsoft Commerce Server 2000 Profile Service Buffer Overflow Vulnerability
9624| [4852] Microsoft Windows 2000 Remote Access Service Buffer Overflow Vulnerability
9625| [4846] Microsoft IIS 5.0 Denial Of Service Vulnerability
9626| [4827] Microsoft MSN Messenger Malformed Invite Request Denial of Service
9627| [4675] Microsoft MSN Messenger Font Tag Denial Of Service Vulnerability
9628| [4584] Microsoft Outlook Express DOS Device Denial of Service Vulnerability
9629| [4564] Microsoft Internet Explorer Self-Referential Object Denial of Service Vulnerability
9630| [4532] Microsoft Windows 2000 Lanman Denial of Service Vulnerability
9631| [4482] Microsoft IIS FTP Connection Status Request Denial of Service Vulnerability
9632| [4479] Microsoft IIS ISAPI Filter Access Violation Denial of Service Vulnerability
9633| [4464] Microsoft Windows Terminal Server Group Policy Bypass Vulnerability
9634| [4463] Microsoft VBScript ActiveX Word Object Denial Of Service Vulnerability
9635| [4205] Microsoft Windows SMTP Service Authorization Bypass Vulnerability
9636| [4204] Microsoft SMTP Service Malformed Command Denial of Service Vulnerability
9637| [4045] Microsoft Office v. X for Macintosh Network PID Checker Denial of Service Vulnerability
9638| [4006] Microsoft MSDTC Service Denial of Service Vulnerability
9639| [4002] Microsoft Site Server 3.0 Content Upload Denial of Service Vulnerability
9640| [3942] Microsoft Windows XP .Manifest Denial of Service Vulnerability
9641| [3892] Microsoft Internet Explorer Form Denial of Service Vulnerability
9642| [3730] Microsoft Internet Explorer Refresh Denial of Service Vulnerability
9643| [3729] Microsoft IE for Solaris X Server Denial of Service Vulnerability
9644| [3724] Microsoft Universal Plug and Play Simple Service Discovery Protocol Denial of Service Vulnerability
9645| [3501] Microsoft ISA Server Denial of Service Vulnerability
9646| [3499] Microsoft UPnP Denial of Service Vulnerability
9647| [3481] Microsoft Windows 2000/XP GDI Denial of Service Vulnerability
9648| [3313] Microsoft Windows NT RPC Endpoint Mapper Denial of Service Vulnerability
9649| [3291] Microsoft Windows 2000 RunAs Service Denial of Services Vulnerability
9650| [3223] Microsoft Outlook Web Access Denial of Service Vulnerability
9651| [3215] Microsoft Windows 2000 IrDA Buffer Overflow Denial of Service Vulnerability
9652| [3197] Microsoft ISA Server Proxy Service Memory Leak Denial of Service Vulnerability
9653| [3196] Microsoft ISA Server H.323 Memory Leak Denial of Service Vulnerability
9654| [3195] Microsoft IIS MIME Header Denial of Service Vulnerability
9655| [3194] Microsoft IIS WebDAV Invalid Request Denial of Service Vulnerability
9656| [3185] Microsoft Windows 2000 RunAs Service Named Pipe Hijacking Vulnerability
9657| [3183] Microsoft Windows NNTP Denial of Service Vulnerability
9658| [3104] Microsoft Remote Procedure Call Service DoS Vulnerability
9659| [3090] Microsoft Services for Unix Telnet DoS Vulnerability
9660| [3089] Microsoft Services for Unix NFS DoS Vulnerability
9661| [3045] Microsoft Exchange 5.5 LDAP Denial of Service Vulnerabilities
9662| [2844] Microsoft Windows 2000 Telnet Service DoS Vulnerability
9663| [2717] Microsoft IIS FTP Denial of Service Vulnerability
9664| [2654] Microsoft IIS Long URL Denial of Service Vulnerability
9665| [2483] Microsoft IIS WebDAV 'Search' Denial of Service Vulnerability
9666| [2453] Microsoft IIS WebDAV Denial of Service Vulnerability
9667| [2218] Microsoft IIS '../..' Denial of Service Vulnerability
9668| [2133] Microsoft Windows 2000 Directory Services Restore Mode Blank Password Vulnerability
9669| [2123] Microsoft Windows Media Services Severed Connection DoS Vulnerability
9670| [2111] Microsoft NT RAS/PPTP Malformed Control Packet Denial of Service Attack
9671| [1987] Microsoft NT 4.0 SynAttackProtect Denial of Service Vulnerability
9672| [1933] Microsoft Indexing Services for Windows 2000 File Verification Vulnerability
9673| [1861] Microsoft Indexing Services .htw Cross-Site Scripting Vulnerability
9674| [1655] Microsoft Windows Media Unicast Services DoS Vulnerability
9675| [1651] Microsoft Windows 2000 Still Image Service Privilege Escalation Vulnerability
9676| [1608] Microsoft FrontPage Server Extensions MS-DOS Device Name Denial Of Service Vulnerability
9677| [1476] Microsoft IIS 3.0 .htr Missing Variable Denial of Service Vulnerability
9678| [1435] Microsoft FrontPage 2000 Server Extensions Denial Of Service Vulnerability
9679| [1282] Microsoft Media Service DoS Vulnerability
9680| [1000] Microsoft Windows Media Services Handshake Sequence DoS Vulnerability
9681|
9682| IBM X-Force - https://exchange.xforce.ibmcloud.com:
9683| [24402] Microsoft Windows 2000 Terminal Service client IP not logged
9684| [16521] Microsoft Windows 2003 Deny Logon Through Terminal Services privilege
9685| [11816] Microsoft Windows 2000 Terminal Services MSGINA.DLL insecure access permissions
9686| [11696] Microsoft Windows 2000 Terminal Services man-in-the-middle attack
9687| [11141] Microsoft Windows 2000 Terminal Services MSGINA.DLL denial of service
9688| [9946] Microsoft Windows 2000 Terminal Services session screensaver fails to lock the console
9689| [8813] Microsoft Windows 2000 Terminal Services allows attacker to bypass group policy settings
9690| [8199] Microsoft Windows 2000 Terminal Services unlocked client
9691| [7538] Microsoft Windows 2000 and XP Terminal services allow an attacker to spoof IP addresses
9692| [7302] Microsoft Windows NT and 2000 Terminal Server malformed RDP packet series denial of service
9693| [6912] Microsoft Windows NT and 2000 Terminal Server RDP memory leak denial of service
9694| [4083] Microsoft Windows 2000 Terminal Services may damage Office files saved as HTML
9695| [86090] Microsoft Windows ICMPv6 denial of service
9696| [86072] Microsoft Windows Active Directory Federation Services information disclosure
9697| [86069] Microsoft Windows Windows NAT Driver denial of service
9698| [85802] Microsoft PowerPoint denial of service
9699| [85801] Microsoft Windows Movie Maker .wav denial of service
9700| [85233] Microsoft Windows denial of service
9701| [84620] Microsoft Windows kernel denial of service
9702| [84571] Microsoft Windows denial of service
9703| [84546] Microsoft Windows Media Player .wav denial of service
9704| [83911] Microsoft Windows denial of service
9705| [83099] Microsoft Windows denial of service
9706| [83095] Microsoft Windows denial of service
9707| [82771] Microsoft Internet Explorer sandbox denial of service
9708| [82769] Microsoft Windows TTF denial of service
9709| [82421] Microsoft SharePoint W3WP denial of service
9710| [82089] Microsoft Windows ZwSetInformationProcess() denial of service
9711| [81677] Microsoft Windows TCP/IP sequence denial of service
9712| [81675] Microsoft Windows NFS server denial of service
9713| [80866] Microsoft .NET Framework OData denial of service
9714| [80750] Microsoft Internet Explorer denial of service
9715| [80523] Microsoft Exchange Server RSS feeds denial of service
9716| [79651] Microsoft Paint .bmp denial of service
9717| [79649] Microsoft Office Publisher denial of service
9718| [79648] Microsoft Windows Help Viewer denial of service
9719| [79479] Microsoft Windows Media Player .avi denial of service
9720| [78861] Microsoft Windows Kerberos denial of service
9721| [77993] Microsoft Indexing Service ActiveX control denial of service
9722| [77359] Microsoft Internet Information Services FTP information disclosure
9723| [77358] Microsoft Internet Information Services log files information disclosure
9724| [77354] Microsoft Windows Print Spooler service format string
9725| [77353] Microsoft Windows Remote Administration Protocol denial of service
9726| [76835] Synel SY-780/A terminal denial of service
9727| [76743] Microsoft .NET Framework tilde denial of service
9728| [76716] Microsoft IIS FTP denial of service
9729| [76223] Microsoft Windows .otf denial of service
9730| [76221] Microsoft Windows XML Core Services code execution
9731| [75977] Microsoft WordPad .doc denial of service
9732| [75329] Microsoft Windows xxxCreateWindowEx() denial of service
9733| [75134] Microsoft .NET Framework index denial of service
9734| [73870] Microsoft Internet Explorer Protected Mode denial of service
9735| [73542] Microsoft Windows Remote Desktop Protocol denial of service
9736| [73539] Microsoft DirectWrite denial of service
9737| [73532] Microsoft Windows DNS Server denial of service
9738| [73029] Microsoft Internet Explorer BODY denial of service
9739| [72346] Microsoft Windows Explorer denial of service
9740| [71989] Microsoft ASP.NET CaseInsensitiveHashProvider.getHashCode() function denial of service
9741| [71966] Microsoft Windows Media Player access denial of service
9742| [71944] Microsoft Windows Phone messages denial of service
9743| [71418] Microsoft Windows keyboard layout denial of service
9744| [70946] Microsoft Windows TrueType denial of service
9745| [70337] OpenOffice.org Microsoft Word .doc sprm file parser denial of service
9746| [70148] Microsoft Host Integration Server UDP denial of service
9747| [70112] Microsoft Windows TrueType denial of service
9748| [70107] Microsoft Forefront Unified Access Gateway NULL denial of service
9749| [69638] Microsoft Windows csrss.exe denial of service
9750| [69215] Microsoft Windows DHCPv6 denial of service
9751| [69214] Microsoft Internet Explorer Iedvtool.dll denial of service
9752| [68838] Microsoft SharePoint and Windows SharePoint Services cross-site scripting
9753| [68837] Microsoft SharePoint and Windows SharePoint Services XML file disclosure
9754| [68836] Microsoft SharePoint and Windows SharePoint Services contact details cross-site scripting
9755| [68830] Microsoft Windows Remote Desktop Protocol denial of service
9756| [68815] Microsoft Windows kernel meta-data denial of service
9757| [68808] Microsoft Windows DNS Server denial of service
9758| [68803] Microsoft Windows TCP/IP QoS denial of service
9759| [68802] Microsoft Windows TCP/IP ICMP denial of service
9760| [68469] Microsoft Windows GPU denial of service
9761| [68467] Microsoft Windows NVIDIA Geforce 310 denial of service
9762| [68465] Microsoft Windows Intel G41 denial of service
9763| [68002] Microsoft Windows Media Player klite denial of service
9764| [67761] Microsoft XML Editor Web Service Discovery information disclosure
9765| [67750] Microsoft Windows Active Directory Certificate Services Web Enrollment cross-site scripting
9766| [67730] Microsoft Windows Server Hyper-V VMBus denial of service
9767| [67727] Microsoft Windows DFS denial of service
9768| [67724] Microsoft Windows SMB request denial of service
9769| [67520] Microsoft Windows Vista nsiproxy.sys denial of service
9770| [67100] Microsoft Windows Windows Internet Name Service code execution
9771| [66855] Microsoft Windows Media Player .ogg denial of service
9772| [66639] Microsoft Windows XP afd.sys denial of service
9773| [66469] Microsoft Windows Explorer Shmedia.dll denial of service
9774| [64915] Microsoft Windows Active Directory denial of service
9775| [64583] Microsoft Windows Neighbor Discovery (ND) protocol denial of service
9776| [64248] Microsoft Internet Information Services TELNET_STREAM_CONTEXT::OnSendData buffer overflow
9777| [63585] Microsoft Windows Netlogon denial of service
9778| [63572] Microsoft Exchange Server RPC denial of service
9779| [63563] Microsoft Windows Server Hyper-V VMBus denial of service
9780| [63514] Microsoft Outlook file attachment denial of service
9781| [62737] Microsoft WindowsTask Scheduler service privilege escalation
9782| [62716] Microsoft Windows Mobile .vcf denial of service
9783| [62186] Microsoft Internet Information Services directory names code execution
9784| [62148] Microsoft Windows SChannel denial of service
9785| [61994] Microsoft Windows MPEG Layer-3 Audio Decoder denial of service
9786| [61937] Microsoft Word MSO.dll denial of service
9787| [61894] Microsoft Paint BMP denial of service
9788| [61513] Microsoft Internet Information Services (IIS) URL authentication bypass
9789| [61512] Microsoft Internet Information Services request header buffer overflow
9790| [61511] Microsoft Internet Information Services repeated POST denial of service
9791| [61503] Microsoft Windows Print Spooler service code execution
9792| [61258] Microsoft Windows IcmpSendEcho2Ex denial of service
9793| [61184] Microsoft Windows win32k!GreStretchBltInternal() denial of service
9794| [60739] Microsoft Internet Explorer frame.frameBorder denial of service
9795| [60721] Microsoft WindowsTCP/IP IPv6 denial of service
9796| [60704] Microsoft Windows kernel ACL denial of service
9797| [60693] Microsoft Windows kernel-mode drivers denial of service
9798| [60691] Microsoft Windows SMB stack denial of service
9799| [60690] Microsoft Windows SMB variable denial of service
9800| [60683] Microsoft Windows XML Core Services (MSXML) code execution
9801| [60678] Microsoft Windows Service Isolation privilege escalation
9802| [60522] Microsoft Clip Organizer ActiveX control denial of service
9803| [59088] Microsoft Internet Explorer nntp:// URIs denial of service
9804| [59087] Microsoft Internet Explorer news:// URIs denial of service
9805| [59069] Microsoft Internet Explorer CSS expression denial of service
9806| [58890] Microsoft SharePoint help page denial of service
9807| [58864] Microsoft Internet Information Services (IIS) authentication code execution
9808| [58757] Microsoft Internet Explorer IFRAME element denial of service
9809| [58345] Microsoft Windows SMTP Service query id spoofing
9810| [58344] Microsoft Windows SMTP Service DNS spoofing
9811| [58243] Microsoft Office SharePoint Server and Microsoft Windows SharePoint Services help.aspx cross-site scripting
9812| [58059] Microsoft Windows SfnLOGONNOTIFY() denial of service
9813| [57601] Microsoft Windows kernel exceptions denial of service
9814| [57600] Microsoft Windows kernel image file denial of service
9815| [57599] Microsoft Windows kernel path denial of service
9816| [57597] Microsoft Windows kernel registry keys denial of service
9817| [57596] Microsoft Windows kernel symbolic links denial of service
9818| [57595] Microsoft Windows kernel registry keys denial of service
9819| [57581] Microsoft Office Communicator SIP INVITE denial of service
9820| [57401] Microsoft Internet Explorer data structures denial of service
9821| [57329] Microsoft Windows Media Services info packets buffer overflow
9822| [57324] Microsoft Windows SMTP Service Simple Mail Transfer Protocol memory information disclosure
9823| [57323] Microsoft Windows SMTP Service and Microsoft Exchange SMTP DNS Mail Exchanger (MX) denial of service
9824| [56756] Microsoft Windows .ani file denial of service
9825| [56651] Microsoft Internet Information Services DNS cross-site scripting
9826| [56591] Microsoft Windows API denial of service
9827| [56435] Microsoft Windows Media Player .mpg denial of service
9828| [55925] Microsoft Windows Hyper-V instruction set denial of service
9829| [55922] Microsoft Windows Kerberos Ticket-Granting-Ticket (TGT) denial of service
9830| [55908] Microsoft Windows SMB NULL denial of service
9831| [55907] Microsoft Windows SMB denial of service
9832| [55900] Microsoft Internet Explorer createElement denial of service
9833| [55897] Microsoft Windows TCP/IP SACK denial of service
9834| [55863] Microsoft Internet Explorer multiple unspecified denial of service
9835| [55308] Microsoft Internet Information Services colon security bypass
9836| [55031] Microsoft Internet Information Services (IIS) filenames security bypass
9837| [54442] Microsoft Windows Local Security Authority Subsystem Service (LSASS) denial of service
9838| [54439] Microsoft Windows Internet Authentication Service (IAS) privilege escalation
9839| [54438] Microsoft Windows Internet Authentication Service (IAS) code execution
9840| [54426] Microsoft Windows Active Directory Federation Services (ADFS) code execution
9841| [54425] Microsoft Windows Active Directory Federation Services (ADFS) spoofing
9842| [54317] Microsoft Internet Explorer setHomePage denial of service
9843| [54217] Microsoft Windows KeAccumulateTicks() denial of service
9844| [53990] Microsoft Windows ADAM LDAP denial of service
9845| [53547] Microsoft Windows kernel exception handler denial of service
9846| [53540] Microsoft Windows Indexing Service ActiveX control code execution
9847| [53519] Microsoft Server Message Block (SMB) Protocol software denial of service
9848| [53511] Microsoft Windows Local Security Authority Subsystem Service (LSASS) denial of service
9849| [53417] Microsoft Internet KEYGEN denial of service
9850| [53414] Microsoft Internet window.print denial of service
9851| [53034] Microsoft Internet Information Services (IIS) directory listings denial of service
9852| [52925] Sophos PureMessage for Microsoft Exchange EdgeTransport.exe denial of service
9853| [52915] Microsoft Internet Information Services (IIS) FTP buffer overflow
9854| [52897] Microsoft Internet Explorer JavaScript code denial of service
9855| [52870] Microsoft Internet Explorer integer value denial of service
9856| [52765] Microsoft Internet Explorer XML denial of service
9857| [52762] Microsoft Internet Explorer Unicode string denial of service
9858| [52722] Microsoft Internet Explorer DIV element denial of service
9859| [52590] Microsoft Internet Explorer JavaScript SetAttribute denial of service
9860| [52403] Microsoft Windows OpenType font engine denial of service
9861| [52249] Microsoft Internet Explorer mshtml.dll denial of service
9862| [52127] Microsoft Windows TCP/IP orphaned connections denial of service
9863| [52116] Microsoft Windows RDP Services Client ActiveX control buffer overflow
9864| [52113] ASP.NET Framework component of Microsoft Windows HTTP denial of service
9865| [52110] Microsoft Windows Windows Internet Name Service (WINS) replication partner buffer overflow
9866| [52109] Microsoft Windows Windows Internet Name Service (WINS) replication buffer overflow
9867| [52106] Microsoft Message Queuing Service (MSMQ) IOCTL privilege escalation
9868| [52092] Microsoft Windows Workstation Service RPC message code execution
9869| [51468] Microsoft Windows Wireless LAN AutoConfig service buffer overflow
9870| [50973] Microsoft Windows Server 2003 and Vista win32k.sys denial of service
9871| [50903] Microsoft Windows SPI_SETDESKWALLPAPER SystemParametersInfo denial of service
9872| [50765] Microsoft Windows Print Spooler service privilege escalation
9873| [50764] Microsoft Print Spooler service information disclosure
9874| [50763] Microsoft Windows Print Spooler service buffer overflow
9875| [50761] Microsoft Windows Active Directory LDAP denial of service
9876| [50573] Microsoft Internet Information Services (IIS) WebDAV security bypass
9877| [50391] Microsoft Windows Media Player MID file denial of service
9878| [50350] Microsoft Internet Explorer unprintable characters denial of service
9879| [50129] Microsoft Windows gdiplus.dll PNG denial of service
9880| [49566] Microsoft Windows HTTP services certificate spoofing
9881| [49564] Microsoft ISAServer and Microsoft Forefront TMG Web proxy TCP state denial of service
9882| [49562] Microsoft Windows HTTP services integer underflow
9883| [49438] Microsoft Windows GDI+ EMF EmfPlusFont Object denial of service
9884| [49109] OpenBSD and Microsoft Interix fts_build function denial of service
9885| [49079] Microsoft Windows DNS server memory leak denial of service
9886| [48815] Microsoft XML Core Services HTTPOnly Set-Cookie2 HTTP response headers information disclosure
9887| [48335] Microsoft Internet Explorer HTML form value denial of service
9888| [48179] Sun Solaris pseudo-terminal driver denial of service
9889| [47867] Microsoft Windows .CHM file denial of service
9890| [47788] Microsoft Internet Explorer JavaScript onload=screen attribute denial of service
9891| [47756] Microsoft Money prtstb06.dll ActiveX control denial of service
9892| [47671] Microsoft Exchange Server EMSMDB2 invalid MAPI commands denial of service
9893| [47664] Microsoft Windows Media Player WAV or SND file denial of service
9894| [46673] Microsoft Communicator SIP INVITE message unspecified denial of service
9895| [46671] Microsoft Communicator emoticon unspecified denial of service
9896| [46670] Microsoft Communicator, Office Communications Server (OCS) and Windows Live Messenger RTCP unspecified denial of service
9897| [46506] Microsoft Windows UnhookWindowsHookEx() denial of service
9898| [46385] Microsoft Windows Media Player MIDI or DAT file denial of service
9899| [46309] Microsoft Debug Diagnostic Tool DebugDiag ActiveX control denial of service
9900| [46100] Microsoft Windows XP Service Pack 3 is not installed on the system
9901| [46099] Microsoft Windows XP Service Pack 1 is not installed on the system
9902| [46040] Microsoft Windows Server Service RPC code execution
9903| [45746] Cisco Unity Microsoft API unspecified denial of service
9904| [45719] Microsoft Windows Vista page faults denial of service
9905| [45639] Microsoft Internet Explorer alert function denial of service
9906| [45584] Microsoft IIS adsiis.dll ActiveX control denial of service
9907| [45556] Microsoft IAS Helper COM ActiveX control denial of service
9908| [45555] Microsoft XML Core Services chunked transfer-encoding headers information disclosure
9909| [45554] Microsoft XML Core Services DTD information disclosure
9910| [45464] Microsoft Windows XP GDI+ .ICO denial of service
9911| [45463] Microsoft Windows Mobile bluetooth device name denial of service
9912| [45420] Microsoft WordPad .doc denial of service
9913| [45225] Microsoft Internet Explorer PNG file denial of service
9914| [45146] Microsoft Windows WRITE_ANDX SMB packet denial of service
9915| [44775] PureMessage for Microsoft Exchange PMScanner.exe denial of service
9916| [43980] MINIX pseudo terminal denial of service
9917| [43869] F-PROT Antivirus Microsoft Office file denial of service
9918| [42696] Microsoft Windows PGM fragment option denial of service
9919| [42695] Microsoft Windows PGM option length denial of service
9920| [42668] Microsoft Windows Active Directory LDAP request denial of service
9921| [42232] Microsoft Internet Explorer ActiveX string concatenation denial of service
9922| [42108] Microsoft Malware Protection Engine data structure denial of service
9923| [42107] Microsoft Malware Protection Engine file denial of service
9924| [41934] Microsoft SharePoint Services Picture Source cross-site scripting
9925| [41338] Microsoft Internet Explorer CreateTextRange method denial of service
9926| [40579] Microsoft Active Directory unspecified denial of service
9927| [40577] Microsoft Internet Explorer files denial of service
9928| [40286] Microsoft Internet Explorer src attribute denial of service
9929| [40283] Microsoft Internet Explorer style attribute denial of service
9930| [40102] Microsoft Windows Active Directory LDAP request denial of service
9931| [40098] Microsoft Windows Vista DHCP denial of service
9932| [40087] Microsoft Internet Explorer multiple ActiveX control denial of service
9933| [39254] Microsoft Windows TCP/IP ICMP denial of service
9934| [39209] Microsoft Word wordart denial of service
9935| [39208] Microsoft Office Publisher multiple denial of service
9936| [38797] Microsoft Windows Media Player AIFF denial of service
9937| [38440] Microsoft Forms ActiveX control denial of service
9938| [38430] Microsoft Office Web Component OWC11.DataSourceControl ActiveX denial of service
9939| [37200] Microsoft SQL Server 2000 Service Pack 1 update is not installed
9940| [37198] Microsoft SQL Server 2000 Service Pack 3 update is not installed
9941| [36980] Microsoft Windows Explorer PNG file denial of service
9942| [36803] Microsoft Windows RPC NTLMSSP authentication denial of service
9943| [36378] Microsoft Windows UNIX services setuid binary privilege escalation
9944| [36128] Microsoft Internet Explorer position:relative HTML style code denial of service
9945| [36027] Microsoft Internet Explorer ActiveX popup blocker denial of service
9946| [35902] Microsoft Windows process scheduler denial of service
9947| [35886] Microsoft Windows ARP request denial of service
9948| [35878] Microsoft Windows Media Player .AU file denial of service
9949| [35855] Microsoft Register Server DLL file denial of service
9950| [35802] Microsoft Windows Vista Calendar ICS denial of service
9951| [35764] Microsoft Message Queuing Service buffer overflow
9952| [35538] Microsoft Windows Explorer GIF denial of service
9953| [35455] Microsoft Internet Explorer Zone domain name denial of service
9954| [35397] Microsoft Windows Vista USER32.DLL denial of service
9955| [35197] Microsoft Internet Information Services URL parser buffer overflow
9956| [35195] Microsoft XML Core Services (MSXML) memory request code execution
9957| [35180] Microsoft Windows Active Directory LDAP denial of service
9958| [34755] Microsoft Internet Explorer Outlook Express Address Book object denial of service
9959| [34754] Microsoft Internet Explorer MSHtmlPopupWindow object denial of service
9960| [34743] Microsoft Windows GDI+ denial of service
9961| [34650] Microsoft Internet Explorer Javascript src attribute denial of service
9962| [34639] Microsoft .NET Framework JIT Compiler service buffer overflow
9963| [34637] Microsoft .NET Framework PE Loader service buffer overflow
9964| [34599] Microsoft Windows Server 2003 terminal server security bypass
9965| [34418] Microsoft Internet Information Server (IIS) AUX/.aspx denial of service
9966| [33890] Microsoft Exchange IMAP command denial of service
9967| [33888] Microsoft Exchange iCal MODPROPS denial of service
9968| [33715] Microsoft Internet Explorer unspecified JavaScript denial of service
9969| [33713] Microsoft Word 2007 multiple unspecified denial of service
9970| [33399] Microsoft Windows Vista LLTD Mapper denial of service
9971| [33393] Microsoft Windows Vista ARP denial of service
9972| [33300] Microsoft Windows Vista atikmdag.sys slideshow denial of service
9973| [33258] Microsoft Windows GDI WMF image denial of service
9974| [33118] Microsoft Windows XP winmm.dll denial of service
9975| [33086] Microsoft Windows Ndistapi.sys driver denial of service
9976| [33041] Microsoft Excel XML and XLS file denial of service
9977| [33039] Microsoft Office WMF file denial of service
9978| [33037] Microsoft Windows Explorer WMF file denial of service
9979| [32939] Microsoft Internet Explorer resizeTo denial of service
9980| [32921] Microsoft Windows ole32.dll library denial of service
9981| [32831] Microsoft Internet Explorer BrowseDialog ActiveX control denial of service
9982| [32647] Microsoft Internet Explorer onUnload handler denial of service
9983| [32631] Microsoft SQL Server 2000 Service Pack 2 update is not installed
9984| [32457] Microsoft Internet Explorer getElementById denial of service
9985| [32454] Microsoft Visual Studio time functions denial of service
9986| [32394] Microsoft Windows Mobile Internet Explorer WML page denial of service
9987| [32280] Microsoft Windows Image Acquisition service buffer overflow
9988| [32071] Microsoft Windows Explorer AVI file denial of service
9989| [32002] Microsoft Windows Mobile Pictures and Videos JPEG denial of service
9990| [32001] Microsoft Windows Mobile Internet Explorer unspecified denial of service
9991| [31867] Microsoft Internet Explorer ActiveX multiple properties denial of service
9992| [31814] Microsoft Internet Explorer IFRAME file URI denial of service
9993| [31675] Microsoft Internet Explorer BrowseDialog ActiveX control denial of service
9994| [31642] Microsoft IIS Web server service.cnf file detected
9995| [31630] Microsoft Internet Information Services IISAdmin directory detected
9996| [31549] Microsoft Internet Explorer CCRP Folder Treeview ActiveX control denial of service
9997| [31358] Microsoft XML Core Services IFRAME code execution
9998| [31187] Microsoft Outlook email long header denial of service
9999| [31085] Microsoft Windows Workstation service NetrWkstaUserEnum denial of service
10000| [31015] Microsoft Windows Explorer WMV file denial of service
10001| [31014] Microsoft Windows Media Player MIDI file denial of service
10002| [31011] Microsoft Internet Information Services IUSR_Machine command execution
10003| [30959] Microsoft Outlook ole32.dll ActiveX denial of service
10004| [30756] Microsoft Windows Remote Installation Service code execution
10005| [30717] Microsoft Windows Print Spooler denial of service
10006| [30605] Microsoft Windows SNMP service buffer overflow
10007| [30553] Microsoft Windows Live Messenger emoticon denial of service
10008| [29953] Microsoft Windows Client Service for NetWare (CSNW) denial of service
10009| [29952] Microsoft Windows Client Service for NetWare (CSNW) buffer overflow
10010| [29948] Microsoft Windows Workstation service NetpManageIPCConnect buffer overflow
10011| [29917] Microsoft Windows XP NAT Helper ipnathlp.dll denial of service
10012| [29507] Microsoft Office 2003 unspecified PowerPoint NULL pointer dereference denial of service
10013| [29400] Microsoft Windows drmstor.dll denial of service
10014| [29373] Microsoft Windows SMB rename denial of service
10015| [29210] Microsoft XML Core Services XLST buffer overflow
10016| [29206] Microsoft XML Core Services XMLHTTP information disclosure
10017| [29135] Microsoft Internet Explorer CSS HTML INPUT DIV element denial of service
10018| [28651] Microsoft Indexing Service cross-site scripting
10019| [28608] Microsoft Internet Explorer daxctle.ocx denial of service
10020| [28516] Microsoft Internet Explorer multiple COM object color property denial of service
10021| [28512] Microsoft Internet Explorer multiple Windows 2000 COM object denial of service
10022| [28511] Microsoft Internet Explorer multiple Visual Studio COM object denial of service
10023| [28474] Microsoft Windows PNG IHDR block denial of service
10024| [28444] Microsoft Internet Explorer tsuserex.dll COM object denial of service
10025| [28439] Microsoft Internet Explorer msoe.dll COM object denial of service
10026| [28438] Microsoft Internet Explorer chtskdic.dll COM object denial of service
10027| [28436] Microsoft Internet Explorer imskdic.dll COM object denial of service
10028| [28281] Microsoft Windows WMF gdi32.dll denial of service
10029| [28183] Microsoft Windows gdiplus.dll denial of service
10030| [28068] Microsoft Internet Explorer deleted frame access denial of service
10031| [28066] Microsoft Internet Explorer ADODB.Recordset ActiveX object denial of service
10032| [28046] Microsoft Internet Explorer NDFXArtEffects ActiveX object denial of service
10033| [28002] Microsoft Windows Server service buffer overflow
10034| [27999] Microsoft Windows SMB malformed PIPE denial of service
10035| [27932] Microsoft Internet Explorer native function iteration denial of service
10036| [27931] Microsoft Internet Explorer Forms.ListBox.1 and Forms.ComboBox.1 ActiveX object denial of service
10037| [27930] Microsoft Internet Explorer ASFSourceMediaDescription ActiveX object denial of service
10038| [27929] Microsoft Internet Explorer Internet.HHCtrl ActiveX object denial of service
10039| [27900] Microsoft Internet Explorer wininet.dll denial of service
10040| [27890] Microsoft Internet Explorer href title denial of service
10041| [27884] Microsoft Internet Explorer CEnroll ActiveX object denial of service
10042| [27845] Microsoft Internet Explorer OVCtl ActiveX object denial of service
10043| [27803] Microsoft Internet Explorer DataSourceControl ActiveX object denial of service
10044| [27795] Microsoft Works wksss.exe denial of service
10045| [27762] Microsoft Internet Explorer DXImageTransform.Microsoft.Gradient ActiveX object denial of service
10046| [27761] Microsoft Internet Explorer MHTMLFile ActiveX object denial of service
10047| [27760] Microsoft Internet Explorer FolderItem control denial of service
10048| [27713] Microsoft Internet Explorer RevealTrans ActiveX object denial of service
10049| [27675] Microsoft Internet Explorer TriEditDocument ActiveX object denial of service
10050| [27649] Microsoft Internet Explorer HtmlDlgSafeHelper ActiveX object denial of service
10051| [27623] Microsoft Internet Explorer Object.Microsoft.DXTFilter ActiveX object denial of service
10052| [27622] Microsoft Internet Explorer DirectAnimation.DAUserData ActiveX object denial of service
10053| [27621] Microsoft Internet Explorer RDS.DataControl ActiveX object denial of service
10054| [27617] Microsoft Office mso.dll LsCreateLine() denial of service
10055| [27599] Microsoft Internet Explorer OutlookExpress.AddressBook ActiveX object denial of service
10056| [27596] Microsoft Internet Explorer ADODB.Recordset ActiveX object denial of service
10057| [27592] Microsoft Internet Explorer table.frameset appendChild() denial of service
10058| [27567] Microsoft Windows explorer.exe Internet Shortcut (.url) denial of service
10059| [27565] Microsoft Internet Explorer StructuredGraphicsControl SourceURL denial of service
10060| [27417] Microsoft Windows Live Messenger contact list denial of service
10061| [26971] Microsoft NetMeeting unspecified memory corruption denial of service
10062| [26830] Microsoft Windows SMB invalid handle denial of service
10063| [26820] Microsoft Windows SMB Server service information disclosure
10064| [26817] Microsoft Internet Explorer CSS position denial of service
10065| [26808] Microsoft Internet Explorer HTML tag parsing denial of service
10066| [26796] Microsoft Internet Information Services (IIS) ASP buffer overflow
10067| [25852] Microsoft Internet Explorer CSS scrollbar denial of service
10068| [25844] Microsoft Dynamics GP magic number denial of service
10069| [25392] Microsoft ASP.NET COM and COM+ w3wp.exe denial of service
10070| [25369] Microsoft Windows DNS recursive query denial of service
10071| [25284] Microsoft Internet Explorer HTML CSS null dereference denial of service
10072| [25256] Microsoft Internet Explorer Java VM denial of service
10073| [25011] Microsoft Internet Explorer display adapter JPEG image denial of service
10074| [24846] Microsoft Internet Explorer window.status memory leak denial of service
10075| [24788] Microsoft Internet Explorer Script Engine stack denial of service
10076| [24629] BlackBerry Enterprise Server Attachment Service Microsoft Word file buffer overflow
10077| [24491] Microsoft Windows MSRPC WebClient service message buffer overflow
10078| [24489] Microsoft Windows IGMP v3 denial of service
10079| [24488] Microsoft Windows Media Player BMP image parsing service buffer overflow
10080| [24346] Microsoft Office \BaseNamedObjects\Mso97SharedDg denial of service
10081| [24162] Microsoft Internet Explorer invalid IMG and XML element denial of service
10082| [24044] Microsoft Windows GRE ExtCreateRegion() and ExtEscape() WMF denial of service
10083| [23895] Microsoft Internet Explorer HTML denial of service
10084| [23706] Microsoft MSN Messenger and Internet Explorer image denial of service
10085| [23284] Microsoft Windows SynAttackProtect denial of service
10086| [23066] Microsoft Windows XP and 2000 Server MSRPC memory allocation denial of service
10087| [22852] Microsoft Internet Explorer mshtmled.dll denial of service
10088| [22524] Microsoft Windows XP Wireless Zero Configuration service information disclosure
10089| [22476] Microsoft Windows Distributed Transaction Coordinator message denial of service
10090| [22475] Microsoft Windows Distributed Transaction Coordinator TIP denial of service
10091| [22318] Microsoft SQL Server 2000 Service Pack 4 update is not installed
10092| [22183] Microsoft Exchange Server 2003 public folder denial of service
10093| [21978] Microsoft Windows user32.dll component denial of service
10094| [21930] Microsoft Internet Explorer URL restricted zone denial of service
10095| [21700] Microsoft Windows Client Service for NetWare code execution
10096| [21658] Microsoft ActiveSync multiple request denial of service
10097| [21625] Microsoft Windows kerberos message denial of service
10098| [21599] Microsoft Windows telephony service buffer overflow
10099| [21553] Microsoft Internet Explorer AJAX denial of service
10100| [21537] Microsoft FrontPage style tag denial of service
10101| [21455] MSN (Microsoft Network) Messenger .pif denial of service
10102| [21407] Microsoft Windows RDP request denial of service
10103| [21355] Microsoft Windows Network Connection Manager denial of service
10104| [21352] Microsoft ASP.NET RCP/encoded denial of service
10105| [21345] Microsoft Windows 2000 Update Rollup 1 for Service Pack 4 has not been installed
10106| [21071] Microsoft Internet Explorer BMP memory denial of service
10107| [21025] Microsoft ISA Server SecureNAT client configuration denial of service
10108| [20818] Microsoft Windows WebClient Service buffer overflow
10109| [20629] Multiple Microsoft Windows IPv6 LAND denial of service
10110| [20408] Microsoft ASP.NET Framework _VIEWSTATE denial of service
10111| [19969] Multiple Microsoft Windows Server 2003 Edition printer driver denial of service
10112| [19965] Multiple Microsoft Windows Server 2003 Editions SMB redirector denial of service
10113| [19727] Microsoft Windows 2000 GDI32.DLL denial of service
10114| [19629] Microsoft Exchange Server 2003 folder denial of service
10115| [19593] Microsoft Windows LAND denial of service
10116| [19220] Microsoft Windows registry key connection denial of service
10117| [19103] Multiple Microsoft Windows TCP/IP denial of service
10118| [19101] Microsoft Windows Servers License Logging service code execution
10119| [19091] Microsoft Windows SharePoint Services and SharePoint Team Services cross-site scripting
10120| [18758] Microsoft Windows Indexing Service allows code execution
10121| [18667] Microsoft Windows ANI file zero rate number overflow denial of service
10122| [18341] Microsoft Windows NT DHCP MachineName denial of service
10123| [18336] Microsoft Windows HyperTerminal session file buffer overflow
10124| [17931] Microsoft Internet Explorer mshtml.dll denial of service
10125| [17911] Microsoft Internet Explorer FONT tags denial of service
10126| [17864] Microsoft Windows XP Explorer WAV file denial of service
10127| [17739] Microsoft FrontPage and Internet Explorer asycpict.dll JPEG denial of service
10128| [17645] Microsoft Internet Information Server WebDAV multiple attributes per XML elements cause denial of service
10129| [17621] Microsoft Windows 2003 SMTP service code execution
10130| [17560] Microsoft Windows 2000 and XP GDI library denial of service
10131| [17542] Microsoft SQL Server data buffer denial of service
10132| [17521] Microsoft Windows 2000 Service Pack 4 is not installed
10133| [17457] Microsoft Windows XP Explorer.exe TIFF denial of service
10134| [17004] Microsoft Windows XP Service Pack 2 is not installed on the system
10135| [16913] Microsoft Windows 2003 users with Synchronize directory service data privilege
10136| [16912] Microsoft Windows 2003 groups with Synchronize directory service data privilege
10137| [16851] Microsoft Windows 2003 and XP WinKey and U key denial of service
10138| [16709] Microsoft Internet Explorer JavaScript denial of service
10139| [16696] Microsoft Systems Management Server (SMS) Remote Control Client service denial of service
10140| [16678] Microsoft Internet Explorer text file denial of service
10141| [16585] Microsoft Outlook Express malformed email header denial of service
10142| [16582] Microsoft Windows Server 2003 kernel CPU denial of service
10143| [16448] Microsoft MN-500 Web administration denial of service
10144| [16420] Microsoft Internet Explorer null pointer denial of service
10145| [16384] Microsoft ISA Server Web Proxy redirect denial of service
10146| [16380] Microsoft ISA Server Web Proxy SSL denial of service
10147| [16306] Microsoft DirectX DirectPlay denial of service
10148| [16211] Microsoft Windows Service Host buffer overflow exploit attempt detected
10149| [16210] Microsoft Windows Service Host buffer overflow exploit attempt detected
10150| [16208] Microsoft Windows RPC Locator Service buffer overflow exploit attempt detected
10151| [16201] Microsoft Internet Information Services buffer overflow exploit attempt detected
10152| [16189] Microsoft Internet Explorer CSS denial of service
10153| [16160] Microsoft Internet Explorer MSHTM.DLL http-equiv META tag denial of service
10154| [16154] Microsoft Windows NT 4.0 TSE Security Patch denial of service
10155| [15859] Microsoft Outlook email ASCII NUL denial of service
10156| [15832] Microsoft Internet Explorer IFRAME denial of service
10157| [15709] Microsoft Windows COM Internet Service and RPC over HTTP denial of service
10158| [15708] Microsoft Windows RPCSS Service RPC message can cause denial of service
10159| [15700] Microsoft Windows 2000 Domain Controller LSASS LDAP message denial of service
10160| [15591] Microsoft Visual Studio and Microsoft Visual C++ denial of service
10161| [15544] Microsoft Internet Explorer shell: command denial of service
10162| [15507] Microsoft Windows XP Explorer wmf denial of service
10163| [15394] Microsoft Windows service running under non-built-in accounts has been detected
10164| [15326] Microsoft Internet Explorer Perfect Nav plugin denial of service
10165| [15127] Microsoft Internet Explorer and Outlook null character in host name denial of service
10166| [15057] Microsoft Windows XP and Windows Server 2003 smbmount Linux client denial of service
10167| [15038] Microsoft Windows 2000 Server Windows Media Services denial of service
10168| [15037] Microsoft Windows Server 2003 WINS /GS flag denial of service
10169| [14422] MSMediaservice attaches to processes of Microsoft Internet Explorer and could allow an attacker to execute code
10170| [13809] Microsoft Internet Explorer scrollbar-base-color attribute denial of service
10171| [13680] Microsoft FrontPage Server Extensions SmartHTML Interpreter denial of service
10172| [13501] Microsoft Internet Explorer position: absolute denial of service
10173| [13453] Microsoft Internet Information Server 404 error message determines service pack level
10174| [13444] Microsoft Windows Non-English patched with MS03-045 denial of service in Sophos Anti-Virus
10175| [13433] Microsoft Exchange SMTP extended verb request denial of service
10176| [13413] Microsoft Windows Messenger Service popup buffer overflow
10177| [13344] Microsoft Windows 98 flood of fragmented UDP packets causes denial of service
10178| [13183] Microsoft Windows service pack detected
10179| [13089] Microsoft Windows NetBIOS Name Service information disclosure
10180| [13088] Microsoft IIS running RealSecure Server Sensor ISAPI plug-in denial of service
10181| [13029] Microsoft Internet Explorer input type tag denial of service
10182| [12872] Microsoft NetMeeting malformed packet denial of service
10183| [12762] Microsoft Windows NT 4.0 Q823803i patch RRAS denial of service
10184| [12701] Microsoft Windows NT 4.0 Server file management function denial of service
10185| [12700] Microsoft SQL Server named pipe denial of service
10186| [12684] Microsoft Exchange Server OWA Outlook 2003 denial of service
10187| [12679] Microsoft Windows RPC DCOM denial of service
10188| [12620] Microsoft Windows 2000 Server SMTP FILETIME denial of service
10189| [12538] Microsoft Internet Explorer C:\aux URL denial of service
10190| [12187] Microsoft Windows XP gethostbyaddr() denial of service
10191| [12100] Microsoft IIS long WebDAV requests containing XML denial of service
10192| [12099] Microsoft IIS Response.AddHeader denial of service
10193| [12043] Microsoft Internet Explorer Script Engine denial of service
10194| [11946] Microsoft Internet Explorer anchorClick behavior denial of service
10195| [11873] Microsoft Internet Explorer, Outlook, and FrontPage shlwapi.dll library denial of service
10196| [11824] Microsoft Windows XP Service Control Manager (SCM) race condition
10197| [11810] Microsoft Windows win2k.sys EngTextOut denial of service
10198| [11805] Microsoft Internet Explorer OBJECT tag denial of service
10199| [11752] Microsoft ISA and Proxy Server Firewall and Winsock Proxy service denial of service
10200| [11576] Microsoft ISA DNS intrusion detection application filter denial of service
10201| [11537] Microsoft IIS WebDAV service is running on the system
10202| [11430] Microsoft Locator service is running on the system
10203| [11415] Multiple vendor terminal emulator DEC UDK denial of service
10204| [11274] Microsoft Windows 2000 NetBIOS continuation packets denial of service
10205| [11273] Microsoft Windows 2000 RPC service could allow an attacker to gain elevated privileges
10206| [11216] Microsoft Windows NT and 2000 command prompt denial of service
10207| [11132] Microsoft Windows Locator service buffer overflow
10208| [11030] Microsoft Windows OpenType font (.otf) fontview denial of service
10209| [10763] Microsoft Outlook malformed email header denial of service
10210| [10588] Microsoft VM HTML Applet tag denial of service
10211| [10587] Microsoft VM passed HTML object denial of service
10212| [10583] Microsoft VM INativeServices could be used to access clipboard contents
10213| [10582] Microsoft VM INativeServices could allow unauthorized memory access
10214| [10503] Microsoft IIS WebDAV memory allocation denial of service
10215| [10431] Microsoft Windows 2000 SNMP LANMAN Extension memory leak denial of service
10216| [10400] Microsoft Windows 2000 RPC TCP port 135 denial of service
10217| [10370] Microsoft IIS HTTP HOST header denial of service
10218| [10259] Microsoft Services for Unix (SFU) invalid RPC packet denial of service
10219| [10258] Microsoft Services for Unix (SFU) RPC parameter size buffer overflow could crash the server
10220| [10194] Microsoft FrontPage Server Extensions (FPSE) 2000 SmartHTML Interpreter denial of service
10221| [10184] Microsoft IIS 5.0 resource utilization denial of service
10222| [10120] Microsoft Windows XP Remote Desktop malformed PDU Confirm Active packet denial of service
10223| [10117] Microsoft Internet Explorer FTP URL denial of service
10224| [10031] Microsoft SQL Server Resolution Service stack buffer overflow
10225| [9883] Microsoft Internet Explorer Google Toolbar search request denial of service
10226| [9791] Microsoft Exchange IIS license exhaustion denial of service
10227| [9789] Microsoft Exchange MSRPC denial of service
10228| [9752] Microsoft Windows 2000 Service Pack 3 is not installed
10229| [9662] Microsoft SQL Server Resolution Service keep-alive function denial of service
10230| [9661] Microsoft SQL Server Resolution Service heap buffer overflow
10231| [9657] Microsoft Metadirectory Services (MMS) could allow unauthorized access to the data repository
10232| [9617] Microsoft Internet Explorer JavaScript page transitions denial of service
10233| [9580] Microsoft IIS SMTP service encapsulated addresses could allow mail relaying
10234| [9531] Microsoft Internet Explorer CLASSID denial of service
10235| [9523] Microsoft SQL Server service account insecure registry permissions
10236| [9423] Microsoft Commerce Server Profile Service API buffer overflow
10237| [9421] Microsoft Windows Media Player WMDM service invalid resource connection could allow elevated privileges
10238| [9367] Microsoft Internet Explorer Cascading Style-Sheet (CSS) bold font denial of service
10239| [9195] Microsoft Exchange message attribute denial of service
10240| [9159] Microsoft Active Directory zero page length denial of service
10241| [9122] Microsoft Internet Explorer JavaScript self.location refresh denial of service
10242| [9087] Microsoft Internet Explorer and Outlook Express BGSOUND DOS device reference could cause a denial of service
10243| [8969] Microsoft Internet Explorer and Outlook Express malformed XBM file denial of service
10244| [8941] Microsoft Internet Explorer JavaScript recursive onError event denial of service
10245| [8904] Microsoft Internet Explorer self-referenced OBJECT directive denial of service
10246| [8867] Microsoft Windows 2000 LanMan denial of service
10247| [8815] Microsoft VBScript ActiveX Word object denial of service
10248| [8801] Microsoft IIS FTP session status request denial of service
10249| [8800] Microsoft IIS FrontPage Server Extensions and ASP.NET ISAPI filter error handling denial of service
10250| [8488] Microsoft Internet Explorer JavaScript location.replace loop denial of service
10251| [8356] Microsoft Outlook X-UIDL: header denial of service
10252| [8341] Microsoft Internet Explorer 4.0 long OBJECT CLASSID denial of service
10253| [8307] Microsoft Windows 2000, Windows XP, and Exchange 2000 SMTP data transfer command denial of service
10254| [8304] Microsoft Windows 2000 and Exchange 5.5 SMTP service unauthorized mail privileges
10255| [8209] Microsoft Windows XP CIFS port denial of service
10256| [8207] Microsoft Windows XP UDP port denial of service
10257| [8087] Microsoft Office v. X for Mac OS X PID Checker denial of service
10258| [8037] Microsoft Windows 2000 empty TCP packet denial of service
10259| [7947] BadBlue Microsoft Office file viewing script non-existent file request denial of service
10260| [7938] Microsoft Internet Explorer HTML form denial of service
10261| [7826] Microsoft Internet Explorer showModelessDialog() denial of service
10262| [7722] Microsoft Windows XP, Me, 98, and 98SE UPnP spoofed UDP packet with SSDP announcement denial of service attack
10263| [7709] Microsoft Windows multiple vendor Web browser high image count denial of service
10264| [7667] Microsoft Windows 2000 IKE UDP packet flood denial of service
10265| [7542] Microsoft Windows 95 and 98 with multiple TCP/IP stacks ICMP packet denial of service
10266| [7533] Microsoft Windows 2000 RunAs service denial of service
10267| [7532] Microsoft Windows 2000 RunAs service allows local attacker to bypass pipe authentication
10268| [7531] Microsoft Windows 2000 RunAs service reveals sensitive information
10269| [7528] Microsoft Windows NT and Windows 2000 malformed RPC request denial of service
10270| [7527] Microsoft SQL Server malformed RPC request denial of service
10271| [7526] Microsoft Exchange Server malformed RPC request denial of service
10272| [7446] Microsoft ISA Server fragmented UDP packet flood denial of service
10273| [7428] Microsoft Windows Me and XP UPnP denial of service
10274| [7421] Microsoft Windows NT GetThreadContext/SetThreadContext denial of service
10275| [7409] Microsoft Windows 2000 and Windows XP GDI denial of service
10276| [7405] Microsoft Windows NT NonPagedPool denial of service
10277| [7403] Microsoft Windows NT Win32k.sys denial of service
10278| [7402] Microsoft Windows NT kernel mode handle-closing denial of service
10279| [7369] Microsoft Windows CSRSS.EXE denial of service
10280| [7329] Microsoft Windows NT WINS malformed packet flood denial of service
10281| [7318] Microsoft Windows ME SSDP service denial of service
10282| [7224] Microsoft Windows NT smbmount request from Linux client denial of service
10283| [7168] Microsoft Exchange OWA deeply-nested folder request denial of service
10284| [7107] Microsoft Windows NT Xenroll denial of service
10285| [7105] Microsoft Windows RPC endpoint mapper malformed request denial of service
10286| [7039] Microsoft Exchange OWA denial of service
10287| [7008] Microsoft Windows 2000 IrDA device denial of service
10288| [6990] Microsoft ISA Server Proxy Service memory leak denial of service
10289| [6989] Microsoft ISA Server H.323 Gatekeeper Service memory leak denial of service
10290| [6983] Microsoft IIS invalid MIME header denial of service
10291| [6982] Microsoft IIS WebDAV long invalid request denial of service
10292| [6981] Microsoft IIS URL redirection denial of service
10293| [6977] Microsoft Windows NT and 2000 NNTP memory leak denial of service
10294| [6943] Microsoft Windows NT NT4ALL denial of service
10295| [6931] Microsoft Windows 2000 without Service Pack 2
10296| [6924] Microsoft Windows 98 ARP packet flooding denial of service
10297| [6914] Multiple Microsoft products malformed RPC request denial of service
10298| [6883] Microsoft SFU Telnet denial of service
10299| [6882] Microsoft SFU NFS denial of service
10300| [6858] Microsoft IIS cross-site scripting patch denial of service
10301| [6803] Microsoft Windows 2000 SMTP service allows mail relaying
10302| [6669] Microsoft Windows 2000 Telnet system call denial of service
10303| [6668] Microsoft Windows 2000 Telnet handle leak denial of service
10304| [6667] Microsoft Windows 2000 Telnet multiple idle sessions denial of service
10305| [6666] Microsoft Windows 2000 Telnet username denial of service
10306| [6665] Microsoft Windows 2000 Telnet service weak domain authentication
10307| [6664] Microsoft Windows 2000 Telnet service predictable pipe names could allow elevation of privileges
10308| [6651] Microsoft ISA Server Web Proxy denial of service caused by embedded code in HTML email
10309| [6549] Microsoft IIS WebDAV lock method memory leak can cause a denial of service
10310| [6535] Microsoft IIS FTP wildcard processing function denial of service
10311| [6506] Microsoft Windows 2000 Server Kerberos denial of service
10312| [6383] Microsoft ISA Server Web Proxy denial of service
10313| [6205] Microsoft IIS WebDAV denial of service
10314| [6172] Microsoft Exchange malformed URL request denial of service
10315| [6171] Microsoft IIS and Exchange malformed URL request denial of service
10316| [6136] Microsoft Windows 2000 domain controller denial of service
10317| [6103] Microsoft Windows NT PPTP denial of service
10318| [6070] Microsoft Windows UDP socket denial of service
10319| [6035] Microsoft Windows 2000 Server RDP denial of service
10320| [6006] Microsoft Windows NT mutex denial of service
10321| [5938] Microsoft Internet Explorer mshtml.dll denial of service
10322| [5936] Microsoft Windows 2000 Server Directory Service Restore Mode allows user to login with blank password
10323| [5823] Microsoft IIS Web form submission denial of service
10324| [5800] Microsoft Windows 2000 Index Service ActiveX controls allow unauthorized access to file information
10325| [5785] Microsoft Media Services dropped connection denial of service
10326| [5746] Microsoft Windows NT MSTask.exe denial of service
10327| [5623] Microsoft Windows NT and 2000 Phone Book service buffer overflow
10328| [5598] Microsoft Windows 2000 Telnet daemon could allow a denial of service
10329| [5573] Microsoft Windows NT SynAttackProtect denial of service
10330| [5510] Microsoft Internet Information Service (IIS) ISAPI buffer overflow
10331| [5502] Microsoft Windows 2000 Indexing Services ixsso.query
10332| [5489] Microsoft Windows NT Terminal Server GINA RegAPI.DLL buffer overflow
10333| [5470] Microsoft Internet Information Service (IIS) invalid executable filename passing
10334| [5417] Microsoft Windows NT MSIEXEC service uses the msi.dll registery key that has weak permissions
10335| [5411] Microsoft Windows File Share service denial of service
10336| [5387] Microsoft Windows HyperTerminal Telnet buffer overflow
10337| [5370] Microsoft Windows 9x NetBIOS invalid driver type denial of service
10338| [5357] Microsoft Windows 9x malformed NWLink NMPI packet denial of service
10339| [5222] Microsoft Windows 2000 malformed RPC packet denial of service
10340| [5203] Microsoft Windows 2000 still image service
10341| [5202] Microsoft IIS invalid URL allows attackers to crash service
10342| [5193] Microsoft Windows Media Services Unicast Service denial of service
10343| [5124] Microsoft FrontPage Server Extensions device name denial of service
10344| [5079] Microsoft Windows 95/98 malformed IPX ping packet denial of service
10345| [5033] Microsoft Windows 2000 without Service Pack 1
10346| [5031] Microsoft Windows 2000 Service Control Manager named pipe could allow a unauthorized user to gain privileges
10347| [4899] Microsoft FrontPage Extensions shtml.dll multiple access denial of service
10348| [4893] Microsoft mail clients denial of service
10349| [4823] Microsoft Windows 2000 Telnet server binary stream denial of service
10350| [4790] Microsoft IIS \mailroot\pickup directory denial of service
10351| [4698] Microsoft Windows EventLog service started
10352| [4648] Microsoft Windows NT malformed remote registry request denial of service
10353| [4600] Microsoft Windows NT denial of service caused by unacknowledged SMB requests
10354| [4585] Microsoft Windows Encoder denial of service
10355| [4552] Microsoft Windows Browser service can be shutdown by an unauthorized remote user
10356| [4430] Microsoft IIS malformed URL extension data denial of service
10357| [4279] Microsoft IIS escape characters denial of service
10358| [4203] Microsoft Windows TCP/IP Printing Service denial of service
10359| [4140] Microsoft Windows Telnet service authentication may expose user passwords
10360| [4117] Microsoft IIS chunked encoding post or put denial of service
10361| [4108] Microsoft Windows Media Technologies malformed license request denial of service
10362| [4107] Microsoft Windows path names containing DOS devices denial of service
10363| [4034] Microsoft Windows Media Services handshake packets denial of service
10364| [3993] Microsoft Windows Trin00 Distributed Denial of Service (DDoS) tool found
10365| [3959] Microsoft Direct Access Object (DAO) or JET method denial of service
10366| [3694] Microsoft Windows NT malformed resource enumeration denial of service
10367| [3534] Microsoft Windows NT 4.0 without Service Pack 6
10368| [3391] Microsoft FrontPage Extensions service.pwd file could reveal encrypted passwords
10369| [3328] Microsoft Windows ARP packet denial of service
10370| [3246] Microsoft HTML table form Denial of Service
10371| [3115] Microsoft IIS and SiteServer denial of service caused by malformed HTTP requests
10372| [3104] Microsoft Windows NT TSE denial of service can consume all available memory
10373| [2299] Microsoft Windows NT CSRSS denial of service
10374| [2229] Microsoft IIS ExAir sample site denial of service
10375| [2201] Microsoft Windows NT 4.0 without Service Pack 5
10376| [2095] Microsoft SQL Server OLE Automation extended stored procedures were found that can be used to reconfigure the security of other services
10377| [2093] The account under which the Microsoft SQL Server service is running is not in compliance with policy
10378| [1977] Microsoft Windows NT RPC services can be used to deplete system resources
10379| [1969] Microsoft Exchange LDAP denial of service
10380| [1823] Microsoft IIS long GET request denial of service
10381| [1769] Latest Microsoft SQL Server Service Packs are not installed
10382| [1394] Microsoft Windows NT 4.0 without Service Pack 4
10383| [1376] Microsoft Proxy 2.0 denial of service
10384| [1296] Microsoft Windows service user
10385| [1295] Microsoft Windows NT service user password found
10386| [1223] Microsoft Exchange Server SMTP and NNTP denial of service
10387| [530] Microsoft Windows NT RAS service packet filtering rules can be bypassed
10388| [342] Microsoft Windows NT SMB logon denial of service
10389| [186] Microsoft Windows NT DNS denial of service
10390| [140] Microsoft Windows telnet service installed
10391| [120] Microsoft Windows schedule service running
10392| [114] Microsoft Windows NT rsh service Running
10393| [102] Microsoft Windows NT rexec service running
10394| [98] Microsoft Windows NT rcmd service running
10395| [92] Microsoft Windows NT rlogin service installed
10396| [17] Microsoft Windows NT RPC locator denial of service
10397| [16] Microsoft Windows Remote Access Service
10398| [14] Microsoft Windows NT 4.0 without Service Pack 3
10399|
10400| Exploit-DB - https://www.exploit-db.com:
10401| [21123] Microsoft Windows 2000/NT Terminal Server Service RDP DoS Vulnerability
10402| [18606] Microsoft Terminal Services Use After Free (MS12-020)
10403| [30756] Microsoft Forms 2.0 ActiveX Control 2.0 Memory Access Violation Denial of Service Vulnerabilities
10404| [30749] Microsoft Office 2003 Web Component Memory Access Violation Denial of Service Vulnerability
10405| [30619] Microsoft Windows Explorer PNG Image - Local Denial Of Service Vulnerability
10406| [30493] Microsoft XML Core Services <= 6.0 SubstringData Integer Overflow Vulnerability
10407| [30462] Microsoft Windows Media Player 11 - AU Divide-By-Zero Denial of Service Vulnerability
10408| [30455] Microsoft Internet Explorer 6.0 Position:Relative Denial of Service Vulnerability
10409| [30160] Microsoft Windows XP - GDI+ ICO File Remote Denial of Service Vulnerability
10410| [29813] Microsoft Windows Vista ARP Table Entries Denial of Service Vulnerability
10411| [29800] Microsoft Internet Explorer 7.0 HTML Denial of Service Vulnerability
10412| [29738] Microsoft Windows XP/2000 WinMM.DLL - WAV Files Remote Denial of Service (DoS) Vulnerability
10413| [29664] Microsoft Office Publisher 2007 - Remote Denial of Service (DoS) Vulnerability
10414| [29660] Microsoft Office 2003 - Denial of Service (DoS) Vulnerability
10415| [29659] Microsoft Windows XP/2003 Explorer WMF File Handling Denial of Service Vulnerability
10416| [29536] Microsoft Internet Explorer 5.0.1 - Multiple ActiveX Controls Denial of Service Vulnerabilities
10417| [29295] Microsoft Outlook ActiveX Control Remote Internet Explorer Denial of Service Vulnerability
10418| [29236] Microsoft Internet Explorer 7.0 CSS Width Element Denial of Service Vulnerability
10419| [29229] Microsoft Internet Explorer 6.0 Frame Src Denial of Service Vulnerability
10420| [29172] Microsoft Office 97 HTMLMARQ.OCX Library Denial of Service Vulnerability
10421| [28897] Microsoft Internet Explorer 7.0 MHTML Denial of Service Vulnerability
10422| [28880] Microsoft Internet Explorer 6.0/7.0 RemoveChild Denial of Service Vulnerability
10423| [28500] Microsoft Indexing Service Query Validation Cross-Site Scripting Vulnerability
10424| [28421] Microsoft Internet Explorer 6.0 - Multiple COM Object Color Property Denial of Service Vulnerabilities
10425| [28401] Microsoft Internet Explorer 6.0 Visual Studio COM Object Instantiation Denial of Service Vulnerability
10426| [28389] Microsoft Internet Explorer 6.0 MSOE.DLL Denial of Service Vulnerability
10427| [28387] Microsoft Internet Explorer 6.0 IMSKDIC.DLL Denial of Service Vulnerability
10428| [28343] Microsoft Internet Explorer 6.0/7.0 IFrame Refresh Denial of Service Vulnerability
10429| [28301] Microsoft Internet Explorer 6.0 Deleted Frame Object Denial of Service Vulnerability
10430| [28299] Microsoft Windows XP/2000/2003 Graphical Device Interface Plus Library Denial of Service Vulnerability
10431| [28265] Microsoft Internet Explorer 6.0 Native Function Iterator Denial of Service Vulnerability
10432| [28263] Microsoft Windows XP/2000/2003 Remote Denial of Service Vulnerability
10433| [28258] Microsoft Internet Explorer 6.0 - Multiple Object ListWidth Property Denial of Service Vulnerability
10434| [28256] Microsoft Internet Explorer 6.0 Internet.HHCtrl Click Denial of Service Vulnerability
10435| [28252] Microsoft Internet Explorer 6.0 String To Binary Function Denial of Service Vulnerability
10436| [28246] Microsoft Internet Explorer 6.0 OVCtl Denial of Service Vulnerability
10437| [28244] Microsoft Internet Explorer 6.0 DataSourceControl Denial of Service Vulnerability
10438| [28227] Microsoft Windows 2000/XP Registry Access Local Denial of Service Vulnerability
10439| [28213] Microsoft Internet Explorer 6.0 RevealTrans Denial of Service Vulnerability
10440| [28207] Microsoft Internet Explorer 6.0 TriEditDocument Denial of Service Vulnerability
10441| [28202] Microsoft Internet Explorer 6.0 HtmlDlgSafeHelper Remote Denial of Service Vulnerability
10442| [28197] Microsoft Internet Explorer 6.0 Object.Microsoft.DXTFilter Denial of Service Vulnerability
10443| [28196] Microsoft Internet Explorer 6.0 DirectAnimation.DAUserData Denial of Service Vulnerability
10444| [28194] Microsoft Internet Explorer 6 RDS.DataControl Denial of Service Vulnerability
10445| [28169] Microsoft Internet Explorer 5.0.1/6.0 Structured Graphics Control Denial of Service Vulnerability
10446| [28164] Microsoft Internet Explorer 6.0 Href Title Denial of Service Vulnerability
10447| [28145] Microsoft Internet Explorer 6.0 ADODB.Recordset Filter Property Denial of Service Vulnerability
10448| [28144] Microsoft Internet Explorer 6.0 OutlookExpress.AddressBook Denial of Service Vulnerability
10449| [28001] Microsoft SMB Driver Local Denial of Service Vulnerability
10450| [27906] Microsoft Internet Explorer 6.0 Malformed HTML Parsing Denial of Service Vulnerability
10451| [27082] Microsoft Internet Explorer 5.0.1 Malformed IMG and XML Parsing Denial of Service Vulnerability
10452| [26985] Microsoft Internet Explorer 5.0.1 HTML Parsing Denial of Service Vulnerabilities
10453| [26690] Microsoft Windows 2000/2003/XP CreateRemoteThread Local Denial of Service Vulnerability
10454| [26457] Microsoft Internet Explorer 6.0 Malformed HTML Parsing Denial of Service Vulnerability
10455| [26341] Microsoft Windows 2000/2003/XP MSDTC TIP Denial of Service Vulnerability
10456| [26323] Microsoft Windows XP Wireless Zero Configuration Service Information Disclosure Vulnerability
10457| [26292] Microsoft Internet Explorer 5.2.3 for Mac OS Denial of Service Vulnerability
10458| [25992] Microsoft Internet Explorer 5.0.1 JPEG Image Rendering CMP Fencepost Denial of Service Vulnerability
10459| [25962] Microsoft ASP.NET 1.0/1.1 RPC/Encoded Remote Denial of Service Vulnerability
10460| [25737] Microsoft Windows 98SE User32.DLL Icon Handling Denial of Service Vulnerability
10461| [25268] Microsoft Windows XP TSShutdn.exe Remote Denial of Service Vulnerability
10462| [25259] Microsoft Windows XP Local Denial of Service Vulnerability
10463| [25231] Microsoft Windows 2000/2003/XP Graphical Device Interface Library Denial of Service Vulnerability
10464| [24775] Microsoft Internet Explorer 6.0 Infinite Array Sort Denial of Service Vulnerability
10465| [24705] Microsoft Internet Explorer 6.0 Font Tag Denial of Service Vulnerability
10466| [24699] Microsoft Windows XP WAV File Handler Denial of Service Vulnerability
10467| [24640] Microsoft SQL Server 7.0 - Remote Denial of Service Vulnerability (2)
10468| [24639] Microsoft SQL Server 7.0 - Remote Denial of Service Vulnerability (1)
10469| [24605] Microsoft Windows XP Explorer.EXE TIFF Image Denial of Service Vulnerability
10470| [24281] Microsoft Systems Management Server 1.2/2.0 - Remote Denial of Service Vulnerability
10471| [24267] Microsoft Internet Explorer 6.0 JavaScript Null Pointer Exception Denial of Service Vulnerability
10472| [24211] Microsoft Internet Explorer 6.0 HREF Save As Denial of Service Vulnerability
10473| [24119] Microsoft Internet Explorer 5.0.1 http-equiv Meta Tag Denial of Service Vulnerability
10474| [24112] Microsoft Internet Explorer 6.0 XML Parsing Denial of Service Vulnerability
10475| [24002] Microsoft Outlook Express 6.0 - Remote Denial of Service Vulnerability
10476| [23912] Microsoft Internet Explorer 6.0 Macromedia Flash Player Plug-in Remote Denial of Service Vulnerability
10477| [23911] Microsoft Internet Explorer 6.0 MSWebDVD Object Denial of Service Vulnerability
10478| [23850] Microsoft Windows XP Explorer.EXE Remote Denial of Service Vulnerability
10479| [23273] Microsoft Internet Explorer 6.0 Scrollbar-Base-Color Partial Denial of Service Vulnerability
10480| [23247] Microsoft Windows XP/2000 Messenger Service Buffer Overrun Vulnerability
10481| [23229] Microsoft Windows XP/2000/2003 Message Queuing Service Heap Overflow Vulnerability
10482| [23216] Microsoft Word 97/98/2002 Malformed Document Denial of Service Vulnerability
10483| [23215] Microsoft Internet Explorer 6 Absolute Position Block Denial of Service Vulnerability
10484| [23101] Microsoft Windows 98 Fragmented UDP Flood Denial of Service Vulnerability
10485| [22957] Microsoft SQL Server 7.0/2000,MSDE Named Pipe Denial of Service Vulnerability
10486| [22837] Microsoft Windows 2000/NT 4 Media Services NSIISlog.DLL Remote Buffer Overflow
10487| [22670] Microsoft IIS 5 WebDAV PROPFIND and SEARCH Method Denial of Service Vulnerability
10488| [22390] Microsoft ActiveSync 3.5 Null Pointer Dereference Denial of Service Vulnerability
10489| [22194] Microsoft Windows XP/2000/NT 4 Locator Service Buffer Overflow Vulnerability
10490| [22132] Microsoft Windows XP/2000 Fontview Denial of Service Vulnerability
10491| [22119] Microsoft Pocket Internet Explorer 3.0 - Denial of Service Vulnerability
10492| [21954] Microsoft Windows XP/2000/NT 4 RPC Service Denial of Service Vulnerability (4)
10493| [21953] Microsoft Windows XP/2000/NT 4 RPC Service Denial of Service Vulnerability (3)
10494| [21952] Microsoft Windows XP/2000/NT 4 RPC Service Denial of Service Vulnerability (2)
10495| [21951] Microsoft Windows XP/2000/NT 4 RPC Service Denial of Service Vulnerability (1)
10496| [21652] Microsoft SQL Server 2000 Resolution Service Heap Overflow Vulnerability
10497| [21613] Microsoft IIS 4/5 SMTP Service Encapsulated SMTP Address Vulnerability
10498| [21556] Microsoft Internet Explorer 5/6 CSSText Bold Font Denial of Service
10499| [21481] Microsoft MSN Messenger 1-4 Malformed Invite Request Denial of Service
10500| [21419] Microsoft Outlook Express 5.5 DoS Device Denial of Service Vulnerability
10501| [21404] Microsoft Internet Explorer 5/6 Self-Referential Object Denial of Service Vulnerability
10502| [21389] Microsoft Windows 2000 Lanman Denial of Service Vulnerability (2)
10503| [21388] Microsoft Windows 2000 Lanman Denial of Service Vulnerability (1)
10504| [21240] Microsoft Windows XP .Manifest Denial of Service Vulnerability
10505| [21131] Microsoft Windows 2000/XP GDI Denial of Service Vulnerability
10506| [21099] Microsoft Windows 2000 RunAs Service Denial of Services Vulnerability
10507| [21069] Microsoft Windows 2000 RunAs Service Named Pipe Hijacking Vulnerability
10508| [20846] Microsoft IIS 4.0/5.0 FTP Denial of Service Vulnerability
10509| [20802] Microsoft IIS 2.0/3.0 Long URL Denial of Service Vulnerability
10510| [20664] Microsoft IIS 5.0 WebDAV Denial of Service Vulnerability
10511| [20508] Microsoft NT 4.0 RAS/PPTP Malformed Control Packet Denial of Service Attack
10512| [20399] Microsoft Indexing Services for Windows 2000 File Verification Vulnerability
10513| [20335] Microsoft Indexing Services for Windows 2000/NT 4.0 .htw Cross-Site Scripting Vulnerability
10514| [20209] Microsoft Windows 2000 Still Image Service Privilege Escalation Vulnerability
10515| [19974] Microsoft Windows Media Services 4.0/4.1 DoS Vulnerability
10516| [19759] Microsoft Windows Media Services 4.0/4.1 Handshake Sequence DoS
10517| [19731] microsoft index server 2.0/indexing services for windows 2000 - Directory Traversal
10518| [19578] Microsoft Windows NT 4.0/SP1/SP2/SP3/SP4/SP5/SP6 Services.exe Denial of Service (2)
10519| [19577] Microsoft Windows NT 4.0/SP1/SP2/SP3/SP4/SP5/SP6 Services.exe Denial of Service (1)
10520| [19516] Microsoft MSN Messenger Service 1.0 Setup BBS ActiveX Control Buffer Overflow
10521| [19207] Microsoft Outlook Express 4.27.3110/4.72.3120 POP Denial of Service Vulnerability
10522| [19197] "Microsoft Windows NT <= 4.0 SP5,Terminal Server 4.0 ""Pass the Hash"" with Modified SMB Client Vulnerability"
10523| [19186] Microsoft XML Core Services MSXML Uninitialized Memory Corruption
10524| [17830] Microsoft WINS Service <= 5.2.3790.4520 Memory Corruption
10525| [16750] Microsoft Message Queueing Service DNS Name Path Overflow
10526| [16748] Microsoft DNS RPC Service extractQuotedChar() Overflow (TCP)
10527| [16747] Microsoft Message Queueing Service Path Overflow
10528| [16378] Microsoft Workstation Service NetAddAlternateComputerName Overflow
10529| [16375] Microsoft RRAS Service RASMAN Registry Overflow
10530| [16373] Microsoft Services MS06-066 nwapi32.dll
10531| [16372] Microsoft Workstation Service NetpManageIPCConnect Overflow
10532| [16371] Microsoft NetDDE Service Overflow
10533| [16369] Microsoft Services MS06-066 nwwks.dll
10534| [16368] Microsoft LSASS Service DsRolerUpgradeDownlevelServer Overflow
10535| [16367] Microsoft Server Service NetpwPathCanonicalize Overflow
10536| [16366] Microsoft DNS RPC Service extractQuotedChar() Overflow (SMB)
10537| [16365] Microsoft Plug and Play Service Overflow
10538| [16364] Microsoft RRAS Service Overflow
10539| [16362] Microsoft Server Service Relative Path Stack Corruption
10540| [16361] Microsoft Print Spooler Service Impersonation Vulnerability
10541| [16359] Microsoft WINS Service Memory Overwrite
10542| [16357] Microsoft IIS Phone Book Service Overflow
10543| [16095] Terminal Server Client .rdp Denial of Service
10544| [15839] Microsoft Windows Fax Services Cover Page Editor (.cov) Memory Corruption
10545| [15167] Microsoft IIS 6.0 ASP Stack Overflow (Stack Exhaustion) Denial of Service (MS10-065)
10546| [14705] Microsoft Windows (IcmpSendEcho2Ex interrupting) Denial of Service Vulnerability
10547| [14179] Microsoft Internet Information Services (IIS) 5 Authentication Bypass Vulnerability (MS10-065)
10548| [12079] Microsoft Office (2010 beta) Communicator SIP Denial of Service Exploit
10549| [9587] Microsoft IIS 5.0/6.0 FTP Server (Stack Exhaustion) Denial of Service
10550| [8466] Microsoft GDI Plugin .png Infinite Loop Denial of Service PoC
10551| [8465] Microsoft Media Player - (quartz.dll .mid) Denial of Service Exploit
10552| [7262] Microsoft Office Communicator (SIP) Remote Denial of Service Exploit
10553| [7196] Microsoft XML Core Services DTD Cross-Domain Scripting PoC MS08-069
10554| [5460] Microsoft Works 7 WkImgSrv.dll ActiveX Denial of Service PoC
10555| [3965] Microsoft IIS 6.0 (/AUX/.aspx) Remote Denial of Service Exploit
10556| [1488] Microsoft HTML Help Workshop (.hhp file) Denial of Service
10557|
10558| OpenVAS (Nessus) - http://www.openvas.org:
10559| [902914] Microsoft IIS GET Request Denial of Service Vulnerability
10560| [902909] Microsoft Windows Service Pack Missing Multiple Vulnerabilities
10561| [902908] Microsoft Windows DirectWrite Denial of Service Vulnerability (2665364)
10562| [902906] Microsoft Windows DNS Server Denial of Service Vulnerability (2647170)
10563| [902782] MicroSoft Windows Server Service Remote Code Execution Vulnerability (921883)
10564| [902708] Microsoft Remote Desktop Protocol Denial of Service Vulnerability (2570222)
10565| [902694] Microsoft Windows IIS FTP Service Information Disclosure Vulnerability (2761226)
10566| [902580] Microsoft Host Integration Server Denial of Service Vulnerabilities (2607670)
10567| [902290] Microsoft Windows Active Directory SPN Denial of Service (2478953)
10568| [902277] Microsoft Windows Netlogon Service Denial of Service Vulnerability (2207559)
10569| [902227] Microsoft Windows LSASS Denial of Service Vulnerability (975467)
10570| [902183] Microsoft Internet Explorer 'IFRAME' Denial Of Service Vulnerability
10571| [902151] Microsoft Internet Explorer Denial of Service Vulnerability - Mar10
10572| [902115] Microsoft Kerberos Denial of Service Vulnerability (977290)
10573| [902033] Microsoft Windows '.ani' file Denial of Service vulnerability
10574| [901301] Microsoft Windows Kerberos Denial of Service Vulnerability (2743555)
10575| [901164] Microsoft Windows SChannel Denial of Service Vulnerability (2207566)
10576| [901151] Microsoft Internet Information Services Remote Code Execution Vulnerabilities (2267960)
10577| [901150] Microsoft Windows Print Spooler Service Remote Code Execution Vulnerability(2347290)
10578| [901102] Microsoft Windows Media Services Remote Code Execution Vulnerability (980858)
10579| [901063] Microsoft Windows LSASS Denial of Service Vulnerability (975467)
10580| [901048] Microsoft Windows Active Directory Denial of Service Vulnerability (973309)
10581| [900891] Microsoft Internet Denial Of Service Vulnerability - Nov09
10582| [900881] Microsoft Windows Indexing Service ActiveX Vulnerability (969059)
10583| [900877] Microsoft Windows LSASS Denial of Service Vulnerability (975467)
10584| [900874] Microsoft IIS FTP Service Remote Code Execution Vulnerabilities (975254)
10585| [900461] Microsoft MSN Live Messneger Denial of Service Vulnerability
10586| [900337] Microsoft Internet Explorer Denial of Service Vulnerability - Apr09
10587| [900314] Microsoft XML Core Service Information Disclosure Vulnerability
10588| [900297] Microsoft Windows Kernel Denial of Service Vulnerability (2556532)
10589| [900296] Microsoft Windows TCP/IP Stack Denial of Service Vulnerability (2563894)
10590| [900240] Microsoft Exchange and Windows SMTP Service Denial of Service Vulnerability (981832)
10591| [900131] Microsoft Internet Explorer Denial of Service Vulnerability
10592| [900058] Microsoft XML Core Services Remote Code Execution Vulnerability (955218)
10593| [802888] Microsoft Windows Media Service Handshake Sequence DoS Vulnerability
10594| [802864] Microsoft XML Core Services Remote Code Execution Vulnerability (2719615)
10595| [802462] Microsoft ActiveSync Null Pointer Dereference Denial Of Service Vulnerability
10596| [801721] Microsoft Active Directory Denial of Service Vulnerability (953235)
10597| [801715] Microsoft XML Core Services Remote Code Execution Vulnerability (936227)
10598| [801705] Microsoft Windows TCP/IP Denial of Service Vulnerability (946456)
10599| [801704] Microsoft Internet Information Services Privilege Elevation Vulnerability (942831)
10600| [801701] Microsoft Windows DNS Client Service Response Spoofing Vulnerability (945553)
10601| [801485] Microsoft Pragmatic General Multicast (PGM) Denial of Service Vulnerability (950762)
10602| [801482] Microsoft Windows ASP.NET Denial of Service Vulnerability(970957)
10603| [801481] Microsoft Wireless LAN AutoConfig Service Remote Code Execution Vulnerability (970710)
10604| [801480] Microsoft Web Services on Devices API Remote Code Execution Vulnerability (973565)
10605| [801349] Microsoft Internet Explorer 'IFRAME' Denial Of Service Vulnerability (June-10)
10606| [801348] Microsoft Internet Explorer 'IFRAME' Denial Of Service Vulnerability -june 10
10607| [800968] Microsoft SharePoint Team Services Information Disclosure Vulnerability
10608| [800669] Microsoft Internet Explorer Denial Of Service Vulnerability - July09
10609| [800504] Microsoft Windows XP SP3 denial of service vulnerability
10610| [800310] Microsoft Windows Media Services nskey.dll ActiveX BOF Vulnerability
10611| [800218] Microsoft Money 'prtstb06.dll' Denial of Service vulnerability
10612| [100607] Microsoft SMTP Service and Exchange Routing Engine Buffer Overflow Vulnerability
10613| [100596] Microsoft Windows SMTP Server MX Record Denial of Service Vulnerability
10614| [13752] Denial of Service (DoS) in Microsoft SMS Client
10615| [11433] Microsoft ISA Server DNS - Denial Of Service (MS03-009)
10616| [903041] Microsoft Windows Kernel Privilege Elevation Vulnerability (2724197)
10617| [903037] Microsoft JScript and VBScript Engines Remote Code Execution Vulnerability (2706045)
10618| [903036] Microsoft Windows Networking Components Remote Code Execution Vulnerabilities (2733594)
10619| [903035] Microsoft Windows Kernel-Mode Drivers Privilege Elevation Vulnerability (2731847)
10620| [903033] Microsoft Windows Kernel-Mode Drivers Privilege Elevation Vulnerabilities (2718523)
10621| [903028] Zebedee Allowed Redirection Port Denial of Service Vulnerability
10622| [903026] Microsoft Office Remote Code Execution Vulnerabilities (2663830)
10623| [903024] Wireshark Denial of Service Vulnerability (Mac OS X)
10624| [903022] Wireshark X.509if Dissector Denial of Service Vulnerability (Mac OS X)
10625| [903017] Microsoft Office Remote Code Execution Vulnerability (2639185)
10626| [903000] Microsoft Expression Design Remote Code Execution Vulnerability (2651018)
10627| [902936] Microsoft Windows Kernel-Mode Drivers Remote Code Execution Vulnerabilities (2783534)
10628| [902934] Microsoft .NET Framework Remote Code Execution Vulnerability (2745030)
10629| [902933] Microsoft Windows Shell Remote Code Execution Vulnerabilities (2727528)
10630| [902932] Microsoft Internet Explorer Multiple Use-After-Free Vulnerabilities (2761451)
10631| [902931] Microsoft Office Remote Code Execution Vulnerabilities - 2720184 (Mac OS X)
10632| [902930] Microsoft Office Remote Code Execution Vulnerabilities (2720184)
10633| [902929] hMailServer IMAP Remote Denial of Service Vulnerability
10634| [902923] Microsoft Internet Explorer Multiple Vulnerabilities (2722913)
10635| [902922] Microsoft Remote Desktop Protocol Remote Code Execution Vulnerability (2723135)
10636| [902921] Microsoft Office Visio/Viewer Remote Code Execution Vulnerability (2733918)
10637| [902920] Microsoft Office Remote Code Execution Vulnerability (2731879)
10638| [902919] Microsoft SharePoint Privilege Elevation Vulnerabilities (2663841)
10639| [902918] WinRadius Server Access Request Packet Parsing Denial of Service Vulnerability
10640| [902916] Microsoft Windows Kernel Privilege Elevation Vulnerabilities (2711167)
10641| [902913] Microsoft Office Remote Code Execution Vulnerabilities-2663830 (Mac OS X)
10642| [902912] Microsoft Office Word Remote Code Execution Vulnerability-2680352 (Mac OS X)
10643| [902911] Microsoft Office Word Remote Code Execution Vulnerability (2680352)
10644| [902910] Microsoft Office Visio Viewer Remote Code Execution Vulnerability (2597981)
10645| [902900] Microsoft Windows SSL/TLS Information Disclosure Vulnerability (2643584)
10646| [902846] Microsoft Windows TLS Protocol Information Disclosure Vulnerability (2655992)
10647| [902845] Microsoft Windows Shell Remote Code Execution Vulnerability (2691442)
10648| [902842] Microsoft Lync Remote Code Execution Vulnerabilities (2707956)
10649| [902841] Microsoft .NET Framework Remote Code Execution Vulnerability (2706726)
10650| [902839] Microsoft FrontPage Server Extensions MS-DOS Device Name DoS Vulnerability
10651| [902833] Microsoft .NET Framework Remote Code Execution Vulnerability (2693777)
10652| [902832] MS Security Update For Microsoft Office, .NET Framework, and Silverlight (2681578)
10653| [902829] Microsoft Windows Common Controls Remote Code Execution Vulnerability (2664258)
10654| [902828] Microsoft .NET Framework Remote Code Execution Vulnerability (2671605)
10655| [902826] KnFTP Server 'FEAT' Command Remote Denial of Service Vulnerability
10656| [902825] at32 Reverse Proxy Multiple HTTP Header Fields Denial Of Service Vulnerability
10657| [902824] Epson EventManager 'x-protocol-version' Denial of Service Vulnerability
10658| [902822] PHP Built-in WebServer 'Content-Length' Denial of Service Vulnerability
10659| [902820] Tiny Server HTTP HEAD Request Remote Denial of Service Vulnerability
10660| [902819] Telnet-FTP Server 'RETR' Command Remote Denial of Service Vulnerability
10661| [902818] Microsoft Remote Desktop Protocol Remote Code Execution Vulnerabilities (2671387)
10662| [902817] Microsoft Visual Studio Privilege Elevation Vulnerability (2651019)
10663| [902815] TCP Sequence Number Approximation Reset Denial of Service Vulnerability
10664| [902811] Microsoft .NET Framework and Microsoft Silverlight Remote Code Execution Vulnerabilities (2651026)
10665| [902807] Microsoft Windows Media Could Allow Remote Code Execution Vulnerabilities (2636391)
10666| [902803] FreeSSHd Remote Denial of Service Vulnerability
10667| [902798] Microsoft SMB Signing Enabled and Not Required At Server
10668| [902797] Microsoft SMB Signing Information Disclosure Vulnerability
10669| [902796] Microsoft IIS IP Address/Internal Network Name Disclosure Vulnerability
10670| [902785] Microsoft AntiXSS Library Information Disclosure Vulnerability (2607664)
10671| [902784] Microsoft Windows Object Packager Remote Code Execution Vulnerability (2603381)
10672| [902783] Microsoft Windows Kernel Security Feature Bypass Vulnerability (2644615)
10673| [902781] Windows Media Player Denial Of Service Vulnerability
10674| [902780] Putty Denial of Service Vulnerability
10675| [902776] Mozilla Products DOM Frame Denial of Service Vulnerability (MAC OS X)
10676| [902766] Microsoft Windows Kernel Privilege Elevation Vulnerability (2633171)
10677| [902760] ClamAV Recursion Level Handling Denial of Service Vulnerability (Windows)
10678| [902757] Zoho ManageEngine ADSelfService Plus Cross Site Scripting Vulnerability
10679| [902746] Microsoft Active Accessibility Remote Code Execution Vulnerability (2623699)
10680| [902727] Microsoft Office Excel Remote Code Execution Vulnerabilities (2587505)
10681| [902726] ClamAV Hash Manager Off-By-One Denial of Service Vulnerability (Win)
10682| [902722] Wireshark IKE Packet Denial of Service Vulnerability (Win)
10683| [902721] Wireshark ANSI A MAP Files Denial of Service Vulnerability (Win)
10684| [902696] Microsoft Internet Explorer Multiple Vulnerabilities (2761465)
10685| [902693] Microsoft Windows Kernel-Mode Drivers Remote Code Execution Vulnerabilities (2761226)
10686| [902692] Microsoft Office Excel ReadAV Arbitrary Code Execution Vulnerability
10687| [902689] Microsoft SQL Server Report Manager Cross Site Scripting Vulnerability (2754849)
10688| [902688] Microsoft System Center Configuration Manager XSS Vulnerability (2741528)
10689| [902687] Microsoft Windows Data Access Components Remote Code Execution Vulnerability (2698365)
10690| [902686] Microsoft Internet Explorer Multiple Vulnerabilities (2719177)
10691| [902684] Wireshark Multiple Denial of Service Vulnerabilities June-11 (Mac OS X)
10692| [902683] Microsoft Remote Desktop Protocol Remote Code Execution Vulnerability (2685939)
10693| [902682] Microsoft Internet Explorer Multiple Vulnerabilities (2699988)
10694| [902678] Microsoft Silverlight Code Execution Vulnerabilities - 2681578 (Mac OS X)
10695| [902677] Microsoft Windows Prtition Manager Privilege Elevation Vulnerability (2690533)
10696| [902676] Microsoft Windows TCP/IP Privilege Elevation Vulnerabilities (2688338)
10697| [902670] Microsoft Internet Explorer Multiple Vulnerabilities (2675157)
10698| [902664] Apache Traffic Server HTTP Host Header Denial of Service Vulnerability
10699| [902663] Microsoft Remote Desktop Protocol Remote Code Execution Vulnerabilities (2671387)
10700| [902662] MicroSoft SMB Server Trans2 Request Remote Code Execution Vulnerability
10701| [902660] Microsoft SMB Transaction Parsing Remote Code Execution Vulnerability
10702| [902658] Microsoft RDP Server Private Key Information Disclosure Vulnerability
10703| [902650] Pidgin XMPP And SILC Protocols Denial of Service Vulnerabilities (Win)
10704| [902649] Microsoft Internet Explorer Multiple Vulnerabilities (2647516)
10705| [902642] Microsoft Internet Explorer Multiple Vulnerabilities (2618444)
10706| [902626] Microsoft SharePoint SafeHTML Information Disclosure Vulnerabilities (2412048)
10707| [902625] Microsoft SharePoint Multiple Privilege Escalation Vulnerabilities (2451858)
10708| [902613] Microsoft Internet Explorer Multiple Vulnerabilities (2559049)
10709| [902609] Microsoft Windows CSRSS Privilege Escalation Vulnerabilities (2507938)
10710| [902598] Microsoft Windows Time Component Remote Code Execution Vulnerability (2618451)
10711| [902597] Microsoft Windows Media Remote Code Execution Vulnerability (2648048)
10712| [902596] Microsoft Windows OLE Remote Code Execution Vulnerability (2624667)
10713| [902588] Microsoft Windows Internet Protocol Validation Remote Code Execution Vulnerability
10714| [902581] Microsoft .NET Framework and Silverlight Remote Code Execution Vulnerability (2604930)
10715| [902570] Colasoft Capsa Malformed SNMP V1 Packet Remote Denial of Service Vulnerability
10716| [902569] MetaServer RT Multiple Remote Denial of Service Vulnerabilities
10717| [902567] Microsoft Office Remote Code Execution Vulnerabilites (2587634)
10718| [902566] Microsoft Windows WINS Local Privilege Escalation Vulnerability (2571621)
10719| [902558] Ruby Random Number Generation Local Denial Of Service Vulnerability
10720| [902555] Finger Service Unused Account Disclosure Vulnerability
10721| [902552] Microsoft .NET Framework Chart Control Information Disclosure Vulnerability (2567943)
10722| [902551] Microsoft .NET Framework Information Disclosure Vulnerability (2567951)
10723| [902527] ejabberd XML Parsing Denial of Service Vulnerability (Windows)
10724| [902523] Microsoft .NET Framework and Silverlight Remote Code Execution Vulnerability (2514842)
10725| [902522] Microsoft .NET Framework Remote Code Execution Vulnerability (2538814)
10726| [902518] Microsoft .NET Framework Security Bypass Vulnerability
10727| [902516] Microsoft Windows WINS Remote Code Execution Vulnerability (2524426)
10728| [902502] Microsoft .NET Framework Remote Code Execution Vulnerability (2484015)
10729| [902501] Microsoft JScript and VBScript Scripting Engines Remote Code Execution Vulnerability (2514666)
10730| [902496] Microsoft Office IME (Chinese) Privilege Elevation Vulnerability (2652016)
10731| [902495] Microsoft Office Remote Code Execution Vulnerability (2590602)
10732| [902494] Microsoft Office Excel Remote Code Execution Vulnerability (2640241)
10733| [902493] Microsoft Publisher Remote Code Execution Vulnerabilities (2607702)
10734| [902492] Microsoft Office PowerPoint Remote Code Execution Vulnerabilities (2639142)
10735| [902487] Microsoft Windows Active Directory LDAPS Authentication Bypass Vulnerability (2630837)
10736| [902484] Microsoft Windows TCP/IP Remote Code Execution Vulnerability (2588516)
10737| [902476] ASAS Server End User Self Service (EUSS) SQL Injection Vulnerability
10738| [902469] ManageEngine ServiceDesk Plus Multiple Stored XSS Vulnerabilities
10739| [902464] Microsoft Visio Remote Code Execution Vulnerabilities (2560978)
10740| [902463] Microsoft Windows Client/Server Run-time Subsystem Privilege Escalation Vulnerability (2567680)
10741| [902460] Ciscokits TFTP Server Long Filename Denial Of Service Vulnerability
10742| [902455] Microsoft Visio Remote Code Execution Vulnerability (2560847)
10743| [902453] Smallftpd FTP Server Multiple Requests Denial of Service Vulnerability
10744| [902445] Microsoft XML Editor Information Disclosure Vulnerability (2543893)
10745| [902443] Microsoft Internet Explorer Multiple Vulnerabilities (2530548)
10746| [902440] Microsoft Windows SMB Server Remote Code Execution Vulnerability (2536275)
10747| [902430] Microsoft Office PowerPoint Remote Code Execution Vulnerabilities (2545814)
10748| [902425] Microsoft Windows SMB Accessible Shares
10749| [902423] Microsoft Office Visio Viewer Remote Code Execution Vulnerabilities (2663510)
10750| [902411] Microsoft Office PowerPoint Remote Code Execution Vulnerabilities (2489283)
10751| [902410] Microsoft Office Excel Remote Code Execution Vulnerabilities (2489279)
10752| [902403] Microsoft Windows Fraudulent Digital Certificates Spoofing Vulnerability
10753| [902396] JustSystems Ichitaro Products Denial of Service Vulnerability
10754| [902395] Microsoft Bluetooth Stack Remote Code Execution Vulnerability (2566220)
10755| [902378] Microsoft Office Excel Remote Code Execution Vulnerabilities (2537146)
10756| [902377] Microsoft Windows OLE Automation Remote Code Execution Vulnerability (2476490)
10757| [902365] Microsoft GDI+ Remote Code Execution Vulnerability (2489979)
10758| [902364] Microsoft Office Remote Code Execution Vulnerabilites (2489293)
10759| [902358] Google Chrome 'SPDY' Denial Of Service Vulnerability
10760| [902357] Google Chrome 'SPDY' Denial Of Service Vulnerability
10761| [902351] Microsoft Groove Remote Code Execution Vulnerability (2494047)
10762| [902337] Microsoft Windows Kernel Elevation of Privilege Vulnerability (2393802)
10763| [902336] Microsoft JScript and VBScript Scripting Engines Information Disclosure Vulnerability (2475792)
10764| [902325] Microsoft Internet Explorer 'CSS Import Rule' Use-after-free Vulnerability
10765| [902324] Microsoft SharePoint Could Allow Remote Code Execution Vulnerability (2455005)
10766| [902319] Microsoft Foundation Classes Could Allow Remote Code Execution Vulnerability (2387149)
10767| [902297] Terminal Server Client RDP File Processing BOF Vulnerabilities
10768| [902291] Novell eDirectory NCP Request Remote Denial of Service Vulnerability
10769| [902289] Microsoft Windows LSASS Privilege Escalation Vulnerability (2478960)
10770| [902288] Microsoft Kerberos Privilege Escalation Vulnerabilities (2496930)
10771| [902287] Microsoft Visio Remote Code Execution Vulnerabilities (2451879)
10772| [902285] Microsoft Internet Explorer Information Disclosure Vulnerability (2501696)
10773| [902281] Microsoft Windows Data Access Components Remote Code Execution Vulnerabilities (2451910)
10774| [902280] Microsoft Windows BranchCache Remote Code Execution Vulnerability (2385678)
10775| [902276] Microsoft Windows Task Scheduler Elevation of Privilege Vulnerability (2305420)
10776| [902274] Microsoft Publisher Remote Code Execution Vulnerability (2292970)
10777| [902269] Microsoft Windows SMB Server NTLM Multiple Vulnerabilities (971468)
10778| [902265] Microsoft Office Word Remote Code Execution Vulnerabilities (2293194)
10779| [902264] Microsoft Office Excel Remote Code Execution Vulnerabilities (2293211)
10780| [902263] Microsoft Windows Media Player Network Sharing Remote Code Execution Vulnerability (2281679)
10781| [902262] Microsoft Windows Shell and WordPad COM Validation Vulnerability (2405882)
10782| [902256] Microsoft Windows win32k.sys Driver 'CreateDIBPalette()' BOF Vulnerability
10783| [902255] Microsoft Visual Studio Insecure Library Loading Vulnerability
10784| [902254] Microsoft Office Products Insecure Library Loading Vulnerability
10785| [902250] Microsoft Word 2003 'MSO.dll' Null Pointer Dereference Vulnerability
10786| [902246] Microsoft Internet Explorer 'toStaticHTML()' Cross Site Scripting Vulnerability
10787| [902244] MS Local Security Authority Subsystem Service Privilege Elevation Vulnerability (983539)
10788| [902243] Microsoft Outlook TNEF Remote Code Execution Vulnerability (2315011)
10789| [902232] Microsoft Windows TCP/IP Privilege Elevation Vulnerabilities (978886)
10790| [902231] Microsoft Windows Tracing Feature Privilege Elevation Vulnerabilities (982799)
10791| [902230] Microsoft .NET Common Language Runtime Remote Code Execution Vulnerability (2265906)
10792| [902229] Microsoft Window MPEG Layer-3 Remote Code Execution Vulnerability (2115168)
10793| [902228] Microsoft Office Word Remote Code Execution Vulnerabilities (2269638)
10794| [902226] Microsoft Windows Shell Remote Code Execution Vulnerability (2286198)
10795| [902217] Microsoft Outlook SMB Attachment Remote Code Execution Vulnerability (978212)
10796| [902210] Microsoft IE cross-domain IFRAME gadgets keystrokes steal Vulnerability
10797| [902197] Wireshark SMB PIPE Dissector Denial of Service Vulnerability (Windows)
10798| [902196] Wireshark SMB dissector Denial of Service Vulnerability (Windows)
10799| [902193] Microsoft .NET Framework XML HMAC Truncation Vulnerability (981343)
10800| [902192] Microsoft Office COM Validation Remote Code Execution Vulnerability (983235)
10801| [902191] Microsoft Internet Explorer Multiple Vulnerabilities (982381)
10802| [902189] ClamAV 'cli_pdf()' and 'cli_scanicon()' Denial of Service Vulnerabilities (Win
10803| [902186] Mozilla Firefox Multiple Denial Of Service vulnerabilities (Windows)
10804| [902185] Mozilla Products 'IFRAME' Denial Of Service vulnerability (Windows)
10805| [902184] Google Chrome 'IFRAME' Denial Of Service Vulnerability
10806| [902182] Opera Browser Multiple Denial Of Service Vulnerability (Windows)
10807| [902178] Microsoft Visual Basic Remote Code Execution Vulnerability (978213)
10808| [902176] Microsoft SharePoint '_layouts/help.aspx' Cross Site Scripting Vulnerability
10809| [902173] VMware Authorization Service Denial of Service Vulnerability (Win) -Apr10
10810| [902166] Microsoft Internet Explorer 'neutering' Mechanism XSS Vulnerability
10811| [902159] Microsoft VBScript Scripting Engine Remote Code Execution Vulnerability (980232)
10812| [902158] Microsoft Office Publisher Remote Code Execution Vulnerability (981160)
10813| [902157] Microsoft 'ISATAP' Component Spoofing Vulnerability (978338)
10814| [902156] Microsoft SMB Client Remote Code Execution Vulnerabilities (980232)
10815| [902155] Microsoft Internet Explorer Multiple Vulnerabilities (980182)
10816| [902143] Mozilla Products Denial Of Service Vulnerability (Linux)
10817| [902142] Mozilla Products Denial Of Service Vulnerability (Win)
10818| [902133] Microsoft Office Excel Multiple Vulnerabilities (980150)
10819| [902117] Microsoft DirectShow Remote Code Execution Vulnerability (977935)
10820| [902116] Microsoft Client/Server Run-time Subsystem Privilege Elevation Vulnerability (978037)
10821| [902114] Microsoft Office PowerPoint Remote Code Execution Vulnerabilities (975416)
10822| [902112] Microsoft SMB Client Remote Code Execution Vulnerabilities (978251)
10823| [902095] Microsoft Office Excel Remote Code Execution Vulnerability (2269707)
10824| [902094] Microsoft Windows Kernel Mode Drivers Privilege Elevation Vulnerabilities (2160329)
10825| [902093] Microsoft Windows Kernel Privilege Elevation Vulnerabilities (981852)
10826| [902080] Microsoft Help and Support Center Remote Code Execution Vulnerability (2229593)
10827| [902069] Microsoft SharePoint Privilege Elevation Vulnerabilities (2028554)
10828| [902068] Microsoft Office Excel Remote Code Execution Vulnerabilities (2027452)
10829| [902067] Microsoft Windows Kernel Mode Drivers Privilege Escalation Vulnerabilities (979559)
10830| [902039] Microsoft Visio Remote Code Execution Vulnerabilities (980094)
10831| [902038] Microsoft MPEG Layer-3 Codecs Remote Code Execution Vulnerability (977816)
10832| [902015] Microsoft Paint Remote Code Execution Vulnerability (978706)
10833| [901305] Microsoft Windows IP-HTTPS Component Security Feature Bypass Vulnerability (2765809)
10834| [901304] Microsoft Windows File Handling Component Remote Code Execution Vulnerability (2758857)
10835| [901212] Microsoft Windows DirectPlay Remote Code Execution Vulnerability (2770660)
10836| [901211] Microsoft Windows Common Controls Remote Code Execution Vulnerability (2720573)
10837| [901210] Microsoft Office Privilege Elevation Vulnerability - 2721015 (Mac OS X)
10838| [901209] Microsoft Windows Media Center Remote Code Execution Vulnerabilities (2604926)
10839| [901208] Microsoft Internet Explorer Multiple Vulnerabilities (2586448)
10840| [901206] Check RPC rstatd Service Running
10841| [901205] Microsoft Windows Components Remote Code Execution Vulnerabilities (2570947)
10842| [901203] Apache httpd Web Server Range Header Denial of Service Vulnerability
10843| [901202] Check rlogin Service Running
10844| [901193] Microsoft Windows Media Remote Code Execution Vulnerabilities (2510030)
10845| [901183] Internet Information Services (IIS) FTP Service Remote Code Execution Vulnerability (2489256)
10846| [901180] Microsoft Internet Explorer Multiple Vulnerabilities (2482017)
10847| [901176] Kingsoft Antivirus 'KisKrnl.sys' Driver Denial of Service Vulnerability
10848| [901169] Microsoft Windows Address Book Remote Code Execution Vulnerability (2423089)
10849| [901166] Microsoft Office Remote Code Execution Vulnerabilites (2423930)
10850| [901163] Microsoft Windows Media Player Remote Code Execution Vulnerability (2378111))
10851| [901162] Microsoft Internet Explorer Multiple Vulnerabilities (2360131)
10852| [901161] Microsoft ASP.NET Information Disclosure Vulnerability (2418042)
10853| [901142] FreeType Multiple denial of service vulnerabilities (Windows)
10854| [901140] Microsoft Windows SMB Code Execution and DoS Vulnerabilities (982214)
10855| [901139] Microsoft Internet Explorer Multiple Vulnerabilities (2183461)
10856| [901137] Pidgin 'X-Status' Message Denial of Service Vulnerability (Win)
10857| [901136] OpenTTD 'NetworkSyncCommandQueue()' Denial of Service Vulnerability
10858| [901132] SasCAM Request Processing Denial of Service Vulnerability
10859| [901124] SolarWinds TFTP Server Write Request Denial Of Service Vulnerability
10860| [901120] Microsoft IIS Authentication Remote Code Execution Vulnerability (982666)
10861| [901119] Microsoft Windows OpenType Compact Font Format Driver Privilege Escalation Vulnerability (980218)
10862| [901104] Tembria Server Monitor HTTP Request Denial of Service Vulnerability
10863| [901103] Memcached Denial of service vulnerability
10864| [901097] Microsoft Internet Explorer Multiple Vulnerabilities (978207)
10865| [901095] Microsoft Embedded OpenType Font Engine Remote Code Execution Vulnerabilities (972270)
10866| [901081] IBM DB2 db2pd Denial Of Service Vulnerability (Linux)
10867| [901080] IBM DB2 db2pd Denial Of Service Vulnerability (Win)
10868| [901069] Microsoft Office Project Remote Code Execution Vulnerability (967183)
10869| [901065] Microsoft Windows IAS Remote Code Execution Vulnerability (974318)
10870| [901064] Microsoft Windows ADFS Remote Code Execution Vulnerability (971726)
10871| [901057] UseBB BBcode Parsing Remote Denial Of Service Vulnerability
10872| [901055] Sun VirtualBox or xVM VirtualBox Denial Of Service Vulnerability (Linux)
10873| [901054] Sun VirtualBox or xVM VirtualBox Denial Of Service Vulnerability (Win)
10874| [901043] SystemTap Unprivileged Mode Multiple Denial Of Service Vulnerabilities
10875| [901041] Microsoft Internet Explorer Multiple Code Execution Vulnerabilities (974455)
10876| [901033] Wireshark Multiple Denial of Service Vulnerabilities (Linux)
10877| [901031] Wireshark Multiple Denial of Service Vulnerabilities (Win)
10878| [901030] Wireshark OpcUa Dissector Denial of Service Vulnerability (Win)
10879| [901012] Microsoft Windows Media Format Remote Code Execution Vulnerability (973812)
10880| [900993] PHP 'unserialize()' Function Denial of Service Vulnerability
10881| [900989] Wireshark Daintree SNA File Parser Denial of Service Vulnerability (Linux)
10882| [900988] Wireshark IPMI Dissector Denial of Service Vulnerability (Win)
10883| [900977] COWON Media Center JetAudio .wav File Denial Of Service Vulnerability
10884| [900973] Microsoft Office Word Remote Code Execution Vulnerability (976307)
10885| [900965] Microsoft Windows SMB2 Negotiation Protocol Remote Code Execution Vulnerability
10886| [900964] Microsoft .NET Common Language Runtime Code Execution Vulnerability (974378)
10887| [900963] Microsoft Windows Kernel Privilege Escalation Vulnerability (971486)
10888| [900957] Microsoft Windows Patterns & Practices EntLib DOS Vulnerability
10889| [900956] Microsoft Windows Patterns & Practices EntLib Version Detection
10890| [900944] Microsoft IIS FTP Server 'ls' Command DOS Vulnerability
10891| [900940] Pidgin Multiple Denial Of Service Vulnerabilities (Win)
10892| [900929] Microsoft JScript Scripting Engine Remote Code Execution Vulnerability (971961)
10893| [900925] PHP dba_replace Denial of Service Vulnerability
10894| [900922] TheGreenBow IPSec VPN Client Denial Of Service Vulnerability
10895| [900919] Pidgin MSN SLP Packets Denial Of Service Vulnerability (Win)
10896| [900908] Microsoft Windows Message Queuing Privilege Escalation Vulnerability (971032)
10897| [900907] Microsoft Windows AVI Media File Parsing Vulnerabilities (971557)
10898| [900903] KDE Konqueror Select Object Denial of Service Vulnerability
10899| [900898] Microsoft Internet Explorer 'XSS Filter' XSS Vulnerabilities - Nov09
10900| [900897] Microsoft Internet Explorer PDF Information Disclosure Vulnerability - Nov09
10901| [900887] Microsoft Office Excel Multiple Vulnerabilities (972652)
10902| [900886] Microsoft Windows Kernel-Mode Drivers Multiple Vulnerabilities (969947)
10903| [900880] Microsoft Windows ATL COM Initialization Code Execution Vulnerability (973525)
10904| [900879] Microsoft Windows Media Player ASF Heap Overflow Vulnerability (974112)
10905| [900878] Microsoft Products GDI Plus Code Execution Vulnerabilities (957488)
10906| [900876] Microsoft Windows CryptoAPI X.509 Spoofing Vulnerabilities (974571)
10907| [900873] Microsoft Windows DNS Devolution Third-Level Domain Name Resolving Weakness (971888)
10908| [900872] PHP 'tsrm_win32.c' Denial Of Service Vulnerability (Win)
10909| [900866] Mozilla Firefox 'window.print()' Denial Of Service Vulnerability (Linux)
10910| [900865] Mozilla Firefox 'window.print()' Denial Of Service Vulnerability (Win)
10911| [900864] Internet Explorer 'KEYGEN' Element Denial Of Service Vulnerability
10912| [900863] Microsoft Internet Explorer 'window.print()' DOS Vulnerability
10913| [900862] Google Chrome 'KEYGEN' Element Denial Of Service Vulnerability
10914| [900859] Google Chrome Denial Of Service Vulnerability - Sep09
10915| [900856] FreeRADIUS Tunnel-Password Denial Of Service Vulnerability
10916| [900850] Mozilla Firefox Denial Of Service Vulnerability - Sep09 (Linux)
10917| [900848] Mozilla Firefox Multiple Denial Of Service Vulnerabilities - Sep09 (Linux)
10918| [900846] Mozilla Firefox Denial Of Service Vulnerability - Sep09 (Win)
10919| [900844] Mozilla Firefox Multiple Denial Of Service Vulnerabilities - Sep09 (Win)
10920| [900841] Apache 'mod_proxy_ftp' Module Denial Of Service Vulnerability (Linux)
10921| [900838] Microsoft Windows TCP/IP Remote Code Execution Vulnerability (967723)
10922| [900837] Microsoft DHTML Editing Component ActiveX Remote Code Execution Vulnerability (956844)
10923| [900836] Microsoft Internet Explorer Address Bar Spoofing Vulnerability
10924| [900834] Asterisk SIP Channel Driver Denial Of Service Vulnerability (Linux)
10925| [900833] Google Chrome 'chromehtml: URI' Denial Of Service Vulnerability
10926| [900831] Mozilla Firefox 'document.location' Denial Of Service Vulnerability
10927| [900828] Neon Certificate Spoofing and Denial of Service Vulnerability
10928| [900826] Microsoft Internet Explorer 'location.hash' DOS Vulnerability
10929| [900825] Google Chrome 'tooltip_manager.cc' Denial Of Service Vulnerability
10930| [900824] Google Chrome 'location.hash' Denial Of Service Vulnerability
10931| [900814] Microsoft Windows WINS Remote Code Execution Vulnerability (969883)
10932| [900813] Microsoft Remote Desktop Connection Remote Code Execution Vulnerability (969706)
10933| [900812] Asterisk RTP Text Frames Denial Of Service Vulnerability
10934| [900809] Microsoft Visual Studio ATL Remote Code Execution Vulnerability (969706)
10935| [900808] Microsoft Visual Products Version Detection
10936| [900805] Google Chrome Unicode String Denial Of Service Vulnerability
10937| [900804] Opera Unicode String Denial Of Service Vulnerability (Linux)
10938| [900803] Opera Unicode String Denial Of Service Vulnerability (Win)
10939| [900757] Microsoft Windows Media Player '.AVI' File DOS Vulnerability
10940| [900741] Microsoft Internet Explorer Information Disclosure Vulnerability Feb10
10941| [900740] Microsoft Windows Kernel Could Allow Elevation of Privilege (977165)
10942| [900711] Microsoft IIS WebDAV Remote Authentication Bypass Vulnerability
10943| [900690] Microsoft Virtual PC/Server Privilege Escalation Vulnerability (969856)
10944| [900689] Microsoft Embedded OpenType Font Engine Remote Code Execution Vulnerabilities (961371))
10945| [900683] Foxit Reader Multiple Denial of Service Vulnerabilities - Jun09
10946| [900682] GUPnP Message Handling Denial Of Service Vulnerability
10947| [900670] Microsoft Office Excel Remote Code Execution Vulnerabilities (969462)
10948| [900648] PumpKIN TFTP Server Denial of Service Vulnerability
10949| [900634] Trend Micro OfficeScan Client Denial Of Service Vulnerability
10950| [900594] Wireshark AFS Dissector Denial of Service Vulnerability (Win)
10951| [900593] Wireshark Infiniband Dissector Denial of Service Vulnerability (Linux)
10952| [900592] Wireshark Infiniband Dissector Denial of Service Vulnerability (Win)
10953| [900589] Microsoft ISA Server Privilege Escalation Vulnerability (970953)
10954| [900588] Microsoft DirectShow Remote Code Execution Vulnerability (961373)
10955| [900580] VicFTPS LIST Command Denial of Service Vulnerability
10956| [900573] Apache APR-Utils XML Parser Denial of Service Vulnerability
10957| [900572] Apache APR-Utils Multiple Denial of Service Vulnerabilities
10958| [900570] Ruby BigDecimal Library Denial of Service Vulnerability (Linux)
10959| [900568] Microsoft Windows Search Script Execution Vulnerability (963093)
10960| [900567] Microsoft IIS Security Bypass Vulnerability (970483)
10961| [900566] Microsoft Active Directory LDAP Remote Code Execution Vulnerability (969805)
10962| [900559] Wireshark PCNFSD Dissector Denial of Service Vulnerability (Win)
10963| [900546] ClamAV Denial of Service Vulnerability (Win)
10964| [900545] ClamAV Denial of Service Vulnerability (Linux)
10965| [900538] mpg123 Player Denial of Service Vulnerability (Linux)
10966| [900511] RaidenFTPD Server CWD and MLST Command Denial of Service Vulnerability
10967| [900480] PostgreSQL Denial of Service Vulnerability (Linux)
10968| [900476] Microsoft Excel Remote Code Execution Vulnerabilities (968557)
10969| [900465] Microsoft Windows DNS Memory Corruption Vulnerability - Mar09
10970| [900463] NoticeWare Mail Server Denial of Service Vulnerability
10971| [900450] WinFTP Server PASV Command Denial of Service Vulnerability
10972| [900445] Microsoft Autorun Arbitrary Code Execution Vulnerability (08-038)
10973| [900443] MikMod Module Player Denial of Service Vulnerability (Linux)
10974| [900417] Konqueror in KDE Denial of Service Vulnerability
10975| [900415] Avahi Denial of Service Vulnerability
10976| [900413] MailScanner Infinite Loop Denial of Service Vulnerability
10977| [900404] Microsoft Windows RTCP Unspecified Remote DoS Vulnerability
10978| [900400] Microsoft Internet Explorer Unicode String DoS Vulnerability
10979| [900395] Netscape 'select()' Object Denial Of Service Vulnerability (Linux)
10980| [900393] Netscape 'select()' Object Denial Of Service Vulnerability (Win)
10981| [900391] Microsoft Office Publisher Remote Code Execution Vulnerability (969516)
10982| [900386] StrongSwan/Openswan Denial Of Service Vulnerability June-09
10983| [900366] Microsoft Internet Explorer Web Script Execution Vulnerabilites
10984| [900365] Microsoft Office Word Remote Code Execution Vulnerabilities (969514)
10985| [900336] Microsoft Windows Media Player MID File Integer Overflow Vulnerability
10986| [900328] Microsoft Internet Explorer Remote Code Execution Vulnerability (963027)
10987| [900303] Microsoft Internet Explorer HTML Form Value DoS Vulnerability
10988| [900299] Microsoft Report Viewer Information Disclosure Vulnerability (2578230)
10989| [900298] MS Windows Remote Access Service NDISTAPI Driver Privilege Elevation Vulnerability (2566454)
10990| [900295] Microsoft Windows DNS Server Remote Code Execution Vulnerability (2562485)
10991| [900294] Microsoft Data Access Components Remote Code Execution Vulnerabilities (2560656)
10992| [900291] HP Data Protector Manager RDS Service Denial of Service Vulnerability
10993| [900289] Active Directory Certificate Services Web Enrollment Elevation of Privilege Vulnerability (2518295)
10994| [900288] Microsoft Distributed File System Remote Code Execution Vulnerabilities (2535512)
10995| [900287] Microsoft SMB Client Remote Code Execution Vulnerabilities (2536276)
10996| [900285] Microsoft Foundation Class (MFC) Library Remote Code Execution Vulnerability (2500212)
10997| [900282] Microsoft DNS Resolution Remote Code Execution Vulnerability (2509553)
10998| [900281] Microsoft IE Developer Tools WMITools and Windows Messenger ActiveX Control Vulnerability (2508272)
10999| [900280] Microsoft Windows SMB Server Remote Code Execution Vulnerability (2508429)
11000| [900279] Microsoft SMB Client Remote Code Execution Vulnerabilities (2511455)
11001| [900278] Microsoft Internet Explorer Multiple Vulnerabilities (2497640)
11002| [900276] IGSS ODBC Server Multiple Uninitialized Pointer Denial of Service Vulnerability
11003| [900274] SpoonFTP 'RETR' Command Remote Denial of Service Vulnerability
11004| [900273] Microsoft Remote Desktop Client Remote Code Execution Vulnerability (2508062)
11005| [900272] ActFax LPD/LPR Server Denial of Service Vulnerability
11006| [900271] ActFax FTP Server Post Auth 'RETR' Command Denial of Service Vulnerability
11007| [900270] Objectivity/DB Lock Server Denial of Service Vulnerability
11008| [900269] Objectivity/DB Advanced Multithreaded Server Denial of Service Vulnerability
11009| [900268] Mongoose Webserver Content-Length Denial of Service Vulnerability
11010| [900267] Microsoft Media Decompression Remote Code Execution Vulnerability (2447961)
11011| [900266] Microsoft Windows Movie Maker Could Allow Remote Code Execution Vulnerability (2424434)
11012| [900263] Microsoft Windows OpenType Compact Font Format Driver Privilege Escalation Vulnerability (2296199)
11013| [900262] Microsoft Internet Explorer Multiple Vulnerabilities (2416400)
11014| [900261] Microsoft Office PowerPoint Remote Code Execution Vulnerabilities (2293386)
11015| [900248] Microsoft Windows Movie Maker Could Allow Remote Code Execution Vulnerability (981997)
11016| [900246] Microsoft Media Decompression Remote Code Execution Vulnerability (979902)
11017| [900245] Microsoft Data Analyzer and IE Developer Tools ActiveX Control Vulnerability (980195)
11018| [900241] Microsoft Outlook Express and Windows Mail Remote Code Execution Vulnerability (978542)
11019| [900237] Microsoft Windows Authentication Verification Remote Code Execution Vulnerability (981210)
11020| [900236] Microsoft Windows Kernel Could Allow Elevation of Privilege (979683)
11021| [900235] Microsoft Windows Media Player Could Allow Remote Code Execution (979402)
11022| [900232] Microsoft Windows Movie Maker Could Allow Remote Code Execution Vulnerability (975561)
11023| [900230] Microsoft Windows SMB Server Multiple Vulnerabilities (971468)
11024| [900229] Microsoft Data Analyzer ActiveX Control Vulnerability (978262)
11025| [900228] Microsoft Office (MSO) Remote Code Execution Vulnerability (978214)
11026| [900227] Microsoft Windows Shell Handler Could Allow Remote Code Execution Vulnerability (975713)
11027| [900223] Microsoft Ancillary Function Driver Elevation of Privilege Vulnerability (956803)
11028| [900211] HP OpenView Network Node Manager Denial of Service Vulnerabilities
11029| [900192] Microsoft Internet Explorer Information Disclosure Vulnerability
11030| [900187] Microsoft Internet Explorer Argument Injection Vulnerability
11031| [900178] Microsoft Windows 'UnhookWindowsHookEx' Local DoS Vulnerability
11032| [900173] Microsoft Windows Media Player Version Detection
11033| [900172] Microsoft Windows Media Player 'MIDI' or 'DAT' File DoS Vulnerability
11034| [900170] Microsoft iExplorer '&NBSP
11035| [900127] Personal FTP Server RETR Command Remote Denial of Service Vulnerability
11036| [900125] Microsoft SQL Server 2000 sqlvdir.dll ActiveX Buffer Overflow Vulnerability
11037| [900120] Microsoft Organization Chart Remote Code Execution Vulnerability
11038| [900119] Softalk Mail Server IMAP Denial of Service Vulnerability
11039| [900117] ClamAV Invalid Memory Access Denial Of Service Vulnerability
11040| [900113] RhinoSoft Serv-U SFTP Remote Denial of Service Vulnerability
11041| [900109] hMailServer IMAP Denial of Service Vulnerability
11042| [900108] Microsoft Windows NSlookup.exe Remote Code Execution Vulnerability
11043| [900104] MailEnable IMAP Denial of Service Vulnerability
11044| [900097] Vulnerability in Microsoft DirectShow Could Allow Remote Code Execution
11045| [900095] Microsoft ISA Server and Forefront Threat Management Gateway DoS Vulnerability (961759)
11046| [900093] Microsoft DirectShow Remote Code Execution Vulnerability (961373)
11047| [900092] Windows HTTP Services Could Allow Remote Code Execution Vulnerabilities (960803)
11048| [900080] Vulnerabilities in Microsoft Office Visio Could Allow Remote Code Execution (957634)
11049| [900079] Vulnerabilities in Microsoft Exchange Could Allow Remote Code Execution (959239)
11050| [900077] OpenOffice Denial of Service Vulnerability (Win)
11051| [900076] OpenOffice Denial of Service Vulnerability (Linux)
11052| [900064] Vulnerability in Microsoft Office SharePoint Server Could Cause Elevation of Privilege (957175)
11053| [900063] Vulnerabilities in Microsoft Office Word Could Allow Remote Code Execution (957173)
11054| [900061] Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (959070)
11055| [900056] Vulnerability in Server Service Could Allow Remote Code Execution (958644)
11056| [900055] Server Service Could Allow Remote Code Execution Vulnerability (958644)
11057| [900052] Windows Internet Printing Service Allow Remote Code Execution Vulnerability (953155)
11058| [900049] Host Integration Server RPC Service Remote Code Execution Vulnerability (956695)
11059| [900048] Microsoft Excel Remote Code Execution Vulnerability (956416)
11060| [900047] Microsoft Office nformation Disclosure Vulnerability (957699)
11061| [900046] Microsoft Office Remote Code Execution Vulnerabilities (955047)
11062| [900033] Microsoft PowerPoint Could Allow Remote Code Execution Vulnerabilities (949785)
11063| [900029] Microsoft Office Filters Could Allow Remote Code Execution Vulnerabilities (924090)
11064| [900028] Microsoft Excel Could Allow Remote Code Execution Vulnerabilities (954066)
11065| [900025] Microsoft Office Version Detection
11066| [900017] AVG Anti-Virus UPX Processing Denial of Service Vulnerability
11067| [900006] Microsoft Word Could Allow Remote Code Execution Vulnerability
11068| [900004] Microsoft Access Snapshot Viewer ActiveX Control Vulnerability
11069| [864524] Fedora Update for accountsservice FEDORA-2012-10120
11070| [861438] Fedora Update for Terminal FEDORA-2007-1620
11071| [861265] Fedora Update for Terminal FEDORA-2007-4385
11072| [861044] Fedora Update for Terminal FEDORA-2007-4368
11073| [855802] Solaris Update for Native LDAP, PAM, name-service-switch 138874-05
11074| [855724] Solaris Update for Native LDAP, PAM, name-service-switch 138875-05
11075| [855605] Solaris Update for Federated Naming Service (FNS) X500 116997-01
11076| [855343] Solaris Update for Federated Naming Service (FNS) X500 116998-01
11077| [855043] Solaris Update for vgatext and terminal-emulator 109155-01
11078| [841208] Ubuntu Update for remote-login-service USN-1624-1
11079| [841066] Ubuntu Update for accountsservice USN-1485-1
11080| [840946] Ubuntu Update for accountsservice USN-1351-1
11081| [840094] Ubuntu Update for xfce4-terminal vulnerability USN-497-1
11082| [835127] HP-UX Update for MC/ServiceGuard HPSBUX00129
11083| [835108] HP-UX Update for HP WEBM Services HPSBUX00288
11084| [830221] Mandriva Update for gnome-terminal MDKA-2007:016 (gnome-terminal)
11085| [803104] Oracle VM VirtualBox Unspecified Denial of Service Vulnerability (Mac OS X)
11086| [803103] Oracle VM VirtualBox Unspecified Denial of Service Vulnerability (Windows)
11087| [803091] OpenBSD Portmap Remote Denial of Service Vulnerability
11088| [803065] LibreOffice Import Files Denial of Service Vulnerabilities (Mac OS X)
11089| [803064] LibreOffice Import Files Denial of Service Vulnerabilities (Windows)
11090| [803037] Optima PLC APIFTP Server Denial of Service Vulnerabilities
11091| [803028] Microsoft Internet Explorer Remote Code Execution Vulnerability (2757760)
11092| [803007] Microsoft Windows Minimum Certificate Key Length Spoofing Vulnerability (2661254)
11093| [803000] Citrix Provisioning Services SoapServer Buffer Overflow Vulnerability
11094| [802996] Mozilla Firefox 'WebSockets' Denial of Service Vulnerability (Windows)
11095| [802993] Mozilla Firefox 'WebSockets' Denial of Service Vulnerability (Mac OS X)
11096| [802921] VLC Media Player 'MP4' Denial of Service Vulnerability (Mac OS X)
11097| [802920] VLC Media Player 'MP4' Denial of Service Vulnerability (Windows)
11098| [802914] MailEnable SMTP HELO Command Denial of Service Vulnerability
11099| [802913] freeFTPD PORT Command Denial of Service Vulnerability
11100| [802912] Microsoft Unauthorized Digital Certificates Spoofing Vulnerability (2728973)
11101| [802908] Wireshark Multiple Denial of Service Vulnerabilities - July 12 (Mac OS X)
11102| [802907] Wireshark Multiple Denial of Service Vulnerabilities - July 12 (Windows)
11103| [802906] Pidgin MSN and XMPP Denial of Service Vulnerabilities (Windows)
11104| [802905] PowerNet Twin Client 'RFSynC' Denial of Service Vulnerability
11105| [802902] Wireshark Denial of Service Vulnerability-02 March 11 (Mac OS X)
11106| [802900] Wireshark Denial of Service Vulnerability March-11 (Mac OS X)
11107| [802899] Wireshark PPP And NFS Dissector Denial of Service Vulnerabilities (Mac OS X)
11108| [802898] Wireshark PPP And NFS Dissector Denial of Service Vulnerabilities (Windows)
11109| [802886] Microsoft Sidebar and Gadgets Remote Code Execution Vulnerability (2719662)
11110| [802877] Wireshark 'bytes_repr_len' Denial of Service Vulnerability (Mac OS X)
11111| [802870] Mozilla Products 'jsinfer.cpp' Denial of Service Vulnerability (Mac OS X)
11112| [802869] Mozilla Products 'jsinfer.cpp' Denial of Service Vulnerability (Windows)
11113| [802867] Mozilla Products Updater Service Privilege Escalation Vulnerabilities (Win)
11114| [802850] Google Chrome Multiple Denial of Service Vulnerabilities - May 12 (Mac OS X)
11115| [802849] Google Chrome Multiple Denial of Service Vulnerabilities - May 12 (Linux)
11116| [802848] Google Chrome Multiple Denial of Service Vulnerabilities - May 12 (Windows)
11117| [802846] Wireshark ZigBee ZCL Dissector Denial of Service Vulnerability (Mac OS X)
11118| [802844] Wireshark Lucent/Ascend File Parser Denial of Service Vulnerability (Mac OS X)
11119| [802831] EMC NetWorker 'nsrexecd' RPC Packet Denial of Service Vulnerability
11120| [802829] Opera Large Integer Argument Denial of Service Vulnerability (Linux)
11121| [802827] EMC Data Protection Advisor NULL Pointer Dereference Denial of Service Vulnerability
11122| [802826] RealNetworks RealPlayer MP4 File Handling Denial of Service Vulnerability (Win)
11123| [802825] Jabber Studio Jabberd Server SASL Negotiation Denial of Service Vulnerability
11124| [802809] Google Chrome Multiple Denial of Service Vulnerabilities - March12 (Mac OS X)
11125| [802808] Google Chrome Multiple Denial of Service Vulnerabilities - March12 (Linux)
11126| [802807] Google Chrome Multiple Denial of Service Vulnerabilities - March12 (Windows)
11127| [802806] Microsoft IIS Default Welcome Page Information Disclosure Vulnerability
11128| [802799] Wireshark Denial of Service Vulnerability-01 March 11 (Mac OS X)
11129| [802774] Microsoft VPN ActiveX Control Remote Code Execution Vulnerability (2695962)
11130| [802768] Wireshark CSN.1 Dissector Denial of Service Vulnerability (Mac OS X)
11131| [802767] Wireshark Heap Based BOF and Denial of Service Vulnerabilities (Mac OS X)
11132| [802766] Wireshark ANSI A MAP Files Denial of Service Vulnerability (Mac OS X)
11133| [802765] Wireshark IEEE 802.11 Dissector Denial of Service Vulnerability (Mac OS X)
11134| [802763] Wireshark Multiple Denial of Service Vulnerabilities (Mac OS X)
11135| [802760] Wireshark IEEE 802.11 Dissector Denial of Service Vulnerability (Windows)
11136| [802759] Wireshark Multiple Denial of Service Vulnerabilities - April 12 (Windows)
11137| [802757] Opera Browser 'SRC' Denial of Service Vulnerability (Mac OS X)
11138| [802754] Opera Web Browser Select Object Denial Of Service Vulnerability (Mac OS X)
11139| [802742] Opera Browser 'SRC' Denial of Service Vulnerability (Linux)
11140| [802726] Microsoft SMB Signing Disabled
11141| [802713] Pidgin Multiple Denial of Service Vulnerabilities (Windows)
11142| [802708] Microsoft Internet Explorer Code Execution and DoS Vulnerabilities
11143| [802685] IBM RBD Web Services Information Disclosure Vulnerability (Win)
11144| [802677] CA ARCserve Backup RPC Services Multiple Vulnerabilities (Windows)
11145| [802665] Wireshark ASN.1 BER Dissector Denial of Service Vulnerability (Mac OS X)
11146| [802651] Opera Multiple Denial of Service Vulnerabilities - June12 (Linux)
11147| [802650] Opera Multiple Denial of Service Vulnerabilities - June12 (Mac OS X)
11148| [802649] Opera Multiple Denial of Service Vulnerabilities - June12 (Windows)
11149| [802635] xArrow Multiple Denial of Service Vulnerabilities
11150| [802634] Microsoft Windows Unauthorized Digital Certificates Spoofing Vulnerability (2718704)
11151| [802627] LAN Messenger Malformed Initiation Request Remote Denial of Service Vulnerability
11152| [802626] Wireshark Code Execution and Denial of Service Vulnerabilities (Mac OS X)
11153| [802625] Wireshark Multiple Denial of Service Vulnerabilities (Mac OS X)
11154| [802617] NetDecision HTTP Server Long HTTP Request Remote Denial of Service Vulnerability
11155| [802614] Tiny HTTP Server Remote Denial of Service Vulnerability
11156| [802613] Core FTP Server 'Type' Command Remote Denial of Service Vulnerability
11157| [802605] TYPSoft FTP Server Multiple Commands Remote Denial of Service Vulnerabilities
11158| [802566] PHP Multiple Denial of Service Vulnerabilities (Windows)
11159| [802557] LibreOffice 'DOC' File Denial of Service Vulnerability (Windows)
11160| [802539] Oracle Database Server 'RDBMS' component Denial of Service Vulnerability
11161| [802523] Oracle Database Server MDSYS.MD Buffer Overflows and Denial of Service Vulnerabilities
11162| [802510] Mozilla Products Browser Engine Denial of Service Vulnerabilities (Windows)
11163| [802506] Investintech Products Denial of Service Vulnerabilities
11164| [802503] Wireshark CSN.1 Dissector Denial of Service Vulnerability (Windows)
11165| [802502] Wireshark Heap Based BOF and Denial of Service Vulnerabilities (Windows)
11166| [802500] Microsoft Windows TrueType Font Parsing Privilege Elevation Vulnerability
11167| [802489] VLC Media Player 'libpng_plugin' Denial of Service Vulnerability (Mac OS X)
11168| [802488] VLC Media Player 'libpng_plugin' Denial of Service Vulnerability (Windows)
11169| [802468] Compatibility Issues Affecting Signed Microsoft Binaries (2749655)
11170| [802426] Microsoft Windows ActiveX Control Multiple Vulnerabilities (2647518)
11171| [802420] VLC Media Player '.amr' File Denial of Service Vulnerability (Windows)
11172| [802409] Oracle GlassFish Server Hash Collision Denial of Service Vulnerability
11173| [802408] PHP Web Form Hash Collision Denial of Service Vulnerability (Win)
11174| [802406] Hillstone Software TFTP Write/Read Request Server Denial Of Service Vulnerability
11175| [802396] Opera Large Integer Argument Denial of Service Vulnerability (Mac OS X)
11176| [802395] Opera Large Integer Argument Denial of Service Vulnerability (Windows)
11177| [802386] HP Diagnostics Server 'magentservice.exe' Buffer Overflow Vulnerability
11178| [802384] Apache Tomcat Parameter Handling Denial of Service Vulnerability (Win)
11179| [802383] Microsoft Windows Color Control Panel Privilege Escalation Vulnerability
11180| [802382] Wibu-Systems CodeMeter Runtime TCP Packets Denial of Service Vulnerability
11181| [802379] Microsoft Windows Kernel 'win32k.sys' Memory Corruption Vulnerability
11182| [802378] Apache Tomcat Hash Collision Denial Of Service Vulnerability
11183| [802376] Google Chrome Multiple Denial of Service Vulnerabilities - January12 (Mac OS X)
11184| [802375] Google Chrome Multiple Denial of Service Vulnerabilities - January12 (Linux)
11185| [802374] Google Chrome Multiple Denial of Service Vulnerabilities - January12 (Windows)
11186| [802372] WinMount 'WMDrive.sys' Driver IOCTL Handling Denial of Service Vulnerability
11187| [802370] TomatoSoft Free Mp3 Player '.mp3' File Denial of Service Vulnerability
11188| [802349] PHP EXIF Header Denial of Service Vulnerability (Windows)
11189| [802340] EtherApe RPC Packet Processing Denial of Service Vulnerability
11190| [802339] Google Chrome Mozilla Network Security Services Privilege Escalation Vulnerability (Mac OS X)
11191| [802338] Google Chrome Mozilla Network Security Services Privilege Escalation Vulnerability (Windows)
11192| [802331] Pidgin Libpurple Protocol Plugins Denial of Service Vulnerabilities (Win)
11193| [802308] Wireshark Lucent/Ascend File Parser Denial of Service Vulnerability (Win)
11194| [802300] Tor Directory Authority 'policy_summarize' Denial of Service Vulnerability (Windows)
11195| [802295] Linux Kernel IGMP Remote Denial of Service Vulnerability
11196| [802287] Microsoft Internet Explorer Cache Objects History Information Disclosure Vulnerability
11197| [802286] Microsoft Internet Explorer Multiple Information Disclosure Vulnerabilities
11198| [802260] Microsoft Windows WINS Remote Code Execution Vulnerability (2524426)
11199| [802248] Wireshark Multiple Denial of Service Vulnerabilities (Windows)
11200| [802236] Finger Service Remote Information Disclosure Vulnerability
11201| [802232] CiscoKits CCNA TFTP Server 'Write' Command Denial Of Service Vulnerability
11202| [802231] Finger Redirection Remote Denial of Service Vulnerability
11203| [802223] Shibboleth XML Security Signature Key Parsing Denial of Service Vulnerability (Win)
11204| [802221] Citrix Provisioning Services 'streamprocess.exe' Component Remote Code Execution Vulnerability
11205| [802214] Mozilla Products Multiple Denial of Service Vulnerabilities July-11 (Windows)
11206| [802203] Microsoft Internet Explorer Cookie Hijacking Vulnerability
11207| [802202] Microsoft Internet Explorer Cookie Hijacking Vulnerability
11208| [802201] Wireshark 'bytes_repr_len' Function Denial of Service Vulnerability (Windows)
11209| [802200] Wireshark Multiple Denial of Service Vulnerabilities (Windows)
11210| [802198] Apple QuickTime Multiple Denial of Service Vulnerabilities - (Windows)
11211| [802163] Calendar Manager Service rpc.cmsd Service Detection
11212| [802140] Microsoft Explorer HTTPS Sessions Multiple Vulnerabilities (Windows)
11213| [802137] Nfs-utils rpc.rquotad Service Detection
11214| [802136] Microsoft Windows Insecure Library Loading Vulnerability (2269637)
11215| [802129] AzeoTech DAQFactory Denial of Service Vulnerability
11216| [802119] VLC Media Player 'AMV' Denial of Service Vulnerability (Windows)
11217| [802118] VLC Media Player 'AMV' Denial of Service Vulnerability (Linux)
11218| [802113] Opera Browser 'SRC' Denial of Service Vulnerability (Windows)
11219| [802044] Lighttpd Connection header Denial of Service Vulnerability
11220| [802036] Beckhoff TwinCAT 'TCATSysSrv.exe' Network Packet Denial of Service Vulnerability
11221| [802020] Serva32 web server Denial of Service Vulnerability
11222| [802012] Rumble SMTP Server 'MAIL FROM' Command Denial of Service Vulnerability
11223| [802011] Avaya IP Office Manager TFTP Denial of Service Vulnerability
11224| [802007] Hiawatha WebServer 'Content-Length' Denial of Service Vulnerability
11225| [802003] Quick 'n Easy FTP Login Denial of Service Vulnerability
11226| [802002] SolarFTP PASV Command Remote Denial of Service Vulnerability
11227| [802001] SolarFTP USER Command Remote Denial of Service Vulnerability
11228| [801991] Microsoft Windows SMB/NETBIOS NULL Session Authentication Bypass Vulnerability
11229| [801984] ManageEngine ServiceDesk Plus Authentication Bypass Vulnerability
11230| [801983] ManageEngine ServiceDesk Plus 'searchText' XSS Vulnerability
11231| [801968] Adobe Flash Media Server Remote Denial of Service Vulnerability (August-2011)
11232| [801966] Microsoft Windows ActiveX Control Multiple Vulnerabilities (2562937)
11233| [801963] HP Data Protector Media Management Daemon Denial of Service Vulnerability
11234| [801962] ManageEngine ServiceDesk Plus Multiple XSS Vulnerabilities
11235| [801943] Lost Door J-Revolution Denial of Service Vulnerability
11236| [801937] IBM solidDB RPC Test Commands Denial of Service Vulnerabilities
11237| [801935] Microsoft Silverlight Multiple Memory Leak Vulnerabilities
11238| [801934] Microsoft Silverlight Version Detection
11239| [801914] Microsoft Windows IPv4 Default Configuration Security Bypass Vulnerability
11240| [801892] Adobe Flash Media Server XML Data Remote Denial of Service Vulnerability
11241| [801891] Google Chrome Multiple Denial of Service Vulnerabilities - May11 (Linux)
11242| [801890] Google Chrome Multiple Denial of Service Vulnerabilities - May11 (Windows)
11243| [801876] Microsoft Internet Explorer 'msxml.dll' Information Disclosure Vulnerability
11244| [801860] PHP 'grapheme_extract()' NULL Pointer Dereference Denial Of Service Vulnerability
11245| [801854] Citrix Licensing Administration Console Security Bypass And Denial Of Service Vulnerabilities
11246| [801833] Wireshark ASN.1 BER Dissector Denial of Service Vulnerability (Win)
11247| [801831] Microsoft Internet Explorer Incorrect GUI Display Vulnerability
11248| [801830] Microsoft Internet Explorer 'ReleaseInterface()' Remote Code Execution Vulnerability
11249| [801824] IBM Tivoli Directory Proxy Server Denial of Service Vulnerability
11250| [801823] IBM Tivoli Directory Server LDAP BER Denial of Service Vulnerability
11251| [801809] IBM Tivoli Directory Server DIGEST-MD5 Denial of Service Vulnerability
11252| [801790] Perl Denial of Service Vulnerability (Windows)
11253| [801786] Wireshark Denial of Service and Buffer Overflow Vulnerabilities (Windows)
11254| [801785] Wireshark X.509if Dissector Denial of service vulnerability (Windows)
11255| [801772] Rsync Multiple Denial of Service Vulnerabilities (Windows)
11256| [801764] Pidgin Yahoo Protocol 'YMSG' NULL Pointer Dereference Denial of Service Vulnerability (Win)
11257| [801761] Wireshark Denial of Service Vulnerability March-11 (Windows)
11258| [801758] Wireshark Denial of Service Vulnerability March-11 (Windows)
11259| [801756] Wireshark Denial of Service Vulnerability - March-11 (Windows)
11260| [801748] Google Chrome Multiple Denial of Service Vulnerabilities - February 11(Linux)
11261| [801747] Google Chrome Multiple Denial of Service Vulnerabilities - February 11(Windows)
11262| [801742] Wireshark Denial of Service Vulnerability (Windows)
11263| [801725] Microsoft Products GDI Plus Remote Code Execution Vulnerabilities (954593)
11264| [801723] Vulnerability in Windows Services for UNIX Could Allow Elevation of Privilege (939778)
11265| [801719] Microsoft Windows CSRSS CSRFinalizeContext Local Privilege Escalation Vulnerability (930178)
11266| [801718] Microsoft Windows Vista Information Disclosure Vulnerability (931213)
11267| [801717] Microsoft Windows Vista Teredo Interface Firewall Bypass Vulnerability
11268| [801716] Microsoft Outlook Express/Windows Mail MHTML URI Handler Information Disclosure Vulnerability (929123)
11269| [801713] Microsoft Outlook Express And Windows Mail NNTP Protocol Heap Buffer Overflow Vulnerability (941202)
11270| [801712] Vulnerability in RPC Could Allow Denial of Service (933729)
11271| [801707] Microsoft Internet Explorer mshtml.dll Remote Memory Corruption Vulnerability (942615)
11272| [801706] Microsoft Windows TCP/IP Remote Code Execution Vulnerabilities (941644)
11273| [801702] Microsoft Internet Explorer HTML Rendering Remote Memory Corruption Vulnerability (944533)
11274| [801687] TYPSoft FTP Server RETR CMD Denial Of Service Vulnerability
11275| [801677] Microsoft WMI Administrative Tools ActiveX Control Remote Code Execution Vulnerabilities
11276| [801669] Microsoft Windows IIS FTP Server DOS Vulnerability
11277| [801640] ProFTPD Denial of Service Vulnerability
11278| [801638] Apple Safari libxml Denial of Service Vulnerability
11279| [801614] pyftpdlib FTP Server Denial of Service Vulnerability
11280| [801606] Microsoft Internet Explorer 'mshtml.dll' Information Disclosure Vulnerability
11281| [801598] Microsoft Windows2k3 Active Directory 'BROWSER ELECTION' Buffer Overflow Vulnerability
11282| [801597] Microsoft Office Excel 2003 Invalid Object Type Remote Code Execution Vulnerability
11283| [801596] Microsoft Excel 2007 Office Drawing Layer Remote Code Execution Vulnerability
11284| [801595] Microsoft Office Excel Axis and Art Object Parsing Remote Code Execution Vulnerabilities
11285| [801594] Microsoft PowerPoint 2007 OfficeArt Atom Remote Code Execution Vulnerability
11286| [801586] PHP Zend and GD Multiple Denial of Service Vulnerabilities
11287| [801583] PHP 'ext/imap/php_imap.c' Use After Free Denial of Service Vulnerability
11288| [801580] Microsoft Windows Fax Cover Page Editor BOF Vulnerabilities
11289| [801579] HP Data Protector Manager Remote Denial of Service Vulnerability
11290| [801554] Wireshark ZigBee ZCL Dissector Denial of Service Vulnerability (Win)
11291| [801536] Pidgin Libpurple 'purple_base64_decode()' Denial of Service Vulnerabilities (Win)
11292| [801531] IBM solidDB Packets Processing Denial of Service Vulnerabilities
11293| [801527] Microsoft Windows 32-bit Platforms Unspecified vulnerabilities
11294| [801521] Apache APR-util 'buckets/apr_brigade.c' Denial Of Service Vulnerability
11295| [801520] Microsoft IIS ASP Stack Based Buffer Overflow Vulnerability
11296| [801491] Microsoft 'hxvz.dll' ActiveX Control Memory Corruption Vulnerability (948881)
11297| [801489] Microsoft Office Graphics Filters Remote Code Execution Vulnerabilities (968095)
11298| [801488] Microsoft Internet Explorer Data Stream Handling Remote Code Execution Vulnerability (947864)
11299| [801487] Microsoft Windows Kernel Usermode Callback Local Privilege Elevation Vulnerability (941693)
11300| [801486] Microsoft Windows Speech Components Voice Recognition Command Execution Vulnerability (950760)
11301| [801484] Microsoft Windows IPsec Policy Processing Information Disclosure Vulnerability (953733)
11302| [801483] Microsoft Windows Search Remote Code Execution Vulnerability (959349)
11303| [801479] Microsoft Windows TCP/IP Could Allow Remote Code Execution (974145)
11304| [801457] Microsoft Windows Address Book Insecure Library Loading Vulnerability
11305| [801456] Microsoft Windows Progman Group Converter Insecure Library Loading Vulnerability
11306| [801440] Adersoft VbsEdit '.vbs' File Denial Of Service Vulnerability
11307| [801435] Wireshark 'IPMI dissector' Denial of Service Vulnerability (Win)
11308| [801433] Wireshark 'packet-gsm_a_rr.c' Denial of Service Vulnerability (Win)
11309| [801430] VLC Media Player Meta-Information Denial of Service Vulnerability (Linux)
11310| [801429] VLC Media Player Meta-Information Denial of Service Vulnerability (Windows)
11311| [801347] Mozilla Firefox 'IFRAME' Denial Of Service vulnerability (Windows)
11312| [801345] Microsoft .NET 'ASP.NET' Cross-Site Scripting vulnerability
11313| [801344] Microsoft .NET '__VIEWSTATE' Cross-Site Scripting vulnerability
11314| [801342] Microsoft ASP.NET Cross-Site Scripting vulnerability
11315| [801333] Microsoft Windows Kernel 'win32k.sys' Multiple DOS Vulnerabilities
11316| [801332] Apple Safari 'webkit' Denial Of Service Vulnerability
11317| [801330] Microsoft Internet Explorer Cross Site Data Leakage Vulnerability
11318| [801322] VMware Products USB Service Local Privilege Escalation Vulnerability (Win)
11319| [801305] Adobe Reader PDF Handling Denial Of Service Vulnerability (Linux)
11320| [801245] bozotic HTTP server Denial of Service Vulnerability
11321| [801235] Qt 'QSslSocketBackendPrivate::transmit()' Denial of Service Vulnerability
11322| [801222] Weborf 'Range' Header Denial of Service Vulnerability
11323| [801216] Opera 'IFRAME' Denial Of Service vulnerability (Windows)
11324| [801208] Wireshark DOCSIS Dissector Denial of Service Vulnerability (Win)
11325| [801148] Shibboleth Service Provider Multiple XSS Vulnerabilities (Win)
11326| [801141] Opera Denial Of Service Vulnerability - Nov09 (Linux)
11327| [801139] Snort 'IPv6' Packet Denial Of Service Vulnerability (Linux)
11328| [801135] Mozilla Firefox Denial Of Service Vulnerability Nov-09 (Linux)
11329| [801134] Mozilla Firefox Denial Of Service Vulnerability Nov-09 (Win)
11330| [801129] Gpg4Win Denial Of Service Vulnerability
11331| [801118] Rhino Software Serv-U 'SITE SET' Command Denial Of Service vulnerability
11332| [801116] Shibboleth Service Provider NULL Character Spoofing Vulnerability (Win)
11333| [801115] Shibboleth Service Provider Version Detection
11334| [801109] Microsoft IE CA SSL Certificate Security Bypass Vulnerability - Oct09
11335| [801104] Adobe Acrobat PDF File Denial Of Service Vulnerability
11336| [801090] Microsoft Windows Indeo Codec Multiple Vulnerabilities
11337| [801039] HTML-Parser 'decode_entities()' Denial of Service Vulnerability
11338| [801033] Wireshark Multiple Denial Of Service Vulnerability - Nov09 (Linux)
11339| [801032] Wireshark Multiple Denial Of Service Vulnerabilities - Nov09 (Win)
11340| [801030] Pidgin Oscar Protocol Denial of Service Vulnerability (Win)
11341| [801027] VMware Authorization Service Denial of Service Vulnerability (Win)
11342| [800963] ZoIPer Empty Call-Info Denial of Service Vulnerability
11343| [800922] Opera Web Browser Select Object Denial Of Service Vulnerability (Linux)
11344| [800921] Opera Web Browser Select Object Denial Of Service Vulnerability (Win)
11345| [800910] Microsoft Internet Explorer Buffer Overflow Vulnerability - Jul09
11346| [800902] Microsoft Internet Explorer XSS Vulnerability - July09
11347| [800872] Microsoft Internet Explorer 'li' Element DoS Vulnerability - Sep09
11348| [800866] Sun Java System Web Proxy Server Denial Of Service Vulnerability (Linux)
11349| [800865] Sun Java System Web Proxy Server Denial Of Service Vulnerability (Win)
11350| [800863] Microsoft Internet Explorer XML Document DoS Vulnerability - Aug09
11351| [800862] Microsoft Windows Kernel win32k.sys Privilege Escalation Vulnerability
11352| [800861] Microsoft Internet Explorer 'findText()' Unicode Parsing DoS Vulnerability
11353| [800852] Firebird SQL 'op_connect_request' Denial Of Service Vulnerability (Win)
11354| [800849] Mozilla Products 'select()' Denial Of Service Vulnerability (Linux)
11355| [800848] Mozilla Products 'select()' Denial Of Service Vulnerability (Win)
11356| [800845] Microsoft Office Web Components ActiveX Control Code Execution Vulnerability
11357| [800841] Tor Denial Of Service Vulnerability - July09 (Linux)
11358| [800839] Tor Denial Of Service Vulnerability - July09 (Win)
11359| [800837] Apache 'mod_deflate' Denial Of Service Vulnerability - July09
11360| [800829] Microsoft Video ActiveX Control 'msvidctl.dll' BOF Vulnerability
11361| [800827] Apache 'mod_proxy_http.c' Denial Of Service Vulnerability
11362| [800823] Pidgin OSCAR Protocol Denial Of Service Vulnerability (Win)
11363| [800751] Mozilla Products 'nsTreeSelection' Denial of Service vulnerability (Windows)
11364| [800750] Mozilla Products Denial of Service Vulnerability (Windows)
11365| [800744] Apple Safari Nested 'object' Tag Remote Denial Of Service vulnerability
11366| [800742] Microsoft Internet Explorer Unspecified vulnerability
11367| [800726] XM Easy Personal FTP Server File/Folder Denial of Service Vulnerability
11368| [800711] Samba winbind Daemon Denial of Service Vulnerability
11369| [800710] Quagga Denial of Service Vulnerability
11370| [800708] IPSec Tools Denial of Service Vulnerability
11371| [800706] Adobe Reader/Acrobat Denial of Service Vulnerability (May09)
11372| [800701] Adobe Reader Denial of Service Vulnerability (May09)
11373| [800700] Microsoft GDIPlus PNG Infinite Loop Vulnerability
11374| [800687] Microsoft Windows Server 2003 OpenType Font Engine DoS Vulnerability
11375| [800673] strongSwan Denial Of Service Vulnerability - Aug09
11376| [800656] Apple Safari Denial Of Service Vulnerability - Jul09
11377| [800626] ModSecurity Multiple Remote Denial of Service Vulnerabilities
11378| [800600] PGP Desktop Local Denial of Service Vulnerability
11379| [800597] ClamAV LZH File Unpacking Denial of Service Vulnerability (Linux)
11380| [800596] ClamAV LZH File Unpacking Denial of Service Vulnerability (Win)
11381| [800584] CUPS Denial of Service Vulnerability - Jun09
11382| [800581] CUPS IPP Packets Processing Denial of Service Vulnerability
11383| [800577] Microsoft Windows Server 2003 win32k.sys DoS Vulnerability
11384| [800566] Google Chrome Denial of Service Vulnerability
11385| [800551] Opera Web Browser XML Denial Of Service Vulnerability (Linux)
11386| [800550] Opera Web Browser XML Denial Of Service Vulnerability (Win)
11387| [800549] Apple Safari Denial of Service Vulnerability (Win) - Apr09
11388| [800544] JustSystems Ichitaro Products Denial Of Service Vulnerability
11389| [800541] Qip ICQ Message Denial Of Service Vulnerability
11390| [800505] Microsoft HTML Help Workshop buffer overflow vulnerability
11391| [800503] AyeView GIF Image Handling Denial of Service Vulnerability
11392| [800494] Apple QuickTime Multiple Denial Of Service Vulnerabilities (Win)
11393| [800490] OpenSSL 'kssl_keytab_is_available()' Denial Of Service Vulnerability (Win)
11394| [800487] CUPS 'scheduler/select.c' Denial Of Service Vulnerability
11395| [800486] Apple Safari 'SRC' Remote Denial Of Service Vulnerability
11396| [800485] Apple Safari 'background' Remote Denial Of Service Vulnerability
11397| [800481] Microsoft SharePoint Cross Site Scripting Vulnerability
11398| [800480] Microsoft Windows Media Player '.mpg' Buffer Overflow Vulnerability
11399| [800479] Aast! Antivirus 'aavmker4.sys' Denial Of Service Vulnerability (Win)
11400| [800473] Squid HTCP Packets Processing Denial of Service Vulnerability
11401| [800466] Microsoft Windows TLS/SSL Spoofing Vulnerability (977377)
11402| [800463] Asterisk T.38 Negotiation Remote Denial Of Service Vulnerability
11403| [800461] Microsoft Internet Explorer Information Disclosure Vulnerability (980088)
11404| [800460] Squid 'lib/rfc1035.c' Denial Of Service Vulnerability
11405| [800442] Microsoft Windows GP Trap Handler Privilege Escalation Vulnerability
11406| [800441] Kerberos5 KDC Cross Realm Referral Denial of Service Vulnerability
11407| [800429] Microsoft Internet Explorer Remote Code Execution Vulnerability (979352)
11408| [800423] Pidgin MSN Protocol Plugin Denial Of Service Vulnerability (Win)
11409| [800410] VMware Products vmware-authd Denial of Service Vulnerability (Win)
11410| [800395] Denial of Service vulnerability in AVG Anti-Virus (Linux)
11411| [800393] Denial Of Service Vulnerability in PHP April-09
11412| [800390] Firefox XUL Parsing Denial of Service Vulnerability (Linux)
11413| [800389] Firefox XUL Parsing Denial of Service Vulnerability (Win)
11414| [800382] Microsoft PowerPoint File Parsing Remote Code Execution Vulnerability (967340)
11415| [800374] Wireshark Denial of Service Vulnerability (Win)
11416| [800347] Microsoft Internet Explorer Clickjacking Vulnerability
11417| [800343] Microsoft Word 2007 Sensitive Information Disclosure Vulnerability
11418| [800337] Microsoft Internet Explorer NULL Pointer DoS Vulnerability
11419| [800332] Microsoft Windows Live Messenger Information Disclosure Vulnerability
11420| [800331] Microsoft Windows Live Messenger Client Version Detection
11421| [800328] Integer Overflow vulnerability in Microsoft Windows Media Player
11422| [800327] BreakPoint Software Hex Workshop Denial of Service vulnerability
11423| [800325] F-PROT AV 'ELF' Header Denial of Service Vulnerability
11424| [800321] Norton Internet Security Denial of Service Vulnerability
11425| [800306] MyServer Remote Denial of Service Vulnerability
11426| [800305] Sami FTP Server Multiple Commands Denial of Service Vulnerability
11427| [800267] Microsoft GDIPlus Library File Integer Overflow Vulnerability
11428| [800237] TitanFTP Server Denial of Service Vulnerability
11429| [800217] Microsoft Money Version Detection
11430| [800216] PGP Desktop Denial of Service Vulnerability
11431| [800213] VirusBlokAda Personal AV Denial of Service Vulnerability
11432| [800211] XM Easy Personal FTP Server Denial of Service Vulnerability
11433| [800209] Microsoft Internet Explorer Version Detection (Win)
11434| [800208] Microsoft Internet Explorer Anti-XSS Filter Vulnerabilities
11435| [800203] NOD32 Email Message Denial of Service Vulnerability
11436| [800195] A-V Tronics InetServ POP3 Denial Of Service Vulnerability
11437| [800194] Blackmoon FTP PORT Command Denial Of Service Vulnerability
11438| [800190] SolarFTP Server Multiple Commands Denial of Service Vulnerability
11439| [800187] MinaliC Webserver Denial of Service Vulnerability
11440| [800185] Zope Object Database ZEO Server Denial of Service Vulnerability
11441| [800184] OpenTTD Multiple use-after-free Denial of Service vulnerability
11442| [800183] Adobe Flash Media Server Multiple Denial of Service Vulnerabilities
11443| [800182] CUPS IPP Use-After-Free Denial of Service Vulnerability
11444| [800175] Xerver HTTP Server Web Administration Denial of Service Vulnerability
11445| [800161] Sun Java System Web Server Denial of Service Vulnerability (Win)
11446| [800139] K-Lite Mega Codec Pack vsfilter.dll Denial Of Service Vulnerability
11447| [800101] CA eTrust SCM Multiple HTTP Gateway Service Vulnerabilities
11448| [800083] Microsoft Outlook Express Malformed MIME Message DoS Vulnerability
11449| [800082] Microsoft SQL Server sp_replwritetovarbin() BOF Vulnerability
11450| [800079] ClamAV Remote Denial of Service Vulnerability
11451| [800074] Wireshark SMTP Processing Denial of Service Vulnerability (Win)
11452| [800064] Zope Python Scripts Local Denial of Service Vulnerability
11453| [800023] Microsoft Windows Image Color Management System Code Execution Vulnerability (952954)
11454| [103609] VMSA-2012-0016: VMware security updates for vSphere API and ESX Service Console
11455| [103512] Atlassian Crowd XML Parsing Denial of Service Vulnerability
11456| [103468] VMSA-2010-0009: ESXi utilities and ESX Service Console third party updates
11457| [103455] VMSA-2011-0012.3 VMware ESXi and ESX updates to third party libraries and ESX Service Console
11458| [103453] VMSA-2011-0004.3 VMware ESX/ESXi SLPD denial of service vulnerability and ESX third party updates for Service Console packages bind, pam, and rpm.
11459| [103450] VMSA-2011-0007 VMware ESXi and ESX Denial of Service and third party updates for Likewise components and ESX Service Console
11460| [103449] VMSA-2010-0016 VMware ESXi and ESX third party updates for Service Console and Likewise components
11461| [103448] VMSA-2012-0001 VMware ESXi and ESX updates to third party library and ESX Service Console
11462| [103411] Samba Memory Leak Local Denial Of Service Vulnerability
11463| [103383] PowerDNS Authoritative Server Remote Denial of Service Vulnerability
11464| [103370] Unbound Multiple Denial of Service Vulnerabilities
11465| [103369] ejabberd 'mod_pubsub' Module Denial of Service Vulnerability
11466| [103367] VxWorks Debugging Service Security-Bypass Vulnerability
11467| [103333] Apache HTTP Server 'ap_pregsub()' Function Local Denial of Service Vulnerability
11468| [103320] Squid Proxy Caching Server CNAME Denial of Service Vulnerability
11469| [103298] Samba 'etc/mtab' File Appending Local Denial of Service Vulnerability
11470| [103283] Samba 'mtab' Lock File Handling Local Denial of Service Vulnerability
11471| [103254] Microsoft SharePoint Server 2007 '_layouts/help.aspx' Cross Site Scripting Vulnerability
11472| [103209] Ingate SIParator SIP Module Remote Denial of Service Vulnerability
11473| [103208] Ingate Firewall SIP Module Remote Denial of Service Vulnerability
11474| [103192] Adobe Flash Media Server Memory Corruption Remote Denial of Service Vulnerability
11475| [103184] ManageEngine ServiceDesk Plus 'FILENAME' Parameter Directory Traversal Vulnerability
11476| [103183] ManageEngine ServiceDesk Plus Detection
11477| [103170] Unbound DNS Resolver Remote Denial of Service Vulnerability
11478| [103160] Serva32 Directory Traversal and Denial of Service Vulnerabilities
11479| [103159] LDAP Account Manager 'selfserviceSaveOk' Parameter Cross Site Scripting Vulnerability
11480| [103101] vsftpd FTP Server 'ls.c' Remote Denial of Service Vulnerability
11481| [103091] VicFTPS 'LIST' Command Remote Denial of Service Vulnerability
11482| [103090] ISC BIND 9 IXFR Transfer/DDNS Update Remote Denial of Service Vulnerability
11483| [103072] XM Easy Personal FTP Server 'TYPE' Command Remote Denial of Service Vulnerability
11484| [103065] Escortservice 'custid' Parameter SQL Injection Vulnerability
11485| [103050] Weborf 'get_param_value()' Function HTTP Header Handling Denial Of Service Vulnerability
11486| [103040] A-V Tronics InetServ SMTP Denial of Service Vulnerability
11487| [103037] Golden FTP Server Malformed Message Denial Of Service Vulnerability
11488| [103030] ISC BIND 9 'RRSIG' Record Type Negative Cache Remote Denial of Service Vulnerability
11489| [103020] PHP 'zend_strtod()' Function Floating-Point Value Denial of Service Vulnerability
11490| [103004] Mongoose 'Content-Length' HTTP Header Remote Denial Of Service Vulnerability
11491| [102059] Microsoft Windows Vector Markup Language Buffer Overflow (938127)
11492| [102055] Microsoft Windows GDI Multiple Vulnerabilities (925902)
11493| [102053] Microsoft Windows Vector Markup Language Vulnerabilities (929969)
11494| [102051] Kaspersky Antivirus UPX Denial of Service vulnerability
11495| [102050] Avast! Zoo Denial of Service Vulnerability
11496| [102049] Panda AntiVirus Zoo Denial of Service Vulnerability
11497| [102019] FileZilla Server Port Command Denial of Service
11498| [102016] SMB Enumerate Services
11499| [102015] Microsoft RPC Interface Buffer Overrun (KB824146)
11500| [101102] Vulnerability in Workstation Service Could Allow Elevation of Privilege (971657)
11501| [101100] Vulnerabilities in Microsoft ATL Could Allow Remote Code Execution (973908)
11502| [101025] Leap CMS service detection
11503| [101021] Opentaps ERP + CRM service detection
11504| [101019] Apache Open For Business service detection
11505| [101018] Windows SharePoint Services detection
11506| [101017] Microsoft MS03-018 security check
11507| [101016] Microsoft MS03-022 security check
11508| [101015] Microsoft MS03-034 security check
11509| [101014] Microsoft MS00-078 security check
11510| [101012] Microsoft MS03-051 security check
11511| [101010] Microsoft Security Bulletin MS05-004
11512| [101009] Microsoft Security Bulletin MS06-033
11513| [101007] Microsoft dotNET version grabber
11514| [101006] Microsoft Security Bulletin MS06-056
11515| [101005] Microsoft Security Bulletin MS07-040
11516| [101004] Microsoft MS04-017 security check
11517| [101003] Microsoft MS00-058 security check
11518| [101000] Microsoft MS00-060 security check
11519| [100952] Microsoft IIS FTPd NLST stack overflow
11520| [100950] Microsoft DNS server internal hostname disclosure detection
11521| [100949] HttpBlitz Server HTTP Request Remote Denial of Service Vulnerability
11522| [100918] NCH Software Office Intercom SIP Invite Remote Denial of Service Vulnerability
11523| [100904] IBM WebSphere Application Server JAX-WS Denial Of Service Vulnerability
11524| [100878] Weborf HTTP Request Denial Of Service Vulnerability
11525| [100872] MinaliC Directory Traversal and Denial of Service Vulnerabilities
11526| [100861] IBM solidDB Multiple Denial of Service Vulnerabilities
11527| [100834] Novell eDirectory Server Malformed Index Denial Of Service Vulnerability
11528| [100831] ISC BIND Denial Of Service and Security Bypass Vulnerability
11529| [100830] ClamAV 'find_stream_bounds()' PDF File Processing Denial Of Service Vulnerability
11530| [100821] OTRS Core System Multiple Cross-Site Scripting and Denial of Service Vulnerabilities
11531| [100798] MailEnable 'MESMTRPC.exe' SMTP Service Multiple Remote Denial of Service Vulnerabilities
11532| [100789] Squid Proxy String Processing NULL Pointer Dereference Denial Of Service Vulnerability
11533| [100779] Zope Unspecified Denial Of Service Vulnerability
11534| [100777] Wing FTP Server HTTP Request Denial Of Service Vulnerability
11535| [100767] Serv-U Denial of Service and Security Bypass Vulnerabilities
11536| [100759] SquirrelMail Remote Denial of Service Vulnerability
11537| [100758] ZNC Multiple Denial Of Service Vulnerabilities
11538| [100731] Wing FTP Server Denial of Service Vulnerability and Information Disclosure Vulnerability
11539| [100725] Apache HTTP Server Multiple Remote Denial of Service Vulnerabilities
11540| [100717] ISC BIND 9 'RRSIG' Record Type Remote Denial of Service Vulnerability
11541| [100703] Sun Java System Web Server Admin Interface Denial of Service Vulnerability
11542| [100691] Weborf HTTP Header Processing Denial Of Service Vulnerability
11543| [100690] Wing FTP Server 'PORT' Command Denial Of Service Vulnerability
11544| [100683] ZNC NULL Pointer Dereference Denial Of Service Vulnerability
11545| [100676] nginx Remote Source Code Disclosure and Denial of Service Vulnerabilities
11546| [100656] ClamAV 'parseicon()' Denial Of Service Vulnerability
11547| [100653] SolarWinds TFTP Server 'Read' Request (Opcode 0x01) Denial Of Service Vulnerability
11548| [100652] ClamAV 'cli_pdf()' PDF File Processing Denial Of Service Vulnerability
11549| [100644] Samba Multiple Remote Denial of Service Vulnerabilities
11550| [100642] SmallFTPD 'DELE' Command Remote Denial Of Service Vulnerability
11551| [100641] TYPSoft FTP Server 'RETR' Command Remote Denial Of Service Vulnerability
11552| [100633] Xitami '/AUX' Request Remote Denial Of Service Vulnerability
11553| [100626] ddrLPD Remote Denial of Service Vulnerability
11554| [100624] Microsoft Windows SMTP Server DNS spoofing vulnerability
11555| [100622] RealVNC 4.1.3 'ClientCutText' Message Remote Denial of Service Vulnerability
11556| [100612] NovaStor NovaNET Multiple Code Execution, Denial of Service, Information Disclosure Vulnerabilities
11557| [100588] OpenSSL 'dtls1_retrieve_buffered_fragment()' Remote Denial of Service Vulnerability
11558| [100587] OpenSSL 'ssl3_get_record()' Remote Denial of Service Vulnerability
11559| [100585] HTTP File Server Security Bypass and Denial of Service Vulnerabilities
11560| [100582] PHP FastCGI Module File Extension Denial Of Service Vulnerabilities
11561| [100581] PHP 'exif_read_data()' JPEG Image Processing Denial Of Service Vulnerability
11562| [100554] JINAIS IRC Message Remote Denial Of Service Vulnerability
11563| [100548] Remote Help HTTP GET Request Format String Denial Of Service Vulnerability
11564| [100534] httpdx Multiple Remote Denial Of Service Vulnerabilities
11565| [100532] FreeBSD and OpenBSD 'ftpd' NULL Pointer Dereference Denial Of Service Vulnerability
11566| [100531] Unbound 'sock_list' Structure Allocation Remote Denial Of Service Vulnerability
11567| [100529] PHP xmlrpc Extension Multiple Remote Denial of Service Vulnerabilities
11568| [100525] httpdx PNG File Handling Remote Denial of Service Vulnerability
11569| [100510] Sun Java System Directory Server LDAP Search Request Denial of Service Vulnerability
11570| [100499] Samba 'client/mount.cifs.c' Remote Denial of Service Vulnerability
11571| [100492] Novell eDirectory eMBox SOAP Request Denial Of Service Vulnerability
11572| [100487] ejabberd 'client2server' Message Remote Denial of Service Vulnerability
11573| [100480] lighttpd Slow Request Handling Remote Denial Of Service Vulnerability
11574| [100471] ircd-ratbox 'HELP' Command Denial Of Service Vulnerability
11575| [100447] Acme thttpd and mini_httpd Terminal Escape Sequence in Logs Command Injection Vulnerability
11576| [100446] Yaws Terminal Escape Sequence in Logs Command Injection Vulnerability
11577| [100445] Ruby WEBrick Terminal Escape Sequence in Logs Command Injection Vulnerability
11578| [100444] Orion Application Server Terminal Escape Sequence in Logs Command Injection Vulnerability
11579| [100443] Boa Webserver Terminal Escape Sequence in Logs Command Injection Vulnerability
11580| [100442] AOLServer Terminal Escape Sequence in Logs Command Injection Vulnerability
11581| [100441] nginx Terminal Escape Sequence in Logs Command Injection Vulnerability
11582| [100440] Cherokee Terminal Escape Sequence in Logs Command Injection Vulnerability
11583| [100438] Sun Java System Directory Server 'core_get_proxyauth_dn' Denial of Service Vulnerability
11584| [100412] Squid Header-Only Packets Remote Denial of Service Vulnerability
11585| [100399] NTP mode 7 MODE_PRIVATE Packet Remote Denial of Service Vulnerability
11586| [100397] Monkey HTTP Daemon Invalid HTTP 'Connection' Header Denial Of Service Vulnerability
11587| [100369] CUPS File Descriptors Handling Remote Denial Of Service Vulnerability
11588| [100366] Asterisk RTP Comfort Noise Processing Remote Denial of Service Vulnerability
11589| [100357] Cisco VPN Client for Windows 'StartServiceCtrlDispatche' Local Denial of Service Vulnerability
11590| [100351] Home FTP Server 'SITE INDEX' Command Remote Denial of Service Vulnerability
11591| [100347] ngIRCd SSL/TLS Support MOTD Request Multiple Denial Of Service Vulnerabilities
11592| [100342] XM Easy Personal FTP Server 'NLST' Command Remote Denial of Service Vulnerability
11593| [100340] Novell eDirectory NULL Base DN Denial Of Service Vulnerability
11594| [100338] Serv-U 'SITE SET TRANSFERPROGRESS ON' Command Remote Denial of Service Vulnerability
11595| [100320] Bftpd Unspecified Remote Denial of Service Vulnerability
11596| [100318] Cherokee Web Server Malformed Packet Remote Denial of Service Vulnerability
11597| [100305] Dopewars Server 'REQUESTJET' Message Remote Denial of Service Vulnerability
11598| [100298] Code-Crafters Ability Mail Server IMAP FETCH Request Remote Denial Of Service Vulnerability
11599| [100296] Xlpd Remote Denial of Service Vulnerability
11600| [100293] DataWizard FtpXQ Remote Denial of Service Vulnerability
11601| [100287] Mozilla Bugzilla 'Bug.create()' WebService Function SQL Injection Vulnerability
11602| [100286] Mozilla Bugzilla 'Bug.search()' WebService Function SQL Injection Vulnerability
11603| [100284] Cerberus FTP Server Long Command Remote Denial of Service Vulnerability
11604| [100283] Microsoft Windows SMB2 '_Smb2ValidateProviderCallback()' Remote Code Execution Vulnerability
11605| [100264] SolarWinds TFTP Server Option Acknowledgement Request Denial Of Service Vulnerability
11606| [100251] ISC BIND 9 Remote Dynamic Update Message Denial of Service Vulnerability
11607| [100249] Squid Multiple Remote Denial of Service Vulnerabilities
11608| [100207] Eggdrop 'ctcpbuf' Remote Denial Of Service Vulnerability
11609| [100198] TYPSoft FTP Server 'ABORT' Command Remote Denial of Service Vulnerability
11610| [100185] Quick 'n Easy Mail Server SMTP Request Remote Denial Of Service Vulnerability
11611| [100171] Apache Web Server Linefeed Memory Allocation Denial Of Service Vulnerability
11612| [100167] Zervit HTTP Server Malformed URI Remote Denial Of Service Vulnerability
11613| [100163] Home Web Server Graphical User Interface Remote Denial Of Service Vulnerability
11614| [100162] Mod_Perl Path_Info Remote Denial Of Service Vulnerability
11615| [100116] Horde Turba 'services/obrowser/index.php' HTML Injection Vulnerability
11616| [100111] Check for rexecd Service
11617| [100084] Squid Proxy Cache ICAP Adaptation Denial of Service Vulnerability
11618| [100081] Check for ident Service
11619| [100080] Check for rsh Service
11620| [100075] Check for echo Service
11621| [100062] Microsoft Remote Desktop Protocol Detection
11622| [90024] Windows Vulnerability in Microsoft Jet Database Engine
11623| [80056] ELOG Web LogBook global Denial of Service
11624| [80030] Packeteer PacketShaper Web Denial of Service
11625| [80007] Microsoft MS00-06 security check
11626| [80006] Sybase Enterprise Application Server service detection
11627| [80004] Firebase/Interbase database Server service detection
11628| [80003] FileMaker service detection
11629| [69366] avahi -- denial of service
11630| [66286] Identify unknown services with nmap
11631| [66063] django -- denial-of-service attack
11632| [66041] Fedora Core 11 FEDORA-2009-10466 (drupal-service_links)
11633| [66040] Fedora Core 10 FEDORA-2009-10445 (drupal-service_links)
11634| [64120] wireshark -- PCNFSD Dissector Denial of Service Vulnerability
11635| [62851] wireshark -- SMTP Processing Denial of Service Vulnerability
11636| [60229] FreeBSD Ports: ircservices
11637| [60016] Gentoo Security Advisory GLSA 200712-12 (ircservices)
11638| [58690] Debian Security Advisory DSA 1393-1 (xfce4-terminal)
11639| [58542] Gentoo Security Advisory GLSA 200708-07 (terminal)
11640| [54667] Gentoo Security Advisory GLSA 200409-10 (multi-gnome-terminal)
11641| [53941] Slackware Advisory SSA:2004-108-01 tcpdump denial of service
11642| [20890] Lotus Domino LDAP Server Denial of Service Vulnerability
11643| [20377] Windows Server Update Services detection
11644| [19777] Malformed ICMP Packets May Cause a Denial of Service (SCTP)
11645| [19304] Allegro Software RomPager 2.10 Denial of Service
11646| [18650] Sambar Search Results Buffer Overflow Denial of Service
11647| [18185] Kerio Winroute Firewall Admin Service
11648| [18184] Kerio Mailserver Admin Service
11649| [18183] Kerio Personal Firewall Admin Service
11650| [17975] Identify unknown services with GET
11651| [17602] FTPD glob (too many *) denial of service
11652| [17348] Jetty < 4.2.19 Denial of Service
11653| [17307] CA License Service Multiple Vulnerabilities
11654| [17296] Kill service with random data
11655| [15852] MailEnable IMAP Service Remote Buffer Overflows
11656| [15753] Multiple Vendor DNS Response Flooding Denial Of Service
11657| [15613] Hummingbird Connectivity FTP service XCWD Overflow
11658| [15487] MailEnable IMAP Service Search DoS Vulnerability
11659| [15467] Vulnerability in RPC Runtime Library Could Allow Information Disclosure and Denial of Service (873350)
11660| [15463] Squid remote denial of service
11661| [14838] myServer POST Denial of Service
11662| [14773] Identifies services like FTP, SMTP, NNTP...
11663| [14772] Service Detection (2nd pass)
11664| [14712] MailEnable SMTP Connector Service DNS Lookup DoS Vulnerability
11665| [14682] eZ/eZphotoshare Denial of Service
11666| [14664] external services identification
11667| [14656] MailEnable HTTPMail Service GET Overflow Vulnerability
11668| [14655] MailEnable HTTPMail Service Content-Length Overflow Vulnerability
11669| [14654] MailEnable HTTPMail Service Authorization Header DoS Vulnerability
11670| [14646] Xedus Denial of Service
11671| [14353] Music Daemon Denial of Service
11672| [14249] Opera web browser news url denial of service vulnerability
11673| [12280] Apache Connection Blocking Denial of Service
11674| [12267] Vulnerability in DirectPlay Could Allow Denial of Service (839643)
11675| [12105] Use LDAP search request to retrieve information from NT Directory Services
11676| [11992] Vulnerability in Microsoft ISA Server 2000 H.323 Filter(816458)
11677| [11905] Checkpoint Firewall-1 UDP denial of service
11678| [11896] DB2 discovery service DOS
11679| [11891] LinkSys EtherFast Router Denial of Service Attack
11680| [11888] Buffer Overrun in Messenger Service (828035)
11681| [11874] IIS Service Pack - 404
11682| [11825] Polycom ViaVideo denial of service
11683| [11808] Microsoft RPC Interface Buffer Overrun (823980)
11684| [11773] Linksys Gozila CGI denial of service
11685| [11517] Leafnode denials of service
11686| [11443] Microsoft IIS UNC Mapped Virtual Host Vulnerability
11687| [11217] Microsoft's SQL Version Query
11688| [11184] vxworks ftpd buffer overflow Denial of Service
11689| [11177] Flaw in Microsoft VM Could Allow Code Execution (810030)
11690| [11162] WebSphere Edge caching proxy denial of service
11691| [11159] MS RPC Services null pointer reference DoS
11692| [11154] Unknown services banners
11693| [11153] Identify unknown services with 'HELP'
11694| [11150] Tomcat servlet engine MS/DOS device names denial of service
11695| [11146] Microsoft RDP flaws could allow sniffing and DOS(Q324380)
11696| [11119] SMB Registry : XP Service Pack version
11697| [11089] Webseal denial of service
11698| [11067] Microsoft's SQL Hello Overflow
11699| [11059] Trend Micro OfficeScan Denial of service
11700| [10990] FTP Service Allows Any Username
11701| [10943] Cumulative Patch for Internet Information Services (Q327696)
11702| [10939] MSDTC denial of service by flooding with nul bytes
11703| [10866] XML Core Services patch (Q318203)
11704| [10862] Microsoft's SQL Server Brute Force
11705| [10848] Oracle 9iAS Dynamic Monitoring Services
11706| [10798] Unprotected PC Anywhere Service
11707| [10778] Unprotected SiteScope Service
11708| [10755] Microsoft Exchange Public Folders Information Leak
11709| [10736] DCE Services Enumeration
11710| [10680] Test Microsoft IIS Source Fragment Disclosure
11711| [10674] Microsoft's SQL UDP Info Query
11712| [10673] Microsoft's SQL Blank Password
11713| [10491] ASP/ASA source using Microsoft Translate f: bug
11714| [10330] Services
11715| [10326] Yahoo Messenger Denial of Service attack
11716| [10144] Microsoft SQL TCP/IP listener is running
11717| [10102] HotSync Manager Denial of Service attack
11718| [10033] CA Unicenter's Transport Service is running
11719| [10032] CA Unicenter's File Transfer Service is running
11720| [2497] IBM Lotus Domino Notes RPC Authentication Processing Denial of Service Vulnerability
11721|
11722| SecurityTracker - https://www.securitytracker.com:
11723| [1006447] Microsoft Windows Terminal Services RDP Implementation Does Not Validate Server Identity, Allowing Man-in-the-Middle Attacks
11724| [1005120] Microsoft Terminal Services Advanced Client (TSAC) ActiveX Control Buffer Overflow Lets Remote Users Execute Arbitrary Code
11725| [1004927] Microsoft Terminal Services Can Be Crashed By Remote Users Conducting a TCP SYN Scan in Certain Situations
11726| [1003591] Microsoft Windows Terminal Services May Cause the System's Screen Saver Lockout Mechanism to Fail in Certain Situations
11727| [1002754] Terminal Services on Microsoft Windows 2000 and XP Allow Remote Users to Log Bogus IP Addresses Instead of the User's Genuine Address
11728| [1002098] Windows Terminal Services in Microsoft Windows 2000 and NT 4.0 Can Be Crashed By Remote Users Due to a Memory Leak
11729| [1028908] Microsoft Active Directory Federation Services Discloses Account Information to Remote Users
11730| [1028905] (Microsoft Issues Fix for Exchange Server) Oracle Fusion Middleware Bugs Let Remote Users Deny Service and Access and Modify Data
11731| [1028904] (Microsoft Issues Fix for Exchange Server) Oracle PeopleSoft Products Bugs Let Remote Users Partially Access and Modify Data and Partially Deny Service
11732| [1028405] Microsoft Active Directory LDAP Processing Flaw Lets Remote Users Deny Service
11733| [1028278] Microsoft SharePoint Input Validation Flaws Permit Cross-Site Scripting and Denial of Service Attacks
11734| [1027949] Microsoft .NET Open Data (OData) Protocol Bug Lets Remote Users Deny Service
11735| [1027943] Microsoft XML Core Services (MSXML) XML Parsing Flaws Let Remote Users Execute Arbitrary Code
11736| [1027857] Microsoft Exchange Server RSS Feed Bug Lets Remote Users Deny Service
11737| [1027623] Microsoft SQL Server Input Validation Flaw in Reporting Services Permits Cross-Site Scripting Attacks
11738| [1027620] Microsoft Kerberos Null Pointer Dereference Lets Remote Users Deny Service
11739| [1027157] Microsoft XML Core Services (MSXML) Object Access Error Lets Remote Users Execute Arbitrary Code
11740| [1027048] Microsoft .NET Bugs Let Remote Users Execute Arbitrary Code and Deny Service
11741| [1026794] Microsoft DirectWrite Unicode Character Processing Flaw Lets Remote Users Deny Service
11742| [1026789] Microsoft DNS Server Lets Remote Users Deny Service
11743| [1026469] Microsoft ASP.NET Hash Table Collision Bug Lets Remote Users Deny Service
11744| [1026169] Microsoft Forefront Unified Access Gateway Input Validation Flaws Permits Cross-Site Scripting, HTTP Response Splitting, and Denial of Service Attacks
11745| [1026168] Microsoft Host Integration Server Bugs Let Remote Users Deny Service
11746| [1026037] Microsoft Windows Internet Name Service (WINS) Input Validation Flaw in ECommEndDlg() Lets Local Users Gain Elevated Privileges
11747| [1025937] Microsoft Windows DHCPv6 Processing Flaw Lets Remote Denial of Service to RPC Services
11748| [1025894] Microsoft DNS Server Flaws Let Remote Users Execute Arbitrary Code and Deny Service
11749| [1025653] Microsoft Active Directory Input Validation Flaw in Certificate Services Web Enrollment Permits Cross-Site Scripting Attacks
11750| [1025644] Microsoft Hyper-V VMBus Packet Validation Flaw Lets Local Users Deny Service
11751| [1025639] Microsoft Distributed File System Bugs Let Remote Users Deny Service and Execute Arbitrary Code
11752| [1025512] Microsoft Windows Internet Name Service Socket Send Exception Handling Bug Lets Remote Users Execute Arbitrary Code
11753| [1025312] Microsoft Windows Kernel Bug in AFD.sys Lets Local Users Deny Service
11754| [1025049] Microsoft Local Security Authority Subsystem Service (LSASS) Lets Local Users Gain Elevated Privileges
11755| [1025042] Microsoft Active Directory SPN Collosions May Let Remote Authenticated Users Deny Service
11756| [1024921] Microsoft IIS FTP Server Lets Remote Users Deny Service
11757| [1024888] Microsoft Exchange Server RPC Processing Flaw Lets Remote Authenticated Users Deny Service
11758| [1024884] Microsoft Hyper-V Input Validation Flaw Lets Local Guest Operating System Users Deny Service
11759| [1024790] Microsoft Outlook Attachment Processing Flaw Lets Remote Users Deny Service
11760| [1024558] Microsoft Cluster Service Disk Permission Flaw Lets Local Users Gain Elevated Privileges
11761| [1024496] Microsoft Internet Information Server (IIS) Web Server Stack Overflow in Reading POST Data Lets Remote Users Deny Service
11762| [1024443] Microsoft Local Security Authority Subsystem Service (LSASS) Heap Overflow Lets Remote Authenticated Users Execute Arbitrary Code
11763| [1024440] Microsoft Internet Information Services Bugs Let Remote Users Bypass Authentication, Deny Service, and Execute Arbitrary Code
11764| [1024312] Microsoft Windows Tracing Feature for Services Lets Local Users Gain Elevated Privileges
11765| [1024301] Microsoft XML Core Services (MSXML) HTTP Response Processing Flaw Lets Remote Users Execute Arbitrary Code
11766| [1024079] Microsoft Internet Information Services Memory Allocation Error Lets Remote Authenticated Users Execute Arbitrary Code
11767| [1024077] Microsoft SharePoint Help Page Processing Bug Lets Remote Users Deny Service
11768| [1023854] Microsoft Exchange Error in Parsing MX Records Lets Remote Users Deny Service
11769| [1023567] Microsoft Hyper-V Instruction Validation Bug Lets Local Users Deny Service
11770| [1023566] Microsoft Windows Kerberos Ticket-Granting-Ticket Processing Flaw Lets Remote Authenticated Users Deny Service
11771| [1023387] Microsoft Internet Information Services (IIS) Filename Extension Parsing Configuration Error May Let Users Bypass Security Controls
11772| [1023297] Microsoft Local Security Authority Subsystem Service Validation Flaw Lets Remote Users Deny Service
11773| [1023296] Microsoft Active Directory Federation Services Lets Remote Authenticated Users Execute Arbitrary Code and Spoof Web Sites
11774| [1023291] Microsoft Internet Authentication Service Bugs Let Remote Authenticated Users Execute Arbitrary Code or Gain Privileges of the Target User
11775| [1023156] Microsoft Active Directory Stack Memory Consumption Flaw Lets Remote Users Deny Service
11776| [1023154] Microsoft License Logging Service Buffer Overflow Lets Remote Users Execute Arbitrary Code
11777| [1023153] Microsoft Web Services on Devices API (WSDAPI) Validation Error Lets Remote Users Execute Arbitrary Code
11778| [1023011] Microsoft Indexing Service ActiveX Control Lets Remote Users Execute Arbitrary Code
11779| [1023010] Microsoft Local Security Authority Subsystem Service (LSASS) Integer Underflow Lets Local Users Deny Service
11780| [1022846] Microsoft Wireless LAN AutoConfig Service Heap Overflow Lets Remote Wireless Users Execute Arbitrary Code
11781| [1022792] Microsoft Internet Information Server (IIS) FTP Server Buffer Overflows Let Remote Authenticated Users Execute Arbitrary Code and Deny Service
11782| [1022715] Microsoft ASP.NET Request Scheduling Flaw Lets Remote Users Deny Service
11783| [1022710] Microsoft Windows Internet Name Service (WINS) Buffer Overflows Let Remote Users Execute Arbitrary Code
11784| [1022358] Microsoft Internet Information Services WebDAV Bug Lets Remote Users Bypass Authentication
11785| [1022349] Microsoft Active Directory Bugs Let Remote Users Execute Arbitrary Code or Deny Service
11786| [1022330] Microsoft Windows Bug in SETDESKWALLPAPER and GETDESKWALLPAPER Calls Let Local Users Deny Service
11787| [1022045] Microsoft ISA Server TCP State Error Lets Remote Users Deny Service
11788| [1021831] Microsoft DNS Server Bugs Let Remote Users Spoof the DNS Service
11789| [1021701] Microsoft Exchange MAPI Command Literal Processing Bug Lets Remote Users Deny Service
11790| [1021640] Solaris Pseudo-Terminal Driver Race Condition Lets Local Users Deny Service
11791| [1021294] Microsoft Office Communicator VoIP Processing Bugs Let Remote Users Deny Service
11792| [1021164] Microsoft XML Core Services (MSXML) Bugs Let Remote Users Obtain Information and Execute Arbitrary Code
11793| [1021020] Cisco Unity Bug in Microsoft API Lets Remote Users Deny Service
11794| [1020229] Microsoft Active Directory LDAP Validation Bug Lets Remote Users Deny Service
11795| [1020016] Microsoft Malware Protection Engine Lets Remote Users Deny Service
11796| [1019385] Microsoft Internet Information Services Error in Processing ASP Page Input Lets Remote Users Execute Arbitrary Code
11797| [1019384] Microsoft Internet Information Services File Change Notification Bug Lets Local Users Gain Elevated Privileges
11798| [1018942] Microsoft Windows DNS Service Insufficent Entropy Lets Remote Users Spoof the DNS Service
11799| [1018559] Microsoft Core XML Services Memory Corruption Error Lets Remote Users Execute Arbitrary Code
11800| [1018202] Microsoft GDI+ ICO File Divide By Zero Bug Lets Remote Users Deny Service
11801| [1018015] Microsoft Exchange Base64, iCal, IMAP, and Attachment Processing Bugs Let Remote Users Deny Service or Execute Arbitrary Code
11802| [1017910] Microsoft Windows DNS Service RPC Stack Overflow Lets Remote Users Execute Arbitrary Code
11803| [1017736] Microsoft Windows Explorer OLE Parsing Bug Lets Users Deny Service
11804| [1017488] Microsoft Outlook '.iCal', '.oss', and SMTP Header Bugs Let Remote Users Execute Arbitrary Code or Deny Service
11805| [1017441] Microsoft Windows Workstation Service Memory Allocation Error in NetrWkstaUserEnum() Lets Remote Users Deny Service
11806| [1017397] Microsoft Outlook Recipient ActiveX Control Lets Remote Users Deny Service
11807| [1017224] Microsoft Client Service for Netware Buffer Overflows Let Remote Users Execute Arbitrary Code and Crash the System
11808| [1017157] Microsoft XML Core Services ActiveX Control Lets Remote Users Execute Arbitrary Code
11809| [1017133] Microsoft NAT Helper 'ipnathlp.dll' Lets Remote Users Deny Service
11810| [1017033] Microsoft XML Core Services Lets Remote Users Execute Arbitrary Code or Obtain Information
11811| [1016827] Microsoft PGM Implementation Buffer Overflow in MSMQ Service Lets Remote Users Execute Arbitrary Code
11812| [1016047] Microsoft Distributed Transaction Coordinator Bugs Let Remote Users Deny Service
11813| [1015895] Microsoft SharePoint Team Services Input Validation Holes Permit Cross-Site Scripting Attacks
11814| [1015825] Microsoft ASP.NET Incorrect COM Component Reference Lets Remote Users Deny Service
11815| [1015794] (Vendor Issues Fix) Microsoft Internet Explorer 'mshtml.dll' Bug in Processing Multiple Action Handlers Lets Remote Users Deny Service
11816| [1015765] Microsoft Windows Services Have Unsafe Default ACLs That Let Remote Authenticated Users Gain Elevated Privileges
11817| [1015629] Microsoft Windows IGMP Processing Bug Lets Remote Users Deny Service
11818| [1015595] Microsoft Windows UPnP/NetBT/SCardSvr/SSDP Services May Be Incorrectly Configured By 3rd Party Applications, Allowing Local Users to Gain Elevated Privileges
11819| [1015559] Microsoft Internet Explorer Shockwave Flash Scripting Bug Lets Remote Users Deny Service
11820| [1015376] Microsoft IIS Lets Remote Users Deny Service or Execute Arbitrary Code With Malformed HTTP GET Requests
11821| [1015233] Microsoft Windows RPC Service May Let Remote Users Deny Service
11822| [1015049] Microsoft Internet Explorer Drag-and-Drop Timing May Let Remote Users Install Arbitrary Files
11823| [1015043] Microsoft Network Connection Manager Lets Remote Users Deny Service
11824| [1015041] Microsoft Client Service for NetWare Buffer Overflow Lets Remote Users Execute Arbitrary Code
11825| [1014642] Microsoft Windows Kerberos and PKINIT Vulnerabilities Allow Denial of Service, Information Disclosure, and Spoofing
11826| [1014639] Microsoft Windows Telephony Service Remote Code Execution or Local Privilege Escalation
11827| [1014638] Microsoft Windows Print Spooler Service Buffer Overflow Lets Remote Users Execute Arbitrary Code
11828| [1014500] Microsoft Internet Explorer (IE) JPEG Rendering Bugs Let Remote Users Deny Service or Execute Arbitrary Code
11829| [1014498] Microsoft Windows Remote Desktop Protocol Bug Lets Remote Users Deny Service
11830| [1014196] Microsoft Windows Buffer Overflow in Web Client Service Lets Remote Authenticated Users Execute Arbitrary Code
11831| [1013688] Microsoft Windows Kernel and Font Buffer Overflows Let Local Users Deny Service or Obtain System Privileges
11832| [1013686] Microsoft Windows TCP, IP, and ICMP Processing Errors Let Remote Users Deny Service and Execute Arbitrary Code
11833| [1013117] Microsoft Windows License Logging Service Lets Remote Users Execute Arbitrary Code
11834| [1013111] Microsoft SharePoint Services Redirection Query Input Validation Hole Lets Remote Users Conduct Cross-Site Scripting Attacks
11835| [1012683] Microsoft Windows ANI File Parsing Errors Let Remote Users Deny Service
11836| [1012518] Microsoft HyperTerminal Buffer Overflow Lets Remote Users Execute Arbitrary Code
11837| [1011880] Microsoft Windows XP Error in Explorer in Processing WAV Files Lets Remote Users Deny Service
11838| [1011645] Microsoft Various Operating System Flaws Lets Remote Users Execute Code and Local Users Gain Elevated Privileges or Deny Service
11839| [1011636] Microsoft SMTP Service Buffer Overflow in Processing DNS Responses May Let Remote Users Execute Arbitrary Code
11840| [1011633] Microsoft IIS WebDAV XML Message Handler Error Lets Remote Users Deny Service
11841| [1011632] Microsoft NT RPC Runtime Library Buffer Overflow Lets Remote Users Deny Service
11842| [1011200] F-Secure Anti-Virus for Microsoft Exchange Input Validation Bug in Content Scanner Server Lets Remote Users Deny Service
11843| [1009777] Microsoft SSL Library Input Validation Error Lets Remote Users Crash the Service
11844| [1009767] Microsoft Windows 2000 Domain Controller LDAP Flaw May Let Remote Users Restart the Authentication Service
11845| [1009762] Microsoft Windows COM Internet Services and RPC over HTTP Can Be Crashed By Remote Users
11846| [1009758] Microsoft Windows RCP Memory Leak Lets Remote Users Deny Service
11847| [1009751] Microsoft LSASS Service Buffer Overflow Lets Remote Users Execute Arbitrary Code With SYSTEM Privileges
11848| [1009673] Microsoft Windows XP 'mswebdvd.dll' Buffer Overflow Lets Remote Users Deny Service
11849| [1009359] Microsoft Windows Media Services Can Be Crashed By Remote Users
11850| [1009008] Microsoft Windows Internet Naming Service (WINS) Length Validation Flaw Lets Remote Users Deny Service
11851| [1008428] Microsoft ASP.NET Web Services XML Parsing Lets Remote Users Consume CPU Resources With SOAP Requests
11852| [1008324] Microsoft Exchange 2003 With Outlook Web Access and Windows SharePoint Services May Grant Incorrect E-mail Account Access to Remote Authenticated Users
11853| [1008148] Microsoft SharePoint Team Services Buffer Overflow May Let Remote Users Execute Arbitrary Code
11854| [1008146] Microsoft Windows Workstation Service (wkssvc.dll) Buffer Overflow Lets Remote Users Execute Arbitrary Code with System Privileges
11855| [1007933] Microsoft Windows Messenger Service Buffer Overflow Lets Remote Users Execute Arbitrary Code With Local System Privileges
11856| [1007922] Microsoft Windows RPC Multi-threaded Race Condition Lets Remote Users Crash the Service or Execute Arbitrary Code
11857| [1007750] Microsoft BizTalk Server Default Directory Permissions May Let Remote Users Deny Service
11858| [1007615] Microsoft Windows NetBIOS Name Service May Disclose Memory Contents to Remote Users
11859| [1007212] Microsoft Windows Remote Procedure Call (RPC) Service Buffer Overflow in Processing DCOM Requests Allows Remote Code Execution
11860| [1007206] Microsoft SMTP Service Can Be Crashed By Remote Users Sending Mail With an Invalid FILETIME Header
11861| [1007059] Microsoft Windows Media Services (nsiislog.dll) Extension to Internet Information Server (IIS) Has Another Buffer Overflow That Lets Remote Execute Arbitrary Code
11862| [1006867] Microsoft IIS Buffer Overflow Lets Remote Users With Upload Privileges Execute Code - Remote Users Can Also Crash the Service
11863| [1006866] Microsoft Windows Media Services (nsiislog.dll) Extension to Internet Information Server (IIS) Lets Remote Execute Arbitrary Code
11864| [1006534] Microsoft Proxy Service in Proxy Server 2.0 Has Unspecified Flaw That Lets Remote Users Stop Traffic
11865| [1006533] Microsoft Firewall Service in ISA Server Has Unspecified Flaw That Lets Remote Users Stop Traffic
11866| [1005986] Microsoft Windows Terminal Server MSGINA.DLL Flaw Lets Remote Authenticated Users Reboot the Server
11867| [1005964] Microsoft Locator Service Buffer Overflow Lets Remote Users Execute Arbitrary Code with System Level Privileges
11868| [1005674] Microsoft Internet Explorer Buffer Overflow in Processing PNG Images Allows Denial of Service Attacks
11869| [1005455] Microsoft Windows Remote Procedure Call (RPC) Service Null Pointer Dereference Allows Remote Users to Crash the Service
11870| [1005339] Microsoft Services for Unix Interix SDK Bugs May Allow Denial of Service Conditions or May Execute Arbitrary Code
11871| [1005296] Microsoft PPTP Service Buffer Overflow May Let Remote Users Execute Arbitrary Code
11872| [1004831] Microsoft Data Engine (MSDE) Buffer Overflow in Database Consistency Checker May Let Remote Authenticated Users Execute Arbitrary Code with the Privileges of the Database Service
11873| [1004830] Microsoft SQL Server Buffer Overflow in Database Consistency Checker May Let Remote Authenticated Users Execute Arbitrary Code with the Privileges of the Database Service
11874| [1004829] Microsoft SQL Server Resolution Service Buffer Overflows Let Remote Users Execute Arbitrary Code with the Privileges of the SQL Service
11875| [1004827] Microsoft Metadirectory Services Authentication Flaw May Let Remote Users Modify Data and Obtain Elevated Privileges on the System
11876| [1004757] Microsoft IIS SMTP Service Encapsulation Bug Lets Remote Users Relay Mail and Send SPAM Via the Service
11877| [1004542] Lumigent Log Explorer Buffer Overflow May Let Remote Users Crash the Microsoft SQL Server Service or Execute Arbitrary Code on the System
11878| [1004529] Microsoft Remote Access Service (RAS) Phonebook Buffer Overflow May Let Local Users Execute Arbitrary Code with Local System Privileges
11879| [1004486] Microsoft ASP.NET Buffer Overflow in Processing Cookies in StateServer Mode May Let Remote Users Crash the Service or Execute Arbitrary Code on the Server
11880| [1004407] Microsoft Exchange 2000 Flaw in Processing a Certain Malformed SMTP Command Allows Remote Users to Deny Service to the Server
11881| [1004290] Microsoft Internet Explorer Bugs in 'BGSOUND' and 'IFRAME' Tags Let Remote Users Create HTML That Will Cause Denial of Service Conditions or Will Access Special DOS Devices
11882| [1004083] Microsoft Windows 2000 'microsoft-ds' Service Flaw Allows Remote Users to Create Denial of Service Conditions By Sending Malformed Packets
11883| [1004032] Microsoft Internet Information Server (IIS) FTP STAT Command Bug Lets Remote Users Crash Both the FTP and the Web Services
11884| [1004031] Microsoft Internet Information Server (IIS) URL Length Bug Lets Remote Users Crash the Web Service
11885| [1003744] Microsoft SQL Server 'xp_dirtree' Buffer Overflow Lets Users Crash the Database Service
11886| [1003688] Microsoft Exchange Server 2000 Command Processing Bug Lets Remote Users Cause the SMTP Service to Crash
11887| [1003687] Microsoft Windows 2000 and Windows XP SMTP Service Command Processing Bug Lets Remote Users Cause the SMTP Service to Crash
11888| [1003686] Microsoft Windows SMTP Service Lets Remote Users Send or Relay Unauthorized Mail (including SPAM) Via the Server
11889| [1003634] Microsoft XML Core Services in SQL Server 2000 Lets Remote Scripts Access and Send Local Files
11890| [1003633] Microsoft XML Core Services in Microsoft Windows XP Operating System Lets Remote Scripts Access and Send Local Files
11891| [1003415] Microsoft Distributed Transaction Coordinator (MSDTC) Service Can Be Crashed By Remote Users
11892| [1003201] Microsoft Windows 95 Backup Utility Has Buffer Overflow That Could Cause Denial of Service Conditions
11893| [1003033] Microsoft C Runtime Format String Flaw Lets Remote Users Crash the Microsoft SQL Server Service
11894| [1002922] Microsoft Windows 2000 Internet Key Exchange (IKE) Service Can Be Crashed By Remote Users
11895| [1002731] Microsoft Windows 2000 RunAs Service May Disclose Authentication Credentials to Local Users
11896| [1002729] Microsoft Windows 2000 RunAs Service Allows Local Users to Disable the Service
11897| [1002728] Microsoft SQL Server May Disclose Database Passwords When Creating Data Transformation Service (DTS) Packages
11898| [1002581] Microsoft Terminal Servers Can Be Crashed By Remote Users Sending Certain Remote Desktop Protocol (RDP) Packets
11899| [1002394] Microsoft Windows NT Remote Procedure Call (RPC) Services Can Be Crashed With Malformed Packets
11900| [1002201] Microsoft Windows TCP/IP Stack Vulnerable to a Certain Man-in-the-Middle Denial of Service Attack
11901| [1002197] Microsoft Windows NNTP Network News Service Has a Memory Leak That Allows Remote Users to Cause the Server to Crash
11902| [1002105] Microsoft SQL Database Server RPC Input Validation Failure Lets Remote Users Crash the Database Service
11903| [1002104] Microsoft Exchange Server RPC Input Validation Failure Lets Remote Users Crash the Exchange Service
11904| [1002099] Microsoft Windows 2000 Telnet Service Can Be Crashed By Remote Users
11905| [1002075] Microsoft Services for Unix Memory Leak in Telnet and NFS Services Allows Remote Users to Crash the Operating System
11906| [1002028] Microsoft Exchange LDAP Service Can Be Crashed By Remote Users
11907| [1001931] Microsoft Windows 2000 SMTP Service May Allow Unauthorized Remote Users to Relay E-mail via the Service
11908| [1001537] Microsoft's Internet Information Server's FTP Services May Give Remote Users Information About User Account Names on the Server's Domain and Trusted Domains
11909| [1001535] Microsoft's Internet Information Server's FTP Services Can Be Crashed By Remote Users
11910| [1001513] Microsoft Windows 2000 Indexing Service Allows Remote Users to View Include Programming Files
11911| [1001123] Microsoft's FTP Server May Allow Remote Users to Deny Service on the Server
11912| [1001088] Microsoft Internet Explorer with Services for Unix 2.0 Can Create Malicious Files on the User's Host
11913|
11914| OSVDB - http://www.osvdb.org:
11915| [83751] Microsoft Windows Terminal Services LCA Issued Certificates Arbitrary Binary Signing Weakness
11916| [82693] Microsoft Windows Terminal Server Licensing Service MD5 Hash Collision Code Signing Spoofing
11917| [60368] Microsoft Windows Terminal Services msgina.dll Unrestricted Resource Lock Remote DoS
11918| [59733] Microsoft Windows 2000 Terminal Services Screensaver Screen Minimization Locking Weakness
11919| [59730] Microsoft Windows 2000 Terminal Services Disconnect Feature Local Privilege Escalation
11920| [56912] Microsoft Windows Terminal Services Client ActiveX Unspecified Overflow
11921| [36146] Microsoft Windows Terminal Services TLS Downgrade Weakness
11922| [29351] Microsoft Windows Terminal Services tsuserex.dll COM Object Instantiation
11923| [20001] Microsoft Windows 2000 Terminal Service Client Connection IP Logging Failure
11924| [15340] Microsoft Windows Server 2003 Terminal Service Client Print DoS
11925| [4877] Microsoft Windows Terminal Services Kerberos Double Authorization Data Entry
11926| [1990] Microsoft Windows Terminal Services False IP Address
11927| [1975] Microsoft Windows Terminal Server Service RDP Remote DoS
11928| [96181] Microsoft Active Directory Federation Services (AD FS) Open Endpoint Unspecified Account Information Disclosure
11929| [88964] Microsoft .NET Framework System.DirectoryServices.Protocols.SortRequestControl.GetValue() Method this.keys.Length Parameter Heap Buffer Overflow
11930| [88959] Microsoft XML Core Services Integer Truncation XML Handling Memory Corruption
11931| [88958] Microsoft XML Core Services Unspecified XSLT Handling Memory Corruption
11932| [88956] Microsoft Windows Printer Spooler Service Print Job Handling Memory Corruption
11933| [85418] Microsoft Windows Share Service File Handle Request Saturation Remote DoS
11934| [84602] Microsoft Windows Remote Desktop Services Malformed RDP Packet Parsing Remote Code Execution
11935| [84599] Microsoft Windows Print Spooler Service Remote Format String
11936| [83169] Microsoft Windows NT telnetd Service Port Scan Remote DoS
11937| [83126] Microsoft Windows NT Registry Plaintext Service Password Local Disclosure
11938| [82873] Microsoft XML Core Services Uninitalized Memory Object Handling Remote Code Execution
11939| [81903] Microsoft Office X for Macintosh Registration Service Remote Overflow DoS
11940| [80004] Microsoft Windows Remote Desktop Protocol Terminal Server RDP Packet Parsing Remote DoS
11941| [79442] Microsoft Windows Server 2008 DNS Server Service Cache Update Policy Deleted Domain Name Resolving Weakness
11942| [74402] Microsoft Windows Remote Access Service NDISTAPI Driver User Input Validation Weakness Local Privilege Escalation
11943| [74400] Microsoft Windows DNS Service Non-Existent Domain Query Parsing Remote DoS
11944| [74399] Microsoft Windows DNS Service NAPTR Query Parsing Overflow
11945| [72937] Microsoft Windows Active Directory Certificate Services Web Enrollment XSS
11946| [72936] Microsoft Windows Server Service Crafted SMB Request Parsing Remote DoS
11947| [72234] Microsoft Windows WINS Service Failed Response Data Reuse Memory Corruption Remote Code Execution
11948| [71780] Microsoft Windows DNS Client Service LLMNR Query Processing Remote Code Execution
11949| [70834] Microsoft Windows Kerberos Unkeyed Checksum Hashing Mechanism Service Ticket Forgery
11950| [69819] Microsoft Windows Netlogon RPC Service Crafted Request Remote DoS
11951| [68550] Microsoft Windows Media Player Network Sharing Service RTSP Use-after-free Remote Code Execution
11952| [67988] Microsoft Windows Print Spooler Service RPC Impersonation StartDocPrinter Procedure Remote Code Execution
11953| [67083] Microsoft Windows TAPI Server (TAPISRV) Service Isolation Bypass Local Privilege Escalation
11954| [66978] Microsoft Windows Tracing Feature for Services Registry String Handling Memory Corruption Local Privilege Escalation
11955| [66977] Microsoft Windows Tracing Feature for Services Registry Key ACL Local Privilege Escalation
11956| [66973] Microsoft XML Core Services Msxml2.XMLHTTP.3.0 ActiveX HTTP Response Handling Memory Corruption
11957| [63726] Microsoft Windows Media Unicast Service Transport Packet Handling Remote Overflow
11958| [60836] Microsoft Windows Active Directory Federation Services (ADFS) Request Header Handling Remote Code Execution
11959| [60835] Microsoft Windows Active Directory Federation Services (ADFS) Single Sign-on Spoofing
11960| [60833] Microsoft Windows Internet Authentication Service Crafted MS-CHAP v2 Message Remote Authentication Bypass
11961| [60832] Microsoft Windows Internet Authentication Service Protected Extensible Authentication Protocol (PEAP) Message Handling Remote Memory Corruption
11962| [59865] Microsoft Windows Web Services on Devices API (WSDAPI) Message Header Handling Memory Corruption
11963| [59479] Microsoft Office SharePoint Server Team Services _layouts/download.aspx Multiple Parameter ASP.NET Source Disclosure
11964| [58854] Microsoft Windows Indexing Service ActiveX Memory Corruption Arbitrary Code Execution
11965| [57806] Microsoft Windows Wireless LAN AutoConfig Service (wlansvc) Frame Parsing Arbitrary Code Execution
11966| [56902] Microsoft Windows Workstation Service NetrGetJoinInformation Function Local Memory Corruption Arbitrary Code Execution
11967| [56901] Microsoft Windows Message Queuing Service (MSMQ) mqac.sys IOCTL Request Parsing Local Privilege Escalation
11968| [56900] Microsoft Windows Internet Name Service (WINS) Network Packet Handling Remote Integer Overflow
11969| [56899] Microsoft Windows Internet Name Service (WINS) Push Request Handling Remote Overflow
11970| [56438] Microsoft XML Core Services Set-Cookie HTTP Response Header Restriction Weakness
11971| [53667] Microsoft Windows RPCSS Service Isolation Local Privilege Escalation
11972| [53666] Microsoft Windows Management Instrumentation (WMI) Service Isolation Local Privilege Escalation
11973| [53621] Microsoft Windows HTTP Services Digital Certificate Distinguished Name Mismatch Weakness
11974| [53620] Microsoft Windows HTTP Services Web Server Response Unspecified Integer Underflow
11975| [53619] Microsoft Windows HTTP Services NTLM Credential Replay Privileged Code Execution
11976| [52693] Microsoft Windows Mobile Bluetooth Stack OBEX FTP Service Traversal Arbitrary File Manipulation
11977| [50558] Microsoft Windows Media Component Service Principal Name (SPN) Credential Reflection Arbitrary Code Execution
11978| [50533] Microsoft Windows Media Services nskey.dll ActiveX CallHTMLHelp Method Overflow
11979| [50279] Microsoft XML Core Services HTTP Request Header Field Cross-domain Session State Manipulation
11980| [49926] Microsoft XML Core Services DTD Crafted XML Document Handling Cross-Domain Scripting Remote Information Disclosure
11981| [49729] Microsoft Internet Authentication Service (IAS) Helper COM Component ActiveX (iashlpr.dll) PutProperty Method Remote DoS
11982| [49243] Microsoft Windows Server Service Crafted RPC Request Handling Unspecified Remote Code Execution
11983| [49060] Microsoft Windows Message Queuing Service RPC Request Handling Remote Code Execution
11984| [49059] Microsoft IIS IPP Service Unspecified Remote Overflow
11985| [46063] Microsoft Windows Internet Name Service (WINS) Packet Handling Local Privilege Escalation
11986| [45027] Microsoft Malware Protection Engine File Parsing Service DoS
11987| [41092] Microsoft Windows DNS Service Predictable Transaction ID Weakness
11988| [36935] Microsoft Windows Services for UNIX Local Privilege Escalation
11989| [36394] Microsoft XML Core Services (MSXML) Multiple Object Handling Overflow
11990| [35961] Microsoft Windows Active Directory LDAP Service Crafted Request Remote DoS
11991| [35960] Microsoft Windows Active Directory LDAP Service Convertible Attribute Remote Code Execution
11992| [35956] Microsoft .NET Framework Just In Time (JIT) Compiler Service Unspecified Arbitrary Code Execution
11993| [35954] Microsoft .NET Framework PE Loader Service Unspecified Arbitrary Code Execution
11994| [34404] Microsoft IE Media Service Component Arbitrary File Rewrite
11995| [32445] Microsoft Windows Workstation Service NetrWkstaUserEnum RPC Request DoS
11996| [31889] Microsoft Windows XP SP2 Image Aquisition Service Local Privilege Escalation
11997| [30817] Microsoft Windows Remote Installation Service TFTP Arbitrary File Overwrite
11998| [30811] Microsoft Windows SNMP Service Remote Overflow
11999| [30263] Microsoft Windows Workstation Service Crafted Message Remote Overflow
12000| [30261] Microsoft Windows Client Service for NetWare (CSNW) Crafted Message Remote DoS
12001| [30260] Microsoft Windows Client Service for NetWare (CSNW) Crafted Message Remote Code Execution
12002| [29439] Microsoft Windows Server Service Crafted SMB Packet Unspecified Issue
12003| [29426] Microsoft XML Core Services XSLT Processing Overflow
12004| [29425] Microsoft XML Core Services XMLHTTP ActiveX Control Server-side Redirect Information Disclosure
12005| [29412] Microsoft Terminal Server Explorer Error Arbitrary Code Execution
12006| [28729] Microsoft Windows Indexing Service Unspecified XSS
12007| [27845] Microsoft Windows Server Service Crafted RPC Message Remote Overflow
12008| [27844] Microsoft Windows DNS Client Service Record Response Overflow
12009| [27155] Microsoft Windows Server Service SRV.SYS Crafted Request SMB Information Disclosure
12010| [27154] Microsoft Windows Server Service SRV.SYS First-class Mailslot Message Remote Overflow
12011| [27151] Microsoft Windows DHCP Client Service Crafted Response Overflow
12012| [23134] Microsoft Windows Web Client Service Crafted WebDAV Request Overflow
12013| [23047] Microsoft Windows SSDP SERVICE_CHANGE_CONFIG Permission Weakness Privilege Escalation
12014| [23046] Microsoft Windows SCardSvr SERVICE_CHANGE_CONFIG Permission Weakness Privilege Escalation
12015| [23045] Microsoft Windows NetBT SERVICE_CHANGE_CONFIG Permission Weakness Privilege Escalation
12016| [23044] Microsoft Windows UPnP SERVICE_CHANGE_CONFIG Permission Weakness Privilege Escalation
12017| [19994] Microsoft Windows 2000 audit directory service access 565 Event Logging Failure
12018| [19922] Microsoft Windows Client Service for NetWare (CSNW) Remote Overflow
12019| [18607] Microsoft Windows Print Spooler Service Remote Overflow
12020| [18605] Microsoft Windows Plug-and-Play Service Remote Overflow
12021| [17885] Microsoft Windows Network Connections Service netman.dll Remote DoS
12022| [17859] Microsoft Windows NULL Session svcctl MSRPC Interface SCM Service Enumeration
12023| [15338] Microsoft Windows Server 2003 Terminal Session Close DoS
12024| [14509] Microsoft Services for Unix Malformed RPC Client Fragment Packet DoS
12025| [14497] Microsoft Services for Unix RPC Library Malformed Packet Fragment DoS
12026| [14430] Microsoft Commerce Server 2000 Profile Service Affected API Overflow
12027| [13762] Microsoft 2000 Domain Controller Directory Service Restore Mode Blank Password
12028| [13599] Microsoft Windows License Logging Service Overflow
12029| [13595] Microsoft Windows Sharepoint Services HTML Redirection XSS
12030| [13475] Microsoft Windows 2000 Telnet Service Predictable Named Pipe Arbitrary Command Execution Variant
12031| [13474] Microsoft Windows 2000 Telnet Service Predictable Named Pipe Arbitrary Command Execution
12032| [13472] Microsoft Services for Unix Telnet Service Memory Consumption DoS
12033| [13471] Microsoft Services for Unix NFS Service Memory Consumption DoS
12034| [13423] Microsoft Windows 2000 Terminal Server SYSVOL Share Connection Saturation Restriction Bypass
12035| [13422] Microsoft Windows PPTP Service Malformed Control Data Overflow
12036| [12832] Microsoft Windows Indexing Service Query Overflow
12037| [12374] Microsoft Windows HyperTerminal Session File Remote Overflow
12038| [11797] Microsoft Windows DCOM RPCSS Service DCERPC Packet Overflow
12039| [11473] Microsoft Windows NT Messenger Service Long Username DoS
12040| [11461] Microsoft Windows Workstation Service WKSSVC.DLL Logging Function Remote Overflow
12041| [11268] Microsoft Exchange Internet Mail Service AUTH/AUTHINFO Command DoS
12042| [11157] Microsoft IIS FTP Service PASV Connection Saturation DoS
12043| [10936] Microsoft Windows Messenger Service Message Length Remote Overflow
12044| [10247] Microsoft Windows SMTP Service NTLM Null Session Mail Relay
12045| [9856] Xylogics Annex Terminal Service ping CGI Program DoS
12046| [7905] Microsoft IE ie5setup.exe Multple Service Disable
12047| [7881] Microsoft Java Implementation INativeServices Clipboard Content Disclosure
12048| [7880] Microsoft Java INativeServices Arbitrary Memory Information Disclosure
12049| [7182] Microsoft Windows Media Unicast Service Severed Connection Memory Leak DoS
12050| [5936] Microsoft SMTP Service 4xx Error Code DoS
12051| [5686] Microsoft Windows Telnet Service Account Information Disclosure
12052| [5133] Microsoft Metadirectory Services LDAP Client Authentication Bypass
12053| [4578] Microsoft SQL Resolution Service Monitor Thread Registry Key Name Overflow
12054| [4577] Microsoft SQL Resolution Service 0x08 Byte Long String Overflow
12055| [4535] Microsoft Media Services ISAPI nsiislog.dll POST Overflow
12056| [4170] Microsoft Windows 2000 Server Media Services TCP Packet Handling Remote DoS
12057| [2960] Microsoft Windows Messenger Service Social Engineering Weakness
12058| [2657] Microsoft Windows Message Queuing Service Heap Overflow
12059| [2535] Microsoft Windows DCOM RPCSS Service Filename Parameter Overflow
12060| [2247] Microsoft Windows Media Services Remote Command Execution #2
12061| [2106] Microsoft Media Services ISAPI nsiislog.dll Overflow
12062| [1933] Microsoft ISA Server Proxy Service Memory Leak DoS
12063| [1912] Microsoft Windows Terminal Server Malformed RDP DoS
12064| [1860] Microsoft Windows Telnet Service Handle Leak DoS
12065| [1858] Microsoft Windows Telnet Service Logon Backspace DoS
12066| [1639] Microsoft Windows NT Terminal Server RegAPI.DLL Username Overflow
12067| [1621] Microsoft Indexing Services for Windows 2000 .htw XSS
12068| [1546] Microsoft Windows Media Unicast Service Malformed Request DoS
12069| [1268] Microsoft Windows TCP/IP Printing Service DoS
12070| [1209] Microsoft Terminal Server rdisk Registry Information Disclosure
12071| [1135] Microsoft Windows NT Print Spooler Service (spoolss.exe) AddPrintProvider() Function Alternate Print Provider Arbitrary Command Execution
12072| [967] Microsoft Windows NT WINS Service Malformed Data DoS
12073| [878] Microsoft SQL Resolution Service Keep-Alive Function DoS
12074| [732] Microsoft Windows SMTP Service Malformed BDAT Request Remote DoS
12075| [463] Microsoft IIS Phone Book Service /pbserver/pbserver.dll Remote Overflow
12076| [403] Microsoft Windows 2000 Still Image Service WM_USER Message Local Overflow
12077| [304] Microsoft Windows NT service pack level via remote registry access
12078|_
12079Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
12080OS fingerprint not ideal because: Timing level 5 (Insane) used
12081No OS matches for host
12082Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows
12083
12084TRACEROUTE (using port 3389/tcp)
12085HOP RTT ADDRESS
120861 165.48 ms 10.250.200.1
120872 166.62 ms 213.184.122.97
120883 165.55 ms bzq-82-80-246-9.cablep.bezeqint.net (82.80.246.9)
120894 227.46 ms bzq-219-189-185.cablep.bezeqint.net (62.219.189.185)
120905 166.11 ms bzq-219-189-2.cablep.bezeqint.net (62.219.189.2)
120916 224.73 ms bzq-179-72-241.cust.bezeqint.net (212.179.72.241)
120927 225.54 ms bzq-219-189-73.cablep.bezeqint.net (62.219.189.73)
120938 220.73 ms ae9.cr1-lon2.ip4.gtt.net (46.33.89.185)
120949 295.75 ms 52.93.1.91
1209510 292.78 ms et-10-3-0.cr4-nyc2.ip4.gtt.net (213.254.214.10)
1209611 288.35 ms 52.93.1.42
1209712 288.32 ms 52.93.1.44
1209813 ... 17
1209918 297.81 ms 54.239.46.227
1210019 ... 26
1210127 293.17 ms 52.93.28.152
1210228 ... 30
12103####################################################################################################
12104Starting Nmap 7.70 ( https://nmap.org ) at 2019-07-26 01:01 EDT
12105NSE: Loaded 45 scripts for scanning.
12106NSE: Script Pre-scanning.
12107NSE: Starting runlevel 1 (of 2) scan.
12108Initiating NSE at 01:01
12109Completed NSE at 01:01, 0.00s elapsed
12110NSE: Starting runlevel 2 (of 2) scan.
12111Initiating NSE at 01:01
12112Completed NSE at 01:01, 0.00s elapsed
12113Initiating Ping Scan at 01:01
12114Scanning 52.44.246.60 [4 ports]
12115Completed Ping Scan at 01:01, 0.35s elapsed (1 total hosts)
12116Initiating Parallel DNS resolution of 1 host. at 01:01
12117Completed Parallel DNS resolution of 1 host. at 01:01, 0.03s elapsed
12118Initiating Connect Scan at 01:01
12119Scanning ec2-52-44-246-60.compute-1.amazonaws.com (52.44.246.60) [65535 ports]
12120Discovered open port 3389/tcp on 52.44.246.60
12121Discovered open port 80/tcp on 52.44.246.60
12122Discovered open port 443/tcp on 52.44.246.60
12123Connect Scan Timing: About 5.16% done; ETC: 01:11 (0:09:30 remaining)
12124Connect Scan Timing: About 15.62% done; ETC: 01:07 (0:05:29 remaining)
12125Connect Scan Timing: About 28.89% done; ETC: 01:06 (0:03:44 remaining)
12126Connect Scan Timing: About 44.42% done; ETC: 01:05 (0:02:31 remaining)
12127Connect Scan Timing: About 61.76% done; ETC: 01:05 (0:01:34 remaining)
12128Connect Scan Timing: About 81.11% done; ETC: 01:04 (0:00:42 remaining)
12129Completed Connect Scan at 01:04, 208.05s elapsed (65535 total ports)
12130Initiating Service scan at 01:04
12131Scanning 3 services on ec2-52-44-246-60.compute-1.amazonaws.com (52.44.246.60)
12132Completed Service scan at 01:04, 17.21s elapsed (3 services on 1 host)
12133Initiating OS detection (try #1) against ec2-52-44-246-60.compute-1.amazonaws.com (52.44.246.60)
12134Retrying OS detection (try #2) against ec2-52-44-246-60.compute-1.amazonaws.com (52.44.246.60)
12135Initiating Traceroute at 01:04
12136Completed Traceroute at 01:05, 6.31s elapsed
12137Initiating Parallel DNS resolution of 14 hosts. at 01:05
12138Completed Parallel DNS resolution of 14 hosts. at 01:05, 0.31s elapsed
12139NSE: Script scanning 52.44.246.60.
12140NSE: Starting runlevel 1 (of 2) scan.
12141Initiating NSE at 01:05
12142Completed NSE at 01:05, 18.91s elapsed
12143NSE: Starting runlevel 2 (of 2) scan.
12144Initiating NSE at 01:05
12145Completed NSE at 01:05, 0.00s elapsed
12146Nmap scan report for ec2-52-44-246-60.compute-1.amazonaws.com (52.44.246.60)
12147Host is up, received syn-ack ttl 113 (0.26s latency).
12148Scanned at 2019-07-26 01:01:06 EDT for 258s
12149Not shown: 65529 filtered ports
12150Reason: 65529 no-responses
12151PORT STATE SERVICE REASON VERSION
1215225/tcp closed smtp conn-refused
1215380/tcp open http syn-ack Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
12154|_http-server-header: Microsoft-HTTPAPI/2.0
12155| vulscan: VulDB - https://vuldb.com:
12156| [131683] Microsoft Windows 7 SP1/Server 2008 SP2/Server 2008 R2 SP1 Win32k memory corruption
12157| [131642] Microsoft Windows 7 SP1/Server 2008 SP2/Server 2008 R2 SP1 Active Directory privilege escalation
12158| [127822] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2012 Kernel information disclosure
12159| [125103] Microsoft Windows Server 2008 SP2 Graphics Component information disclosure
12160| [123853] Microsoft Windows 7 SP1/Server 2008 SP2/Server 2008 R2 SP1 Kernel Memory information disclosure
12161| [122858] Microsoft Windows 7 SP1/Server 2008 SP2/Server 2008 R2 SP1 LNK memory corruption
12162| [122833] Microsoft Windows 7 SP1/Server 2008 SP2/Server 2008 R2 SP1 GDI+ memory corruption
12163| [121109] Microsoft Wireless Display Adapter V2 2.0.8350/2.0.8365/2.0.8372 privilege escalation
12164| [120449] Microsoft Forefront Unified Access Gateway 2000 InitParams.aspx Parameter Server-Side Request Forgery
12165| [119469] Microsoft Windows 7 SP1/Server 2008 SP2/Server 2008 R2 SP1 Kernel privilege escalation
12166| [116015] Microsoft Excel 2007 SP3/2010 SP2/2013 SP1/2013 RT SP1 memory corruption
12167| [114563] Microsoft Office 2007 SP3/2010 SP2/2013/2013 RT SP1 memory corruption
12168| [114528] Microsoft Windows 7 SP1/Server 2008 SP2/Server 2008 R2 SP1 GDI privilege escalation
12169| [114524] Microsoft ASP.NET Core 2.0 denial of service
12170| [114523] Microsoft ASP.NET Core 2.0 Kestrel Web Application privilege escalation
12171| [113257] Microsoft Windows 7 SP1/Server 2008 SP2/Server 2012 Kernel information disclosure
12172| [113256] Microsoft Windows 7 SP1/Server 2008 SP2/Server 2012 Kernel information disclosure
12173| [113255] Microsoft Windows 7 SP1/Server 2008 SP2/Server 2012 Kernel information disclosure
12174| [113247] Microsoft Windows 7 SP1/Server 2008 R2 SP1 EOT Font Engine information disclosure
12175| [113246] Microsoft Windows 7 SP1/Server 2008 R2 SP1 EOT Font Engine information disclosure
12176| [113245] Microsoft Windows 7 SP1/Server 2008 R2 SP1/Server 2012 EOT Font Engine information disclosure
12177| [113244] Microsoft Windows 7 SP1/Server 2008 R2 SP1 EOT Font Engine information disclosure
12178| [113235] Microsoft Outlook 2007 SP3/2010 SP2/2013 SP1/2016 privilege escalation
12179| [113234] Microsoft Office 2007 SP2/2010 SP2/2013 SP1/2013 RT SP1/2016 memory corruption
12180| [113216] Microsoft Outlook 2007 SP3/2010 SP2/2013 SP1/2013 RT SP1/2016 memory corruption
12181| [112285] Microsoft Word 2003/2007/2010/2013/2016 Equation Editor memory corruption
12182| [112284] Microsoft Word 2003/2007/2010/2013/2016 Equation Editor memory corruption
12183| [112283] Microsoft Word 2003/2007/2010/2013/2016 Equation Editor memory corruption
12184| [112282] Microsoft Word 2003/2007/2010/2013/2016 Equation Editor memory corruption
12185| [111578] Microsoft Word 2003/2007/2010/2013/2016 Equation Editor memory corruption
12186| [111577] Microsoft Word 2003/2007/2010/2013/2016 Equation Editor memory corruption
12187| [111576] Microsoft Word 2003/2007/2010/2013/2016 Equation Editor memory corruption
12188| [111575] Microsoft Word 2003/2007/2010/2013/2016 Equation Editor memory corruption
12189| [111574] Microsoft Word 2003/2007/2010/2013/2016 Equation Editor memory corruption
12190| [111573] Microsoft Office 2007/2010/2013/2016 Equation Editor memory corruption
12191| [111572] Microsoft Office 2007/2010/2013/2016 Equation Editor memory corruption
12192| [111570] Microsoft Office 2007/2010/2013/2016 Equation Editor memory corruption
12193| [111568] Microsoft Excel 2007/2010/2013/2016 memory corruption
12194| [111566] Microsoft Word 2007/2010/2013/2016 memory corruption
12195| [111565] Microsoft Word 2007/2010/2013 Email Message memory corruption
12196| [111563] Microsoft Outlook 2007/2010/2013/2016 Email Message privilege escalation
12197| [111347] Microsoft Windows 7 SP1/Server 2008 SP2/Server 2008 R2 SP1 Color Management Icm32.dll information disclosure
12198| [109388] Microsoft Office 2007 SP3/2010 SP2/2013 SP1/2016 memory corruption
12199| [109387] Microsoft ASP.NET Core 2.0 privilege escalation
12200| [109386] Microsoft Excel 2007 SP3/2010 SP2/2013 SP1/2013 RT SP1/2016 memory corruption
12201| [109385] Microsoft Excel 2007 SP3/2010 SP2/2013 SP1/2013 RT SP1/2016 Security Feature Macro privilege escalation
12202| [109381] Microsoft Office/Word 2007 SP3/2010 SP2 memory corruption
12203| [107703] Microsoft Office 2007 SP3/2010 SP2/2013 SP1/2013 RT SP1/2016 memory corruption
12204| [106530] Microsoft Excel 2007 SP3/2010 SP2/2013 SP1/2013 RT SP1/2016 memory corruption
12205| [106528] Microsoft PowerPoint 2007 SP3/2010 SP2/2013 SP1/2013 RT SP1/2016 memory corruption
12206| [106515] Microsoft Publisher 2007 SP3/2010 SP2 memory corruption
12207| [106497] Microsoft Windows 7 SP1/Server 2008 SP2/Server 2008 R2 SP1 Uniscribe memory corruption
12208| [106476] Microsoft Excel 2007 SP3/2010 SP2/2013 SP1/2013 RT SP1/2016 memory corruption
12209| [106475] Microsoft Excel 2007 SP3/2010 SP2/2013 SP1/2013 RT SP1/2016 memory corruption
12210| [105051] Microsoft Windows 7 SP1/Server 2008 SP2/Server 2008 R2 SP1 Font Library privilege escalation
12211| [105032] Microsoft Internet Explorer 9/10 on Server 2008/Server 2012 memory corruption
12212| [102513] Microsoft Windows XP SP3/Server 2003 SP2 OLE olecnv32.dll privilege escalation
12213| [102512] Microsoft Windows XP SP3/Server 2003 SP2 rpc privilege escalation
12214| [102511] Microsoft Windows XP SP3/Server 2003 SP2 RDP EsteemAudit privilege escalation
12215| [102447] Microsoft PowerPoint/SharePoint Server 2007 SP3 privilege escalation
12216| [102444] Microsoft Office 2007 SP3/2010 SP2/2013 SP1/2013 RT SP1/2016 privilege escalation
12217| [102442] Microsoft Outlook 2007 SP3/2010 SP2/2013 SP1/2013 RT SP1/2016 Bypass privilege escalation
12218| [102441] Microsoft Outlook 2007 SP3/2010 SP2/2013 SP1/2013 RT SP1/2016 memory corruption
12219| [102401] Microsoft Windows 7 SP1/Server 2008 R2 SP1 GDI USP10!NextCharInLiga Uniscribe Font information disclosure
12220| [101491] Microsoft Windows up to XP SP3/Server 2003 SP2 Remote Desktop Protocol gpkcsp.dll memory corruption
12221| [101017] Microsoft Office 2007 SP3/2010 SP2/2016 memory corruption
12222| [101012] Microsoft Office 2007 SP3/2010 SP2/2011/2013 SP1/2016 memory corruption
12223| [101011] Microsoft Windows 7 SP1/Server 2008 SP2/Server 2008 R2 SP1 ActiveX Object Memory memory corruption
12224| [100854] Microsoft Windows Server 2003 SP2 RRAS ERRATICGOPHER memory corruption
12225| [99904] Microsoft Windows XP SP3/Server 2003 SP2 SmartCard Authentication RDP Packet EsteemAudit privilege escalation
12226| [99698] Microsoft OneNote 2007 SP3/2010 SP2 DLL Loader privilege escalation
12227| [99684] Microsoft Excel 2007 SP3/2010 SP2 Memory information disclosure
12228| [99654] Microsoft Outlook 2007 SP3/2010 SP2/2011/2013 SP1/2016 Email Message privilege escalation
12229| [99653] Microsoft Outlook 2007 SP3/2010 SP2/2011/2013 SP1/2016 Email Message privilege escalation
12230| [99533] Microsoft Office 2007/2010/2013/2016 RTF Document Necurs Dridex memory corruption
12231| [98561] Microsoft IIS 6.0 on Windows Server 2003 WebDAV ScStoragePathFromUrl Long Header memory corruption
12232| [98092] Microsoft SharePoint Server 2007 SP3 memory corruption
12233| [98088] Microsoft SharePoint Server 2007 SP3 memory corruption
12234| [98087] Microsoft Office 2007 SP3/2010 SP2 memory corruption
12235| [98086] Microsoft Office 2007 SP3/2010 SP2/2013 SP1/2013 RT SP1/2016 memory corruption
12236| [98085] Microsoft Excel 2007 SP3 memory corruption
12237| [98084] Microsoft Word 2007 SP3/2010 SP2/2011 memory corruption
12238| [98083] Microsoft Word 2007 SP3/2010 SP2/2011 memory corruption
12239| [98078] Microsoft Word/Excel 2007 SP3 memory corruption
12240| [98072] Microsoft Office 2007 SP3/2010 SP2/Word Viewer Graphics Component privilege escalation
12241| [98071] Microsoft Office 2007 SP3/2010 SP2/Word Viewer GDI+ information disclosure
12242| [98070] Microsoft Office 2007 SP3/2010 SP2/Word Viewer GDI+ information disclosure
12243| [94450] Microsoft Office 2007 SP3/2010 SP2/2011 memory corruption
12244| [94449] Microsoft Office 2007 SP3/2010 SP2/2011/2013 SP1 information disclosure
12245| [94448] Microsoft Office 2007 SP3/2010 SP2/2011/2013 SP1 information disclosure
12246| [94445] Microsoft Office 2007 SP3/2010 SP2/2013 SP1/2013 RT SP1 information disclosure
12247| [94441] Microsoft Office 2007 SP3/2010 SP2/2013 SP1/2013 RT SP1/2016 privilege escalation
12248| [94440] Microsoft Office 2007 SP3/2010 SP2/2013 SP1/2013 RT SP1/2016 memory corruption
12249| [94439] Microsoft Office 2007 SP3/2011 privilege escalation
12250| [94438] Microsoft Office 2007 SP3/2010 SP2/2013 SP1/2013 RT SP1/2016 privilege escalation
12251| [93542] Microsoft Office 2007 SP3/2010 SP2/2013 SP1/2013 RT SP1 memory corruption
12252| [93541] Microsoft Office 2007 SP3 denial of service
12253| [93539] Microsoft Office 2007/2010 SP2/2011 memory corruption
12254| [93538] Microsoft Office 2007/2010 SP2/2011/2013 SP1 memory corruption
12255| [93537] Microsoft Office 2007/2010 SP2/2011 memory corruption
12256| [93396] Microsoft Office 2007/2010/2011 memory corruption
12257| [93395] Microsoft Office 2007/2010/2011 memory corruption
12258| [93394] Microsoft Office 2007/2010 memory corruption
12259| [92596] Microsoft Windows Vista SP2/7 SP1/Server 2008 SP2/Server 2008 R2 Internet Messaging API File information disclosure
12260| [91554] Microsoft Exchange 2007/2010/2013/2016 Email information disclosure
12261| [91553] Microsoft Office 2007/2010/2013/2013 RT/2016 memory corruption
12262| [91552] Microsoft Office 2007/2010/2013/2013 RT/2016 spoofing
12263| [91551] Microsoft Office 2007/2010/2013/2013 RT/2016 memory corruption
12264| [91549] Microsoft Office 2007/2010/2013/2013 RT/2016 memory corruption
12265| [91548] Microsoft Office 2007/2010/2013/2013 RT/2016 memory corruption
12266| [91546] Microsoft Office 2007/2010/2013/2013 RT memory corruption
12267| [91545] Microsoft Office 2007/2010 memory corruption
12268| [91544] Microsoft Office 2007/2010/2013/2013 RT/2016 memory corruption
12269| [91542] Microsoft Office 2007/2010/2013/2013 RT/2016 information disclosure
12270| [90707] Microsoft OneNote 2007/2010/2013/2013 RT/2016 information disclosure
12271| [90706] Microsoft Office 2007/2010/2013/2013 RT Graphics memory corruption
12272| [90705] Microsoft Office 2007/2010/2011 memory corruption
12273| [90703] Microsoft Office 2007/2010/2013/2013 RT/2016 memory corruption
12274| [89039] Microsoft Office 2007 SP3/2010 SP2/2011/2013 SP1/2013 RT SP1 memory corruption
12275| [89034] Microsoft Windows Vista SP2/Server 2008 JScript/VBScript memory corruption
12276| [87960] Microsoft Windows Server 2008 R2/Server 2012/Server 2012 R2 Active Directory denial of service
12277| [87955] Microsoft Exchange 2007/2010/2013/2016 Oracle Outside In Libraries privilege escalation
12278| [87954] Microsoft Exchange 2007/2010/2013/2016 Oracle Outside In Libraries privilege escalation
12279| [87953] Microsoft Exchange 2007/2010/2013/2016 Oracle Outside In Libraries privilege escalation
12280| [87939] Microsoft Office 2007 SP3/2010 SP2/2013 SP1/2013 RT SP1/2016 OLE DLL memory corruption
12281| [87938] Microsoft Office 2007 SP3/2010 SP2/2011 information disclosure
12282| [87937] Microsoft Office 2007 SP3/2010 SP2/2011 memory corruption
12283| [87935] Microsoft Windows Vista SP2/Server 2008 SP2/Server 2008 R2 SP1 VBScript/JScript memory corruption
12284| [87934] Microsoft Windows Vista SP2/Server 2008 SP2/Server 2008 R2 SP1 VBScript/JScript memory corruption
12285| [87933] Microsoft Windows Vista SP2/Server 2008 SP2/Server 2008 R2 SP1 VBScript/JScript memory corruption
12286| [87147] Microsoft Office 2007/2010 memory corruption
12287| [87145] Microsoft Windows Vista SP2/Server 2008 JScript/VBScript memory corruption
12288| [87144] Microsoft Windows Vista SP2/Server 2008 JScript/VBScript memory corruption
12289| [82228] Microsoft Excel 2007 SP3/2010 SP2 Office Document memory corruption
12290| [82225] Microsoft Word 2007 SP3/2010 SP2/2013 SP1/2013 RT SP1 Office Document memory corruption
12291| [82224] Microsoft Excel 2007 SP3/2010 SP2/2013 SP1/2013 RT SP1/2016 Office Document memory corruption
12292| [81273] Microsoft Office 2007/2010/2013/2016 memory corruption
12293| [81272] Microsoft Office 2007/2010/2013 memory corruption
12294| [81265] Microsoft Windows Vista SP2/Server 2008 Library Loader memory corruption
12295| [80872] Microsoft Office 2007 SP3/2010 SP2/2013 SP1/2013 RT SP1/2016 memory corruption
12296| [80871] Microsoft Office 2007 SP3/2010 SP2/2013 SP1/2013 RT SP1/2016 memory corruption
12297| [80869] Microsoft Office 2007 SP3/2010 SP2/2013 SP1/2013 RT SP1/2016 memory corruption
12298| [79506] Microsoft Windows Vista/7/Server 2008/Server 2008 R2 Library Loader memory corruption
12299| [79505] Microsoft Office 2007 memory corruption
12300| [79504] Microsoft Office 2007/2010/2013/2016 memory corruption
12301| [79503] Microsoft Office 2007/2010/2013 memory corruption
12302| [79502] Microsoft Office 2007/2010/2011 memory corruption
12303| [79501] Microsoft Office 2007/2010 memory corruption
12304| [79499] Microsoft Windows 7/Server 2008 R2 Uniscribe memory corruption
12305| [79493] Microsoft Windows Vista/Server 2008 Graphics memory corruption
12306| [79190] Microsoft Word 2007 SP3/2010 SP2/2013 SP1/2013 RT SP1/2016 Office Document memory corruption
12307| [79189] Microsoft Office 2007 SP3/2010 SP2/2013 SP1/2013 RT SP1/2016 Office Document memory corruption
12308| [79187] Microsoft Office 2007 SP3/2010 SP2/2013 SP1/2016 Sandbox privilege escalation
12309| [79167] Microsoft Windows Vista/7/Server 2008/Server 2008 R2 Journal memory corruption
12310| [78372] Microsoft Visio 2007 SP3/2010 SP2 UML Data memory corruption
12311| [78371] Microsoft SharePoint Server 2007 SP3/2010 SP2 InfoPath Forms Services XXE information disclosure
12312| [77646] Microsoft Office 2007 SP3/2010 SP2/2013 SP1/2013 RT SP1 EPS Image memory corruption
12313| [77629] Microsoft Excel 2007 SP3/2010 SP2/2011/2016 Office Document memory corruption
12314| [77627] Microsoft Excel 2007 SP3/2010 SP2 Office Document memory corruption
12315| [77626] Microsoft Excel 2007 SP3/2010 SP2/2011/2016 Office Document memory corruption
12316| [77617] Microsoft Office 2007 SP3/2010 SP2 OpenType Font memory corruption
12317| [77252] Microsoft Office 2007 SP3/2010 SP2 Office Graphics Library Font memory corruption
12318| [77038] Microsoft Windows Server 2008 SP2 UDDI Services cross site scripting
12319| [76497] Microsoft PowerPoint 2007 SP3/2010 SP2/2013 SP1 Office Document memory corruption
12320| [76491] Microsoft Excel 2007 SP3/2010 SP2/2013 SP1/2013 RT SP1 Office Document memory corruption
12321| [76467] Microsoft Word 2007 SP3/2010 SP2/2011/2013 SP1/2013 RT SP1 Office Document memory corruption
12322| [76466] Microsoft Word 2007 SP3/2010 SP2/2011/2013 SP1/2013 RT SP1 Office Document memory corruption
12323| [76464] Microsoft Excel 2007 SP3/2010 SP2/2013 SP1/2013 RT SP1 Office Document memory corruption
12324| [76463] Microsoft Excel 2007 SP3/2010 SP2/2011/2013 SP1/2013 RT SP1 Office Document memory corruption
12325| [76449] Microsoft Windows 8/8.1/Server 2008/Server 2012/Server 2012 R2 Hyper-V memory corruption
12326| [76440] Microsoft SQL Server 2008/2008 R2/2012/2014 Virtual Function Uninitialized Memory memory corruption
12327| [76439] Microsoft SQL Server 2008/2008 R2/2012/2014 Uninitialized Memory memory corruption
12328| [76438] Microsoft SQL Server 2008/2008 R2/2012/2014 Pointer Casting privilege escalation
12329| [75783] Microsoft Windows Server 2008/Server 2012 Active Directory Federation Services cross site scripting
12330| [75338] Microsoft SharePoint 2007/2010/2013 Content privilege escalation
12331| [75337] Microsoft Office 2007 SP3/2010 SP2/2011/2013 SP1/2013 RT SP1 memory corruption
12332| [75336] Microsoft Office 2007 SP3/2010 SP2/2011/2013 SP1/2013 RT SP1 memory corruption
12333| [74845] Microsoft Office 2007/2010/2013 Document Use-After-Free memory corruption
12334| [74844] Microsoft Office 2007/2010 Document Use-After-Free memory corruption
12335| [74837] Microsoft Office 2007/2010/2011/2013 RTF Document Use-After-Free privilege escalation
12336| [73979] Microsoft Exchange Server 2003 SP1/2003 CU7 Meeting privilege escalation
12337| [73978] Microsoft Exchange Server 2003 SP1/2003 CU7 cross site scripting
12338| [73977] Microsoft Exchange Server 2003 SP1/2003 CU7 cross site scripting
12339| [73976] Microsoft Exchange Server 2003 SP1/2003 CU7 cross site scripting
12340| [73975] Microsoft Exchange Server 2003 SP1/2003 CU7 cross site scripting
12341| [73964] Microsoft SharePoint 2007/2010/2013 cross site scripting
12342| [69158] Microsoft Office 2007/2010/2013 Use-After-Free memory corruption
12343| [69157] Microsoft Office 2007/2010/2013 OneTableDocumentStream memory corruption
12344| [69155] Microsoft Excel 2007/2010/2013/- Object memory corruption
12345| [68416] Microsoft Exchange 2007/2010/2013 Outlook Web Access Token spoofing
12346| [68409] Microsoft Office 2007/2010/2013 Use-After-Free memory corruption
12347| [68408] Microsoft Excel 2007/2010/2013 memory corruption
12348| [68407] Microsoft Excel 2007/2010 memory corruption
12349| [68405] Microsoft Word 2007/2010 Index Use-After-Free memory corruption
12350| [68195] Microsoft Windows Vista/7/Server 2003/Server 2008 Input Method Editor Sandbox privilege escalation
12351| [68189] Microsoft Windows Server 2003 SP2 TCP/IP Stack Stack-Based memory corruption
12352| [68188] Microsoft Word 2007 File memory corruption
12353| [68187] Microsoft Word 2007 File memory corruption
12354| [68186] Microsoft Word 2007 File memory corruption
12355| [67829] Microsoft Office 2007/2010/2011 Object memory corruption
12356| [67825] Microsoft .NET Framework 2.0/3.5/3.5.1 ASLR privilege escalation
12357| [71337] Microsoft Office 2000/2004/XP memory corruption
12358| [67355] Microsoft OneNote 2007 File Processing privilege escalation
12359| [67354] Microsoft SQL Server 2008 SP3/2008 R2 SP2/2012 SP1/2014 SQL Master Data Services cross site scripting
12360| [67353] Microsoft SQL Server 2008 SP3/2008 R2 SP2/2012 SP1/2014 T-SQL Query Stack-Based memory corruption
12361| [67018] Microsoft Windows Server 2008/Server 2012/Server 2012 R2 Service Bus AMQP Message denial of service
12362| [13545] Microsoft Word 2007 Embedded Font memory corruption
12363| [13397] Microsoft Windows XP/2000/Server 2003 DHCP Response DHCP ACK spoofing
12364| [13462] Microsoft Visual Studio 2002/2003/2005/2010 Debug Interface msdia.dll PDB File memory corruption
12365| [13229] Microsoft Office 2007/2010/2013 Common Control Library MSCOMCTL.OCX privilege escalation
12366| [13227] Microsoft Office 2007/2010/2013 Chinese Grammar Checker Library privilege escalation
12367| [13226] Microsoft SharePoint Server 2007/2010/2013 Page memory corruption
12368| [13225] Microsoft SharePoint Server 2007/2010/2013 cross site scripting
12369| [13224] Microsoft SharePoint Server 2007/2010/2013 Page memory corruption
12370| [12859] Microsoft Word 2003 Office Document Stack-Based memory corruption
12371| [12852] Microsoft Publisher 2003/2007 Publisher File pubconv.dll memory corruption
12372| [12845] Microsoft Word 2003 Office File Stack-Based memory corruption
12373| [12844] Microsoft Word 2007/2010 Office File memory corruption
12374| [12843] Microsoft Office 2007/2010/2011/2013 XML Parser Nested Entities Memory Consumption denial of service
12375| [12687] Microsoft Word/Office/Outlook 2003/2007/2010/2013 RTF Document memory corruption
12376| [12530] Microsoft Windows XP/Vista/Server 2003/Server 2008/Server 2012 Security Account Manager Lockout privilege escalation
12377| [12266] Microsoft .NET Framework 2.0 SP2/3.5.1 ASLR Bypass privilege escalation
12378| [12070] Apple Pages 2.0/2.0.1/2.0.2/5.0/5.0.1 on Mac Microsoft Word Document memory corruption
12379| [11950] Microsoft Office Compability Pack/Word 2007 SP3 File memory corruption
12380| [11949] Microsoft Word Viewer/Office Compatibility Pack/Word 2003 SP3/2007 SP3 File memory corruption
12381| [11448] Microsoft Office 2007/2010 Address Space Layout Randomization privilege escalation
12382| [11151] Microsoft Outlook 2007/2010/2013/- S/MIME Certificate Metadata Expansion memory corruption
12383| [11149] Microsoft Office 2003/2007/2010/2013/- WordPerfect Document epsimp32.flt memory corruption
12384| [11148] Microsoft Office 2003/2007 WordPerfect Document epsimp32.flt memory corruption
12385| [11146] Microsoft Office 2003/2007 epsimp32.flt memory corruption
12386| [11230] Microsoft Word 2003 DOC Document Embedded Image denial of service
12387| [11081] Microsoft Windows Vista/Server 2008 TIFF Image memory corruption
12388| [10648] Microsoft Word 2007 Word File memory corruption
12389| [10647] Microsoft Word 2003 Word File memory corruption
12390| [10643] Microsoft SharePoint Server 2007/2010/2013 Input Sanitizer memory corruption
12391| [10642] Microsoft SharePoint Server 2007/2010 Content Display in Frames privilege escalation
12392| [10247] Microsoft SharePoint Server 2007/2010/2013 Online Cloud cross site scripting
12393| [10245] Microsoft Office 2003/2007/2010 Word File memory corruption
12394| [10244] Microsoft Office 2003 SP3 Word File memory corruption
12395| [10243] Microsoft Office 2003/2007 Word File memory corruption
12396| [10242] Microsoft Office 2007 Word File memory corruption
12397| [10241] Microsoft Office 2007 Word File memory corruption
12398| [10240] Microsoft Office 2003/2007/2010 Word File memory corruption
12399| [10239] Microsoft Office 2003/2007 Word File memory corruption
12400| [10238] Microsoft Excel 2003/2007 XML External Entity Data information disclosure
12401| [10237] Microsoft Excel 2003/2007/2010 XML External Entity Data information disclosure
12402| [10236] Microsoft Word/Office 2003/2007 XML External Entity Data information disclosure
12403| [10234] Microsoft Word/Sharepoint 2003 SP3/2007 SP3/2010 SP1 Office File memory corruption
12404| [10232] Microsoft Word/Sharepoint 2003 SP3/2007 SP3/2010 SP1 Office File memory corruption
12405| [10231] Microsoft Word/Sharepoint 2003 SP3/2007 SP3/2010 SP1 Office File memory corruption
12406| [10230] Microsoft Word/Sharepoint 2003 SP3/2007 SP3/2010 SP1 Office File memory corruption
12407| [10229] Microsoft Access 2007/2010/2013 Access File ACCDB File memory corruption
12408| [10228] Microsoft Access 2007/2010/2013 Access File ACCDB File memory corruption
12409| [10227] Microsoft Access 2007/2010/2013 Access File ACCDB File memory corruption
12410| [10192] Microsoft Windows XP SP3/Vista/7/2000/Server 2003 SP2 Windows Theme File privilege escalation
12411| [10191] Microsoft Windows XP/Server 2003 OLE Object privilege escalation
12412| [10190] Microsoft Windows Vista/7/8/Server 2008 Active Directory denial of service
12413| [10189] Microsoft Outlook 2007/2010 S/MIME privilege escalation
12414| [9941] Microsoft Windows XP/Server 2003 Unicode Scripts Processor USP10.DLL Uniscribe Font memory corruption
12415| [9929] Microsoft Windows Server 2008/Server 2012 Active Directory Federation Services Unspecified Account information disclosure
12416| [9715] Microsoft PowerPoint 2007 DirectShow Runtime quartz.dll GetMaxSampleSize denial of service
12417| [9397] Microsoft .NET Framework 2.0 SP2/3.5/3.5.1/4/4.5 Array privilege escalation
12418| [9394] Microsoft .NET Framework 2.0 SP2/3.5/3.5.1/4/4.5 on 64-bit Array memory corruption
12419| [9393] Microsoft .NET Framework 2.0 SP2/3.5/3.5.1/4/4.5 Permission privilege escalation
12420| [8738] Microsoft Visio 2003 SP3/2007 SP3/2010 SP1 XML Parser File information disclosure
12421| [8737] Microsoft Word 2003 SP3 Shape Data Parser File memory corruption
12422| [8736] Microsoft Publisher 2003 SP3 PUB File memory corruption
12423| [8735] Microsoft Publisher 2003 SP3/2007 SP3/2010 SP1 PUB File memory corruption
12424| [8734] Microsoft Publisher 2003 SP3 PUB File memory corruption
12425| [8733] Microsoft Publisher 2003 SP3 PUB File memory corruption
12426| [8732] Microsoft Publisher 2003 SP3 PUB File memory corruption
12427| [8731] Microsoft Publisher 2003 SP3 PUB File memory corruption
12428| [8730] Microsoft Publisher 2003 SP3 PUB File memory corruption
12429| [8729] Microsoft Publisher 2003 SP3 PUB File memory corruption
12430| [8728] Microsoft Publisher 2003 SP3 PUB File memory corruption
12431| [8727] Microsoft Publisher 2003 SP3 PUB File memory corruption
12432| [8726] Microsoft Publisher 2003 PUB File Eingabe memory corruption
12433| [8723] Microsoft .NET Framework 2.0 SP2/3.5/3.5.1/4/4.5 XML File spoofing
12434| [7643] Microsoft Windows Server 2008 R2/Server 2012 NFS Server NULL Pointer Dereference denial of service
12435| [7642] Microsoft Exchange 2007/2010 Outlook Web Access vspdx.dll) privilege escalation
12436| [7641] Microsoft Windows XP/Vista/Server 2003/Server 2008 DirectShow Quartz.dll memory corruption
12437| [8589] Microsoft System Center Operations Manager 2007 SP1/2007 R2 ViewTypeManager.aspx cross site scripting
12438| [7252] Microsoft System Center Operations Manager 2007 ExecuteTask.aspx cross site scripting
12439| [7251] Microsoft System Center Operations Manager 2007 cross site scripting
12440| [7248] Microsoft Windows 7/Server 2008 R2 Print Spooler privilege escalation
12441| [7121] Microsoft Exchange 2007/2010 RSS Feed denial of service
12442| [7118] Microsoft Windows Server 2008 R2/Server 2012 IP-HTTPS unknown vulnerability
12443| [62914] Microsoft Office 2003 SP3/2007 SP3/2008/2010 SP1/2011 Spreadsheet Use-After-Free memory corruption
12444| [7058] Microsoft Windows 7/Server 2008 R2 DHCPv6 Message denial of service
12445| [6935] Microsoft Office Excel 2003/2007/2010 Input Sanitizer File Stack-based memory corruption
12446| [6934] Microsoft Office Excel 2003/2007/2010 Input Sanitizer memory corruption
12447| [6933] Microsoft Office Excel 2003/2007/2010 SerAuxErrBar File memory corruption
12448| [6929] Microsoft .NET Framework 2.0 SP2/3.5/3.5.1/4/4.5 Web Proxy Setting Auto-Discovery memory corruption
12449| [6927] Microsoft .NET Framework 2.0 SP2/3.5.1 Trusted Code Function information disclosure
12450| [6918] Microsoft Excel 2007 SP2 Input Sanitizer File memory corruption
12451| [6830] Microsoft Word 2007/2010 File memory corruption
12452| [6819] Microsoft Excel 2007 File memory corruption
12453| [6627] Microsoft Windows 7/Server 2008 R2 Kerberos denial of service
12454| [6626] Microsoft SharePoint/Lync/Infopath 2007/2010 HTML Sanitization cross site scripting
12455| [6622] Microsoft Word 2003/2007/2010/- RTF Document memory corruption
12456| [6621] Microsoft Word 2007 PAPX memory corruption
12457| [62239] Microsoft Systems Management Server 2003 Configuration Manager Reflected cross site scripting
12458| [5945] Microsoft Office 2007/2010 Computer Graphics Metafile memory corruption
12459| [5939] Microsoft Windows XP/Vista/7/Server 2003/Server 2008 R2 Print Spooler Service memory corruption
12460| [5938] Microsoft Windows XP/Vista/7/Server 2003/Server 2008 R2 Remote Administration Protocol netapi32.dll RAP Request denial of service
12461| [5933] Microsoft SQL Server 2000/2005/2008/2008 R2 Common Controls TabStrip ActiveX MSCOMCTL.OCX memory corruption
12462| [5932] Microsoft Office 2003/2007/2010 Common Controls TabStrip ActiveX MSCOMCTL.OCX memory corruption
12463| [5654] Microsoft Windows XP/Vista/7/Server 2003/Server 2008 information disclosure
12464| [5653] Microsoft Windows XP/Vista/7/Server 2003/Server 2008 win32k.sys memory corruption
12465| [5652] Microsoft Windows XP/Vista/7/Server 2003/Server 2008 win32k.sys memory corruption
12466| [5650] Microsoft Windows XP/Vista/7/Server 2003/Server 2008 memory corruption
12467| [5649] Microsoft Office 2003/2007/2010 libraries memory corruption
12468| [5645] Microsoft SharePoint 2007/2010/3.0 Reflected cross site scripting
12469| [5643] Microsoft SharePoint 2007/2010 information disclosure
12470| [5642] Microsoft SharePoint 2007 cross site request forgery
12471| [5553] Microsoft Windows XP/Vista/7/Server 2003/Server 2008 OpenType Font atmfd.dll denial of service
12472| [5524] Microsoft Windows XP/Vista/7/Server 2003/Server 2008 memory corruption
12473| [5518] Microsoft .NET Framework 2.0 SP2/3.5/3.5.1/4/4.5 memory corruption
12474| [5362] Microsoft Office 2003/2007 GDI+ memory corruption
12475| [5291] Microsoft Visual Studio 2008 Incremental Linker link.exe ConvertRgImgSymToRgImgSymEx memory corruption
12476| [5268] Microsoft Office 2008 on Mac RTF Pfragment File memory corruption
12477| [5080] Microsoft SQL Server 2005/2008/2008R2 CREATE DATABASE sql injection
12478| [5050] Microsoft Office 2007 WPS Converter Heap-based memory corruption
12479| [5049] Microsoft SQL Server 2000/2005/2008 MSCOMCTL.OCX privilege escalation
12480| [5048] Microsoft Office 2003/2007/2010 MSCOMCTL.OCX privilege escalation
12481| [5046] Microsoft Windows XP/Vista/7/Server 2003/Server 2008 Windows Authenticode Signature Verification WinVerifyTrust Signature privilege escalation
12482| [4803] Microsoft Windows Server 2003/Server 2008 DNS Server Domain Resource Record Query Parser denial of service
12483| [4802] Microsoft Windows XP/Vista/7/Server 2003/Server 2008 Remote Desktop Protocol denial of service
12484| [4798] Microsoft Windows XP/Vista/7/Server 2003/Server 2008 Remote Desktop Service memory corruption
12485| [60205] Microsoft .NET Framework 2.0 SP2/3.5.1 Heap-based memory corruption
12486| [4642] Microsoft .NET Framework 2.0 SP2/3.5.1/4 XAML Browser Application memory corruption
12487| [60065] Microsoft Windows 2000 mod_sql unknown vulnerability
12488| [4535] Microsoft Windows XP/Server 2003 Object Packager packager.exe privilege escalation
12489| [4534] Microsoft Windows XP/Vista/7/Server 2003/Server 2008 Line21 DirectShow Filter Quartz.dll/Qdvd.dll Media File memory corruption
12490| [4533] Microsoft Windows XP/Vista/7/Server 2003/Server 2008 Multimedia Library winmm.dll MIDI File memory corruption
12491| [4507] Microsoft .NET Framework 2.0 SP2/3.5 SP1/3.5.1/4.0 Forms Authentication Redirect
12492| [59666] Microsoft Publisher 2003/2007 "Publisher memory corruption
12493| [4482] Microsoft Word 2007/2010/2011 Document Parser memory corruption
12494| [4480] Microsoft Excel 2003 memory corruption
12495| [4478] Microsoft Windows XP/Server 2003 OLE Objects Memory Management memory corruption
12496| [4477] Microsoft PowerPoint 2007 OfficeArt Use-After-Free memory corruption
12497| [4474] Microsoft Windows XP/Vista/7/Server 2003/Server 2008 Active Directory Query memory corruption
12498| [4473] Microsoft Powerpoint 2007/2010 DLL-Loader memory corruption
12499| [4471] Microsoft Office 2003/2007 Publisher Out-of-Bounds memory corruption
12500| [4470] Microsoft Office 2003 SP3 memory corruption
12501| [4453] Microsoft Excel 2003 Record Parser memory corruption
12502| [4446] Microsoft Office 2008/2007 OfficeArt Record Parser memory corruption
12503| [4445] Microsoft Office 2007/2010/2011 Word Document Parser memory corruption
12504| [4438] Microsoft Windows Vista/7/Server 2008 TCP/IP Reference Counter denial of service
12505| [5358] Microsoft Windows XP/Vista/7/Server 2003/Server 2008 TrueType Font Handling memory corruption
12506| [59005] Microsoft Host Integration Server 2004 denial of service
12507| [58492] Microsoft SharePoint Server 2007 Spreadsheet memory corruption
12508| [58491] Microsoft Office 2004/2007/2008/2010/2011 Spreadsheet memory corruption
12509| [58490] Microsoft Office Compatibility Pack 2007 Spreadsheet memory corruption
12510| [58489] Microsoft Office 2004/2007/2008/2010/2011 Spreadsheet memory corruption
12511| [58488] Microsoft Office 2007/2010 memory corruption
12512| [4412] Microsoft Office 2003/2007 Library Loader Designfehler
12513| [4411] Microsoft Excel 2003 memory corruption
12514| [4409] Microsoft Windows Server 2003/Server 2008 WINS unknown vulnerability
12515| [58240] Microsoft Visio 2003/2007 memory corruption
12516| [58237] Microsoft Visio 2003/2007/2010 memory corruption
12517| [4396] Microsoft Windows Vista/7/Server 2008 TCP/IP Stack denial of service
12518| [4393] Microsoft Windows Server 2008 DNS Service memory corruption
12519| [4391] Microsoft .NET Framework 2.0 SP2/3.5.1/4 Socket Restriction privilege escalation
12520| [4390] Microsoft Windows Server 2008 Remote Desktop Web Access cross site scripting
12521| [4388] Microsoft Windows Vista/7/Server 2008 File Metadata Parser denial of service
12522| [57691] Microsoft SQL Server 2008 Web Service information disclosure
12523| [57690] Microsoft Excel 2002/2003 Spreadsheet memory corruption
12524| [57689] Microsoft Excel 2002 Spreadsheet memory corruption
12525| [57688] Microsoft Excel 2002 Spreadsheet memory corruption
12526| [57687] Microsoft Excel 2002/2003/2007 Spreadsheet memory corruption
12527| [57686] Microsoft Excel 2002 Spreadsheet memory corruption
12528| [57685] Microsoft Excel 2002/2003/2007 Array Access memory corruption
12529| [57684] Microsoft Excel 2002/2003/2007/2010 Spreadsheet memory corruption
12530| [4369] Microsoft Excel 2002/2003/2007 memory corruption
12531| [4367] Microsoft Windows Server 2008 Hyper-V VMBus denial of service
12532| [4362] Microsoft Windows Vista/7/Server 2008 denial of service
12533| [57420] Microsoft PowerPoint 2002/2003 memory corruption
12534| [4349] Microsoft Office 2004/2008/2007 Presentation File Parser memory corruption
12535| [4348] Microsoft Powerpoint 2002/2003/2007 memory corruption
12536| [57077] Microsoft Excel 2002 Uninitialized Memory memory corruption
12537| [57078] Microsoft Office 2003/2007/Xp docx unknown vulnerability
12538| [57079] Microsoft PowerPoint 2002/2003/2007/2010 memory corruption
12539| [57076] Microsoft Excel 2002/2003 memory corruption
12540| [57075] Microsoft Excel 2002/2003 memory corruption
12541| [57074] Microsoft Excel 2002 memory corruption
12542| [57073] Microsoft Excel 2002/2003/2007/2010 memory corruption
12543| [4334] Microsoft .NET Framework 2.0 SP2/3.5 SP1/3.5.1/4.0 JIT Compiler memory corruption
12544| [4301] Microsoft Windows Server 2003 SMB Browser Heap-based denial of service
12545| [56475] Microsoft Office 2004/2008 memory corruption
12546| [56414] Microsoft Visio 2002/2003/2007 ELEMENTS.DLL memory corruption
12547| [56413] Microsoft Visio 2002/2003/2007 Exception ORMELEMS.DLL memory corruption
12548| [4298] Microsoft Windows 7/Server 2008 JScript/VBScript Engine information disclosure
12549| [4297] Microsoft Windows XP/Vista/7/Server 2003/Server 2008 OpenType Compact Font Format Driver privilege escalation
12550| [4296] Microsoft Windows XP/Server 2003 LSASS Authentication Request unknown vulnerability
12551| [4295] Microsoft Windows 7/Server 2008 Kerberos weak authentication
12552| [4294] Microsoft Windows XP/Vista/7/Server 2003/Server 2008 Driver win32k.sys unknown vulnerability
12553| [4293] Microsoft Windows XP/Server 2003 Kerberos CRC32 Checksum privilege escalation
12554| [4292] Microsoft Windows XP/Server 2003 CSRSS Logoff privilege escalation
12555| [4289] Microsoft Excel 2007 Shape Data Parser memory corruption
12556| [4286] Microsoft Powerpoint 2007 OfficeArt Container Parser memory corruption
12557| [4279] Microsoft Windows XP/Vista/7/Server 2003/Server 2008 MHTML cross site scripting
12558| [56176] Microsoft Windows XP/7/Server 2003 fxscover.exe CDrawPoly::Serialize memory corruption
12559| [55772] Microsoft Publisher 2002 pubconv.dll memory corruption
12560| [55771] Microsoft Publisher 2002/2003/2010 memory corruption
12561| [55765] Microsoft Office 2003/Xp Integer memory corruption
12562| [55764] Microsoft Office 2003/Xp memory corruption
12563| [55750] Microsoft Publisher 2002/2003 pubconv.dll memory corruption
12564| [55749] Microsoft Publisher 2002/2003/2007/2010 pubconv.dll memory corruption
12565| [55748] Microsoft Publisher 2002/2003/2007 pubconv.dll memory corruption
12566| [4230] Microsoft Exchange 2007 on 64-bit RPC store.exe MAPI Request denial of service
12567| [4229] Microsoft SharePoint 2007 Document Conversion Launcher Service Eingabeung\xC3\xBCltigkeit
12568| [4228] Microsoft Windows Server 2008 Hyper-V VMBus denial of service
12569| [4224] Microsoft Windows Vista/7/Server 2008 Consent User Interface privilege escalation
12570| [4231] Microsoft Windows XP/Vista/7/Server 2003/Server 2008 Driver win32k.sys GreEnableEUDC denial of service
12571| [55420] Microsoft Office 2007/2010 memory corruption
12572| [55419] Microsoft Office 2004/2008/2011/Xp memory corruption
12573| [55412] Microsoft PowerPoint Viewer 2007 memory corruption
12574| [55411] Microsoft PowerPoint 2002/2003 memory corruption
12575| [4204] Microsoft Windows Server 2008 Color Control Panel Eingabeung\xC3\xBCltigkeit
12576| [54995] Microsoft Office 2004/2008 memory corruption
12577| [54994] Microsoft Office 2004/2008 Out-of-Bounds memory corruption
12578| [54993] Microsoft Office Compatibility Pack 2007 memory corruption
12579| [54992] Microsoft Excel 2002 memory corruption
12580| [54991] Microsoft Office 2004 Future memory corruption
12581| [54990] Microsoft Office 2004 memory corruption
12582| [54989] Microsoft Office 2004/2008 memory corruption
12583| [54988] Microsoft Excel 2002 memory corruption
12584| [54987] Microsoft Excel 2002 memory corruption
12585| [54986] Microsoft Excel 2002/2003 memory corruption
12586| [54985] Microsoft Office Compatibility Pack 2003/2004/2007/2008 memory corruption
12587| [54984] Microsoft Office 2004/2008 memory corruption
12588| [54983] Microsoft Excel 2002 Integer memory corruption
12589| [54980] Microsoft Word 2002/2003 memory corruption
12590| [54979] Microsoft Word 2002 memory corruption
12591| [54978] Microsoft Word 2002 memory corruption
12592| [54977] Microsoft Word 2002 Heap-based memory corruption
12593| [54976] Microsoft Word 2002 memory corruption
12594| [54975] Microsoft Word 2002 memory corruption
12595| [54974] Microsoft Word 2002 memory corruption
12596| [54973] Microsoft Word 2002 memory corruption
12597| [54972] Microsoft Word 2002 memory corruption
12598| [54971] Microsoft Word 2002 memory corruption
12599| [4197] Microsoft SharePoint 2007/3.0 cross site scripting
12600| [4196] Microsoft Word 2002/2003/2007/2010 Stack-based memory corruption
12601| [4194] Microsoft Windows Vista/7/Server 2008 SChannel Client Certificate Request denial of service
12602| [54774] Microsoft Word 2003 word_crash_11.8326.8324_poc.doc denial of service
12603| [54757] Microsoft SharePoint Server 2007 HTML Sanitization SafeHTML cross site scripting
12604| [4186] Microsoft Outlook 2002/2003/2007 Content Parser Heap-based memory corruption
12605| [54584] Microsoft Visual C++ 2005 AtlTraceTool8.exe unknown vulnerability
12606| [54554] Microsoft Groove 2007 mso.dll memory corruption
12607| [4187] Microsoft Windows Vista/7/Server 2008 TCP/IP Stack Ipv4SetEchoRequestCreate() denial of service
12608| [54322] Microsoft Word 2002/2003 memory corruption
12609| [54321] Microsoft Office Compatibility Pack 2007 memory corruption
12610| [54320] Microsoft Office Compatibility Pack 2007 memory corruption
12611| [54319] Microsoft Office Compatibility Pack 2007 memory corruption
12612| [54318] Microsoft .NET Framework 2.0 SP1/2.0 SP2/3.5/3.5 SP1/3.5.1 Interfaces memory corruption
12613| [4165] Microsoft Windows Vista/7/Server 2008 TCP/IP Stack denial of service
12614| [4162] Microsoft Windows Vista/7/Server 2008 Kernel memory corruption
12615| [4159] Microsoft Excel 2002/2003 SXDB PivotTable Cache Data Record memory corruption
12616| [4149] Microsoft Windows XP/Vista/7/Server 2003/Server 2008 Shell Shortcut Parser memory corruption
12617| [54083] Microsoft Access 2003 ActiveX Control ACCWIZ.dll memory corruption
12618| [4146] Microsoft Outlook 2002/2003/2007 SMB Attachment PR_ATTACH_METHOD memory corruption
12619| [4145] Microsoft Access 2003/2007 ActiveX ACCWIZ.dll memory corruption
12620| [54617] Microsoft Outlook Web Access up to 2007 cross site request forgery
12621| [4151] Microsoft Windows Vista/Server 2008 NtUserCheckAccessForIntegrityLevel memory corruption
12622| [53591] Microsoft Windows Server 2003 GetServerName cross site scripting
12623| [53505] Microsoft Excel 2002/2007 memory corruption
12624| [53501] Microsoft Excel 2002 memory corruption
12625| [53500] Microsoft Excel 2002 memory corruption
12626| [53499] Microsoft Excel 2002 memory corruption
12627| [53495] Microsoft Excel 2002/2003/2007 memory corruption
12628| [53494] Microsoft Excel 2002 Stack-based memory corruption
12629| [53504] Microsoft Excel 2002 memory corruption
12630| [53503] Microsoft Excel 2002 Stack-Based memory corruption
12631| [53502] Microsoft Excel 2002 Heap-based memory corruption
12632| [53498] Microsoft Excel 2002 Stack-based memory corruption
12633| [53497] Microsoft Excel 2002 memory corruption
12634| [53496] Microsoft Excel 2002 memory corruption
12635| [53493] Microsoft Excel 2002/2003/2007 memory corruption
12636| [4133] Microsoft Office 2003/2007/Xp COM Object Instantiator memory corruption
12637| [53366] Microsoft ASP.NET 2.0 cross site scripting
12638| [53385] Microsoft Exchange Server 2007 Outlook Web Access cross site scripting
12639| [53164] Microsoft Office 2003/2007/Xp ActiveX Control VBE6.DLL memory corruption
12640| [53054] Microsoft VISIO 2002/2003/2007 VISIODWG.DLL memory corruption
12641| [4125] Microsoft SharePoint 2007/3.0 help.aspx cross site scripting
12642| [52777] Microsoft Publisher 2002/2003/2007 memory corruption
12643| [52773] Microsoft Visio 2002/2003/2007 memory corruption
12644| [52772] Microsoft Visio 2002/2003/2007 memory corruption
12645| [4107] Microsoft Windows 7/Server 2008 Kernel denial of service
12646| [4103] Microsoft Windows Server 2003 Media Services Stack-based memory corruption
12647| [52543] Microsoft Virtual PC 2007 unknown vulnerability
12648| [52148] Microsoft Office 2004/2008/2007 Uninitialized Memory memory corruption
12649| [52147] Microsoft Office 2004/2008/2007 Spreadsheet Uninitialized Memory memory corruption
12650| [52146] Microsoft Office 2004/2008/2007 Spreadsheet Heap-based memory corruption
12651| [52145] Microsoft Office 2004/2008/2007 Spreadsheet Heap-based memory corruption
12652| [52144] Microsoft Office 2004/2008/2007 Spreadsheet memory corruption
12653| [52143] Microsoft Office 2004/2008/2007 Spreadsheet memory corruption
12654| [4090] Microsoft Excel 2002/2003/2007 memory corruption
12655| [52036] Microsoft Windows 2000 MsgBox memory corruption
12656| [51995] Microsoft SharePoint Server up to 2006 cross site scripting
12657| [51810] Microsoft Office 2004/Xp MSO.DLL memory corruption
12658| [51802] Microsoft PowerPoint 2003 Stack-based memory corruption
12659| [51801] Microsoft PowerPoint 2003 Stack-based memory corruption
12660| [51800] Microsoft PowerPoint 2002/2003 Use-After-Free memory corruption
12661| [51799] Microsoft PowerPoint 2002/2003 memory corruption
12662| [51798] Microsoft PowerPoint 2002/2003 Heap-based memory corruption
12663| [4082] Microsoft Powerpoint 2002 memory corruption
12664| [54550] Microsoft PowerPoint 2007 rpawinet.dll memory corruption
12665| [54556] Microsoft Visio 2003 mfc71enu.dll unknown vulnerability
12666| [51497] Microsoft Windows Live Messenger 2009 ActiveX Control msnmsgr.exe denial of service
12667| [51133] Microsoft Windows 2000 SP4/XP SP2/SP3/Server 2003 SP2 memory corruption
12668| [51074] Microsoft Office 2002/2003 Integer memory corruption
12669| [4069] Microsoft Project 2007/2003 Project Memory Validator memory corruption
12670| [50794] Microsoft Office 2004/2008 Spreadsheet memory corruption
12671| [50793] Microsoft Office 2004/2008 Spreadsheet memory corruption
12672| [50792] Microsoft Office 2004/2008 Spreadsheet memory corruption
12673| [50791] Microsoft Office 2004/2008 Spreadsheet memory corruption
12674| [50790] Microsoft Office 2004/2008 Spreadsheet Heap-based memory corruption
12675| [50788] Microsoft Office 2004/2008 Spreadsheet memory corruption
12676| [50787] Microsoft Office 2004/2008 Spreadsheet memory corruption
12677| [50786] Microsoft Windows 2000 llssrv.exe memory corruption
12678| [50789] Microsoft Office 2004/2008 Spreadsheet memory corruption
12679| [4056] Microsoft Word 2002/2003 File Information Block Parser Stack-based memory corruption
12680| [50660] Microsoft SharePoint Server 2007 unknown vulnerability
12681| [50443] Microsoft Office Powerpoint 2007 Integer memory corruption
12682| [50432] Microsoft .NET Framework 2.0/2.0 SP1/2.0 SP2/3.5/3.5 SP1 memory corruption
12683| [49866] Microsoft Windows Server 2003 memory corruption
12684| [4031] Microsoft Windows Vista/Server 2008 SMB Processor EducatedScholar memory corruption
12685| [4030] Microsoft Windows Vista/Server 2008 Wireless LAN AutoConfig Service Heap-based memory corruption
12686| [4029] Microsoft Windows 2000/XP TCP/IP Window Size denial of service
12687| [49745] Microsoft Windows Server 2003 denial of service
12688| [49394] Microsoft Windows Server 2003 memory corruption
12689| [49198] Microsoft Visual Studio 2005 information disclosure
12690| [49047] Microsoft Virtual Server 2005 privilege escalation
12691| [49046] Microsoft Windows Server 2003 quartz.dll memory corruption
12692| [49045] Microsoft Windows Server 2003 quartz.dll memory corruption
12693| [49044] Microsoft ISA Server 2006 privilege escalation
12694| [3999] Microsoft Office 2007 Pointer memory corruption
12695| [4000] Microsoft Office 2003/Xp/Sp3 Web Components memory corruption
12696| [48894] Microsoft Windows Server 2003 msvidctl.dll memory corruption
12697| [48572] Microsoft Office Powerpoint 2002 FL21WIN.DLL memory corruption
12698| [48517] Microsoft Windows 2000 Memory Leak memory corruption
12699| [48516] Microsoft Windows Server 2008 unknown vulnerability
12700| [48512] Microsoft Windows Server 2008 unknown vulnerability
12701| [48515] Microsoft Office Word Viewer 2003 memory corruption
12702| [48514] Microsoft Office Word Viewer 2003 Stack-based memory corruption
12703| [48554] Microsoft Excel 2000/2003/2007 memory corruption
12704| [48157] Microsoft Office PowerPoint 2002 Sound memory corruption
12705| [48156] Microsoft Office PowerPoint 2000 Stack-based memory corruption
12706| [48154] Microsoft Office PowerPoint 2002 Sound PP7X32.DLL memory corruption
12707| [48152] Microsoft Office PowerPoint 2002 PP4X32.DLL memory corruption
12708| [48150] Microsoft Office PowerPoint 2002 Sound memory corruption
12709| [48147] Microsoft Office PowerPoint 2002 Sound memory corruption
12710| [48146] Microsoft Office PowerPoint 2002 Integer memory corruption
12711| [48155] Microsoft Office PowerPoint 2002 Notes Container Heap-based memory corruption
12712| [48153] Microsoft Office PowerPoint 2002 Sound memory corruption
12713| [48151] Microsoft Office PowerPoint 2002 Stack-based memory corruption
12714| [48149] Microsoft Office PowerPoint 2002 memory corruption
12715| [48148] Microsoft Office PowerPoint 2002 Sound memory corruption
12716| [3974] Microsoft Powerpoint 2000/2002/2003 Sound Data Stack-based memory corruption
12717| [3973] Microsoft Powerpoint 2000/2002/2003 Notes Container Stack-based memory corruption
12718| [3972] Microsoft Powerpoint 2000/2002/2003 BuildList memory corruption
12719| [3971] Microsoft Powerpoint 2000/2002/2003 Object Stack-based memory corruption
12720| [3970] Microsoft Powerpoint 2000/2002/2003 Paragraph Stack-based memory corruption
12721| [3969] Microsoft Powerpoint 2000/2002/2003 Atom Stack-based memory corruption
12722| [47719] Microsoft Windows 2000 Stack-based memory corruption
12723| [47720] Microsoft Internet Security And Acceleration Server 2006 Forms Authentication cookieauth.dll cross site scripting
12724| [47716] Microsoft Office Converter Pack 2003 WPFT632.CNV memory corruption
12725| [47715] Microsoft Windows 2000 Wordpad memory corruption
12726| [47718] Microsoft Excel 2000/2002/2003/2007 Spreadsheet memory corruption
12727| [3960] Microsoft Windows XP/2000/Server 2003 DirectShow MJPEG memory corruption
12728| [3952] Microsoft ISA Server 2004/2006 denial of service
12729| [3946] Microsoft PowerPoint 2004/2000/2002/2003 memory corruption
12730| [47091] Microsoft Windows Server 2008 unknown vulnerability
12731| [47090] Microsoft Windows Server 2008 unknown vulnerability
12732| [3939] Microsoft Windows 2000 DNS Designfehler
12733| [3938] Microsoft Windows 2000 SSL weak authentication
12734| [3937] Microsoft Windows 2000 memory corruption
12735| [3932] Microsoft Excel 2004/2000/2002/2003/2007 Object Reference Designfehler
12736| [46620] Microsoft Windows Live Messenger 2009 msnmsgr.exe denial of service
12737| [46455] Microsoft Exchange Server 2007 denial of service
12738| [46454] Microsoft Exchange Server 2007 memory corruption
12739| [46453] Microsoft Visio 2002/2003/2007 memory corruption
12740| [46452] Microsoft Visio 2002/2003/2007 memory corruption
12741| [46451] Microsoft Visio 2002/2003/2007 memory corruption
12742| [46327] Microsoft Word 2007 information disclosure
12743| [45758] Microsoft Money 2006 ActiveX Control prtstb06.dll denial of service
12744| [45381] Microsoft Windows Vista SP1/Server 2008 Explorer memory corruption
12745| [45380] Microsoft Windows Vista SP1/Server 2008 Search memory corruption
12746| [45379] Microsoft Office SharePoint Server 2007 denial of service
12747| [3896] Microsoft SQL Server up to 2005 sp_replwritetovarbin memory corruption
12748| [3892] Microsoft Excel 2000/2002/2003 Formula memory corruption
12749| [3891] Microsoft Excel 2000/2002/2003 memory corruption
12750| [3890] Microsoft Excel 2000/2002/2003 NAME Index memory corruption
12751| [3889] Microsoft Word 2000/2002/2003/2007 Table Property Stack-based memory corruption
12752| [3888] Microsoft Word 2000/2002/2003/2007 RTF Stylesheet memory corruption
12753| [3887] Microsoft Word 2000/2002/2003/2007 memory corruption
12754| [3886] Microsoft Word 2000/2002/2003/2007 ControlWord Heap-based memory corruption
12755| [3885] Microsoft Word 2000/2002/2003/2007 memory corruption
12756| [3884] Microsoft Word 2000/2002/2003/2007 memory corruption
12757| [3883] Microsoft Word 2000/2002/2003/2007 RTF Heap-based memory corruption
12758| [3882] Microsoft Word 2000/2002/2003/2007 LFO memory corruption
12759| [3880] Microsoft Visual Basic up to 2003 ActiveX Control Mschrt20.ocx memory corruption
12760| [3879] Microsoft Visual Basic up to 2003 ActiveX Control mscomct2.ocx memory corruption
12761| [3878] Microsoft Visual Basic up to 2003 ActiveX Control mshflxgd.ocx memory corruption
12762| [3877] Microsoft Visual Basic up to 2003 ActiveX Control msflxgrd.ocx memory corruption
12763| [3876] Microsoft Visual Basic up to 2003 ActiveX Control msdatgrd.ocx memory corruption
12764| [45197] Microsoft Windows 2000 nskey.dll memory corruption
12765| [45063] Microsoft Windows Server 2003 Active Directory unknown vulnerability
12766| [45040] Microsoft .NET Framework 2.0.50727 Code Access Security unknown vulnerability
12767| [44855] DjVu Activex Control For Microsoft Office 2000 3.0 ActiveX Control DjVu_ActiveX_MSOffice.dll memory corruption
12768| [44665] Microsoft Peachtree Accounting 2004 ActiveX Control PAWWeb11.ocx unknown vulnerability
12769| [44589] Microsoft Exchange Server 2003 Outlook Web Access unknown vulnerability
12770| [3845] Microsoft Windows 2000 SP4 Active Directory memory corruption
12771| [44533] Microsoft Windows 2000 mqsvc.exe memory corruption
12772| [3844] Microsoft Excel 2003 REPT memory corruption
12773| [3843] Microsoft Excel up to 2007 BIFF File Heap-based memory corruption
12774| [3842] Microsoft Excel 2003 VBA Performance Cache Stack-based Eingabeung\xC3\xBCltigkeit
12775| [44405] Microsoft Digital Image 2006 ActiveX Control PipPPush.DLL unknown vulnerability
12776| [44047] Microsoft SQL Server 2000 ActiveX Control SQLVDIRLib.SQLVDirControl memory corruption
12777| [43981] Microsoft Organization Chart 2.00 orgchart.exe memory corruption
12778| [43957] Microsoft Office 2003/2007/Xp gdiplus.dll memory corruption
12779| [43956] Microsoft Office 2003/2007/Xp gdiplus.dll memory corruption
12780| [43955] Microsoft Office 2003/2007/Xp gdiplus.dll memory corruption
12781| [43952] Microsoft Office 2003/2007/Xp URI memory corruption
12782| [43676] Microsoft Windows XP/Vista/2000/Server 2003 memory corruption
12783| [43675] Microsoft Windows XP/Vista/2000/Server 2003 of memory corruption
12784| [43662] Microsoft Office Powerpoint Viewer up to 2003 memory corruption
12785| [43661] Microsoft Office Powerpoint Viewer 2003 memory corruption
12786| [43660] Microsoft Office Powerpoint Viewer 2003 Integer memory corruption
12787| [43657] Microsoft Office 2000/2003/Xp memory corruption
12788| [43654] Microsoft SharePoint Server 2007 memory corruption
12789| [43653] Microsoft Office 2000/2002/2004/2008 memory corruption
12790| [43652] Microsoft Office 2000/2002/2003/2004/2008 memory corruption
12791| [3797] Microsoft Windows Vista/Server 2008 IPsec Policy Designfehler
12792| [3796] Microsoft Office 2000 WPG memory corruption
12793| [3795] Microsoft Office 2000/2003/Xp BMP Image BMPIMP32.FLT memory corruption
12794| [3794] Microsoft Office 2000/2003/Xp PICT bits_per_pixel memory corruption
12795| [3793] Microsoft Office 2000/2003/Xp PICT memory corruption
12796| [3792] Microsoft Office 2000 EPS File memory corruption
12797| [3783] Microsoft Word 2002 memory corruption
12798| [43103] Microsoft Exchange Srv 2007 Sp1 Outlook Web Access cross site scripting
12799| [43102] Microsoft Windows 2000 SP4/Server 2003 SP2/Server 2008 DNS Cache privilege escalation
12800| [3778] Microsoft Exchange 2003/2007 Outlook Web Access cross site scripting
12801| [3777] Microsoft Windows Vista SP1/Server 2008 Explorer memory corruption
12802| [43087] Microsoft Office Snapshot Viewer ActiveX up to Office 2003 Snapshot Viewer ActiveX Control snapview.ocx memory corruption
12803| [43096] Microsoft Publisher 2003/2007 Crypto API unknown vulnerability
12804| [42816] Microsoft Word 2000/2003 memory corruption
12805| [42732] Microsoft Windows XP/Vista/Server 2003 denial of service
12806| [42731] Microsoft Windows Server 2003 denial of service
12807| [3732] Microsoft Windows 2000/Server 2003 WINS memory corruption
12808| [3701] Microsoft Word 2003 CSS Heap-based memory corruption
12809| [3700] Microsoft Word 2003 RTF Document Heap-based memory corruption
12810| [42065] Microsoft SharePoint Server 2.0 Rich Text Editor cross site scripting
12811| [41881] Microsoft Office 2003/2007/2007 Sp1/Xp memory corruption
12812| [41880] Microsoft Project 2000/2002/2003 memory corruption
12813| [41879] Microsoft Windows 2000/Server 2003/Vista Stack-based memory corruption
12814| [41878] Microsoft Windows 2000/Server 2003/Vista spoofing
12815| [41877] Microsoft Windows Server 2003 vbscript.dll memory corruption
12816| [3671] Microsoft Visio 2002/2003/2003 Sp3/2007/2007 Sp1 memory corruption
12817| [3670] Microsoft Visio 2002/2003/2003 Sp3/2007/2007 Sp1 Object memory corruption
12818| [41455] Microsoft Office 2000/2003/2004/Xp memory corruption
12819| [41454] Microsoft Excel 2000/2002/2003/2007 memory corruption
12820| [41453] Microsoft Excel 2000/2002/2003 memory corruption
12821| [41452] Microsoft Excel 2000/2002/2003/2007 memory corruption
12822| [41451] Microsoft Excel 2000/2002/2003 memory corruption
12823| [41450] Microsoft Excel 2000 memory corruption
12824| [41449] Microsoft Excel 2000/2002/2003 memory corruption
12825| [41448] Microsoft Office 2000/Xp Office Web Components memory corruption
12826| [3648] Microsoft Excel 2003 memory corruption
12827| [3647] Microsoft Outlook up to 2007 mailto URI memory corruption
12828| [41003] Microsoft Office 2000/2003/2004/Xp memory corruption
12829| [41002] Microsoft Office 2000/2003/Xp memory corruption
12830| [41001] Microsoft Works 2005/8.0 wkcvqd01.dll memory corruption
12831| [41000] Microsoft Works 2005/8.0 memory corruption
12832| [40998] Microsoft Publisher 2000/2002/2003 memory corruption
12833| [40994] Microsoft Works 2005/8.0 wkcvqd01.dll memory corruption
12834| [40987] Microsoft Windows 2000 denial of service
12835| [40736] Microsoft ActiveX 2.0 ActiveX Control privilege escalation
12836| [3552] Microsoft Excel 2000/2002/2003 File memory corruption
12837| [40242] Microsoft Publisher 2000/2002/2003/2007 Crash denial of service
12838| [40020] Microsoft Office 2007 ZIP Container unknown vulnerability
12839| [39769] Microsoft Windows 2000 cryptgenrandom weak encryption
12840| [39749] Microsoft Windows 2000 msjet40.dll memory corruption
12841| [39655] Microsoft Windows Server 2003 spoofing
12842| [39324] Microsoft Windows Mobile 2005 SMS unknown vulnerability
12843| [3373] Microsoft Word 2000/2002 memory corruption
12844| [38999] Microsoft Windows Server 2003 explorer.exe denial of service
12845| [38899] Microsoft ISA Server 2004 information disclosure
12846| [38728] Microsoft SQL Server 2005 Enterprise Manager sqldmo.dll memory corruption
12847| [38326] Microsoft Windows 2000 attemptwrite memory corruption
12848| [3241] Microsoft Excel 2000/2003/2004/XP SP3 rtWnDesk memory corruption
12849| [3223] Microsoft Windows XP/Server 2003 URI Eingabeung\xC3\xBCltigkeit
12850| [3212] Microsoft DirectX February 2006 RLE Compression Targa Files Heap-based memory corruption
12851| [37739] Microsoft Excel 2000/2002/2003/2004/2007 memory corruption
12852| [37738] Microsoft Office 2002/2003 memory corruption
12853| [3176] Microsoft Excel 2000/2002/2003/2007 File Attribute memory corruption
12854| [3175] Microsoft Excel 2000/2002/2003/2007 Active Worksheet memory corruption
12855| [3174] Microsoft Excel 2000/2002/2003/2007 Version Information memory corruption
12856| [3172] Microsoft Office Publisher 2007 Pointer memory corruption
12857| [37566] Microsoft Excel 2003 unknown vulnerability
12858| [37526] Microsoft Windows 2000/Server 2003 denial of service
12859| [37248] Microsoft Visio 2002 Packaging memory corruption
12860| [37251] Microsoft Windows 2000 memory corruption
12861| [3119] Microsoft Visio 2002 Object memory corruption
12862| [3118] Microsoft Visio 2002 Data memory corruption
12863| [37093] Microsoft Windows Server 2003 Error Message unknown vulnerability
12864| [37010] Microsoft Office 2000 ActiveX Control ouactrl.ocx memory corruption
12865| [36628] Microsoft Word 2000/2002/2003/2004 winword.exe memory corruption
12866| [36616] Microsoft Works 2004/2005/2006 memory corruption
12867| [36621] Microsoft Exchange Server 2000 Integer denial of service
12868| [36620] Microsoft Exchange Server 2000 Outlook Web Access cross site scripting
12869| [36619] Microsoft Exchange Server 2000/2003/2007 memory corruption
12870| [36618] Microsoft Exchange Server 2000 NULL Pointer Dereference denial of service
12871| [36617] Microsoft Excel 2000/2002/2003/2004 memory corruption
12872| [36623] Microsoft BizTalk Server 2004 ActiveX Control capicom.dll memory corruption
12873| [3067] Microsoft Office 2000/2003/2004/2007/Xp Drawing Object memory corruption
12874| [3065] Microsoft Excel 2000/2002/2003/2007 Filter Stack-based memory corruption
12875| [3064] Microsoft Excel 2000/2002/2003/2004/2007 set Font memory corruption
12876| [3063] Microsoft Excel 2000/2002/2003/2007 BIFF Record Stack-based memory corruption
12877| [3012] Microsoft Windows 2000/Server 2003 DNS Service Stack-based memory corruption
12878| [36039] Microsoft Content Management Server 2001 memory corruption
12879| [36052] Microsoft Windows 2000 Heap-based memory corruption
12880| [36051] Microsoft Word 2007 file798-1.doc memory corruption
12881| [36050] Microsoft Word 2007 file789-1.doc memory corruption
12882| [36040] Microsoft Content Management Server 2001 cross site scripting
12883| [3004] Microsoft Windows up to 2003/XP URL Parser memory corruption
12884| [36041] Microsoft .NET Framework 2.0.50727.42 cross site scripting
12885| [2990] Microsoft Windows 2000/XP/Vista Animated Cursor Stack-based memory corruption
12886| [36515] Microsoft Windows 2000/XP/Server 2003 memory corruption
12887| [35846] Microsoft Windows 2000/Server 2003 Default Configuration information disclosure
12888| [35373] Microsoft Excel 2003 denial of service
12889| [35372] Microsoft Office 2003 denial of service
12890| [35206] Microsoft Windows XP/Server 2003 Crash denial of service
12891| [35161] Microsoft ISA Server 2004 unknown vulnerability
12892| [35236] Microsoft Publisher 2007 memory corruption
12893| [2939] Microsoft Word 2000 memory corruption
12894| [34994] Microsoft Windows 2000 OLE Dialog memory corruption
12895| [34993] Microsoft Office 2000/2003/Xp memory corruption
12896| [35001] Microsoft Office 2000/2003/2004/Xp memory corruption
12897| [35000] Microsoft Word 2000/2002/2003 memory corruption
12898| [2933] Microsoft Windows XP SP2/2000 SP4/Server 2003 SP1 OLE Dialog Stack-based memory corruption
12899| [2894] Microsoft Office 2000/2003/2004/Xp Undefined String Format String
12900| [2884] Microsoft Word 2000/2002/2003 memory corruption
12901| [34321] Microsoft Office 2000/2003/2004/Xp Spreadsheet Heap-based memory corruption
12902| [34320] Microsoft Office 2000/2003/2004/Xp memory corruption
12903| [34319] Microsoft Office 2000/2003/2004/Xp memory corruption
12904| [34318] Microsoft Office 2000/2003/2004/Xp memory corruption
12905| [34322] Microsoft Office 2000/2003/Xp memory corruption
12906| [2811] Microsoft Windows 2000/XP/Server 2003 VML Vector Markup Language Integer memory corruption
12907| [2810] Microsoft Outlook 2000/2002/2003 Office Saved Search OSS File memory corruption
12908| [2809] Microsoft Outlook 2000/2002/2003 Header denial of service
12909| [2808] Microsoft Outlook 2000/2002/2003 Meeting VEVENT memory corruption
12910| [2807] Microsoft Excel 2000/2002/2003 XLS File memory corruption
12911| [34126] Microsoft Office 2003 memory corruption
12912| [34122] Microsoft Office Web Components 2000 memory corruption
12913| [2789] Microsoft Windows 2000/XP RPC Request NetrWkstaUserEnum() denial of service
12914| [2765] Microsoft Project Server 2003 pdsrequest.asp weak authentication
12915| [33851] Microsoft Word 2000/2002/2003 12122006-djtest.doc memory corruption
12916| [2739] Microsoft Windows 2000 Remote Installation Service Fehlende Authentifizierung
12917| [2738] Microsoft Windows 2000/XP/Server 2003 SNMP memory corruption
12918| [2737] Microsoft Windows XP/Server 2003 Manifest denial of service
12919| [33766] Microsoft Word 2000/2002/2003 memory corruption
12920| [2718] Microsoft Word 2000/2002/2003 DOC Document memory corruption
12921| [2717] Microsoft Windows 2000 Print Spooler Memory Consumption denial of service
12922| [2689] Microsoft Windows up to 2000 SP4 Active Directory denial of service
12923| [2688] Microsoft Windows 2000/XP/Server 2003 Client Service for Netware denial of service
12924| [2687] Microsoft Windows 2000/XP/Server 2003 Agent ActiveX ACF File Heap-based memory corruption
12925| [2686] Microsoft Windows 2000/XP/Server 2003 Client Service for Netware memory corruption
12926| [2684] Microsoft Windows 2000/XP Workstation Service Stack-based memory corruption
12927| [2659] Microsoft Windows 2000/XP GDI Crash Designfehler
12928| [2655] Microsoft Windows 2000/XP/Server 2003 XML Core Services Designfehler
12929| [33067] Microsoft Visual Studio .net 2005 ActiveX Control wmiscriptutils.dll memory corruption
12930| [2610] Microsoft PowerPoint 2003 PPT Document NULL Pointer Dereference denial of service
12931| [32693] Microsoft Word 2004 memory corruption
12932| [32686] Microsoft Office 2000/2001/2003/2004 Integer memory corruption
12933| [32690] Microsoft Office 2000/2003/2004/Xp memory corruption
12934| [32676] Microsoft Office 2000/2001/2003/2004 memory corruption
12935| [32675] Microsoft Office 2000/2003/2004/Xp memory corruption
12936| [32694] Microsoft Windows 2000 memory corruption
12937| [32689] Microsoft Excel 2000/2002/2003/2004/XP memory corruption
12938| [32688] Microsoft Excel 2000/2002/2003/2004/XP memory corruption
12939| [32687] Microsoft Word 2000/2002 memory corruption
12940| [32685] Microsoft Office 2000/2001/2003/2004 memory corruption
12941| [2601] Microsoft Windows XP/Server 2003 IPv6 Stack denial of service
12942| [2600] Microsoft Windows XP/Server 2003 IPv6 Stack TCP denial of service
12943| [2599] Microsoft Windows XP/Server 2003 IPv6 Stack ICMP denial of service
12944| [2598] Microsoft Windows XP/Server 2003 Object Packager Designfehler
12945| [2597] Microsoft Office 2003/Xp Smart-Tag Parser memory corruption
12946| [2596] Microsoft Office 2000/2003/2004/Xp Value Read memory corruption
12947| [2595] Microsoft Office 2000/2001/2003/2004 Diagram Value memory corruption
12948| [2594] Microsoft Office 2000/2001/2003/2004 Document memory corruption
12949| [2593] Microsoft ASP.NET 2.0 cross site scripting
12950| [2571] Microsoft PowerPoint up to 2003 Document memory corruption
12951| [2554] Microsoft PowerPoint 2000 memory corruption
12952| [2522] Microsoft Windows 2000/XP/Server 2003 Indexing Service cross site scripting
12953| [2521] Microsoft Publisher 2000/2002/2003 PUB File Stack-based memory corruption
12954| [2508] Microsoft Word 2000 memory corruption
12955| [2478] Microsoft Internet Explorer up to 6 on Win 2000 HTTP 1.1 Compression Heap-based memory corruption
12956| [31692] Microsoft PowerPoint 2000/2001/2002/2003 memory corruption
12957| [2436] Microsoft Windows 2000/XP/Server 2003 Kernel memory corruption
12958| [2435] Microsoft Windows 2000/XP/Server 2003 Exception memory corruption
12959| [2434] Microsoft Windows 2000/XP/Server 2003 Winlogon race condition
12960| [2433] Microsoft Windows 2000 Management Console cross site scripting
12961| [2432] Microsoft Windows 2000/XP/Server 2003 DNS Resolver Heap-based memory corruption
12962| [2431] Microsoft Windows 2000/XP/Server 2003 Winsock API memory corruption
12963| [2430] Microsoft Windows 2000/XP/Server 2003 RPC ELV memory corruption
12964| [2426] Microsoft Windows 2000/XP/Server 2003 WMF File gdi32.dll denial of service
12965| [2415] Microsoft Windows 2000/XP/Server 2003 SMB File srv.sys denial of service
12966| [31527] Microsoft Internet Explorer 6.0 on Win 2000 ActiveX Object Stack-Based denial of service
12967| [31358] Microsoft PowerPoint 2003 powerpnt.exe denial of service
12968| [31354] Microsoft PowerPoint 2003 memory corruption
12969| [31351] Microsoft ISA Server 2004 Filters unknown vulnerability
12970| [2382] Microsoft PowerPoint up to 2003 Presentation Open/Close memory corruption
12971| [2378] Microsoft PowerPoint 2000/2002/2003 Document Parser memory corruption
12972| [31318] Microsoft Excel 2000/2002/2003/2004/XP memory corruption
12973| [31317] Microsoft Excel 2000/2002/2003/2004/XP memory corruption
12974| [31316] Microsoft Excel 2000/2002/2003/2004/XP memory corruption
12975| [31313] Microsoft Excel 2000/2002/2003/2004/XP memory corruption
12976| [31312] Microsoft Excel 2000/2002/2003/2004/XP memory corruption
12977| [31311] Microsoft Excel 2000/2002/2003/XP memory corruption
12978| [31310] Microsoft Excel 2000/2002/2003/2004/XP memory corruption
12979| [31237] Microsoft Office 2000/2003/Xp memory corruption
12980| [31235] Microsoft Office 2000/2003/Xp memory corruption
12981| [2371] Microsoft NET Framework up to 2.0 URL Validator unknown vulnerability
12982| [2370] Microsoft Windows 2000/XP/Server 2003 Server Protocol Driver Server Message Block Heap-based memory corruption
12983| [2369] Microsoft Windows 2000/XP/Server 2003 Server Service Mailslot Heap-based memory corruption
12984| [2367] Microsoft Office 2000/2003/XP Document String memory corruption
12985| [2366] Microsoft Windows 2000/XP/Server 2003 DHCP Client memory corruption
12986| [2365] Microsoft Office 2000/2003/XP PNG Image memory corruption
12987| [2364] Microsoft Office 2000/2003/XP GIF Image memory corruption
12988| [31233] Microsoft Office 2000/2003/Xp mso.dll lscreateline memory corruption
12989| [31238] Microsoft Internet Explorer 6.0 on Win 2000 Crash denial of service
12990| [2357] Microsoft Excel up to 2003 on Asian System Document Repair Style memory corruption
12991| [31133] Microsoft Windows XP/Server 2003 explorer.exe memory corruption
12992| [2325] Microsoft Excel up to 2003 Hyperlink hlink.dll Long Hyperlink memory corruption
12993| [2324] Microsoft Excel 2000/2002/2003/2004 XLS File memory corruption
12994| [30801] Microsoft Windows up to 2000 Connection Manager Stack-based memory corruption
12995| [2312] Microsoft Exchange 2000 Outlook Web Access cross site scripting
12996| [2311] Microsoft Windows 2000/XP/Server 2003 MRXSMB.SYS MRxSmbCscIoctlOpenForCopyChunk memory corruption
12997| [2310] Microsoft Windows 2000 RPC spoofing
12998| [2309] Microsoft Windows 2000/XP/Server 2003 Routing and Remote Access Service RPC Request memory corruption
12999| [2308] Microsoft PowerPoint 2000/2002/2003/2004 PPT Document memory corruption
13000| [2307] Microsoft Windows 2000/XP/Server 2003 JScript Object memory corruption
13001| [2306] Microsoft Windows 2000/XP/Server 2003 IP Source Routing memory corruption
13002| [2305] Microsoft Windows XP/Server 2003 ART Image Heap-based memory corruption
13003| [2294] Microsoft Word up to 2003 DOC Document Backdoor Designfehler
13004| [2275] Microsoft Windows XP/Server 2003 mhtml URI inetcomm.dll memory corruption
13005| [2253] Microsoft Word up to 2003 Backdoor memory corruption
13006| [2221] Microsoft Windows 2000/XP CHM Archive itss.dll memory corruption
13007| [30131] Microsoft Windows NT 4.0/XP/2000/Server 2003 Distributed Transaction Coordinator Crash denial of service
13008| [2218] Microsoft Windows 2000/XP/Server 2003 MSDTC Heap-based denial of service
13009| [2217] Microsoft Exchange 2000/2003 Calender Collaboration Data Object memory corruption
13010| [2190] Microsoft Office 2003 mailto URI unknown vulnerability
13011| [2147] Microsoft Windows 2000/XP/Server 2003 COM Object memory corruption
13012| [2135] Microsoft FrontPage Server Extensions 2002 cross site scripting
13013| [29524] Microsoft ISA Server 2004 unknown vulnerability
13014| [134750] Microsoft ASP.NET Core 2.1/2.2 denial of service
13015| [134745] Microsoft SharePoint Foundation 2013 SP1 cross site scripting
13016| [134744] Microsoft Windows up to Server 2019 GDI information disclosure
13017| [134743] Microsoft SharePoint Server 2013 SP1/2016 cross site scripting
13018| [134742] Microsoft SharePoint Enterprise Server 2016/2019 cross site scripting
13019| [134741] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
13020| [134740] Microsoft SharePoint Enterprise Server 2013 SP1/2016 privilege escalation
13021| [134739] Microsoft SharePoint Foundation 2010 SP2/2013 SP2 cross site scripting
13022| [134738] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
13023| [134737] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
13024| [134736] Microsoft Office 2010 SP2 Access Connectivity Engine memory corruption
13025| [134735] Microsoft Office up to 2019 Access Connectivity Engine memory corruption
13026| [134734] Microsoft Office up to 2019 Access Connectivity Engine memory corruption
13027| [134733] Microsoft Windows up to Server 2019 Unified Write Filter privilege escalation
13028| [134731] Microsoft Windows up to Server 2019 Symlink privilege escalation
13029| [134729] Microsoft Windows up to Server 2019 Storage Service privilege escalation
13030| [134725] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
13031| [134724] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
13032| [134723] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
13033| [134722] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
13034| [134721] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
13035| [134720] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
13036| [134719] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
13037| [134718] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
13038| [134717] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
13039| [134716] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
13040| [134715] Microsoft Windows up to Server 2019 Win32k memory corruption
13041| [134714] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
13042| [134713] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
13043| [134712] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
13044| [134710] Microsoft Windows up to Server 2019 GDI information disclosure
13045| [134709] Microsoft Windows up to Server 2019 Kernel privilege escalation
13046| [134706] Microsoft Windows up to Server 2019 Error Reporting privilege escalation
13047| [134704] Microsoft SQL Server 2017 Analysis Services information disclosure
13048| [134701] Microsoft Windows up to Server 2019 Windows Defender Application Control privilege escalation
13049| [134700] Microsoft Windows up to Server 2019 Diagnostic Hub privilege escalation
13050| [134699] Microsoft Windows up to Server 2019 NDIS ndis.sys memory corruption
13051| [134698] Microsoft Windows up to Server 2019 OLE memory corruption
13052| [134697] Microsoft Office/Word 2016/2019/365 ProPlus memory corruption
13053| [134684] Microsoft Windows up to Server 2019 DHCP Server memory corruption
13054| [134678] Microsoft Windows up to Server 2019 GDI+ memory corruption
13055| [133236] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
13056| [133235] Microsoft Azure DevOps Server 2019 privilege escalation
13057| [133234] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
13058| [133232] Microsoft Azure DevOps Server 2019 cross site scripting
13059| [133229] Microsoft Azure DevOps Server 2019 cross site scripting
13060| [133224] Microsoft Exchange Server 2013 CU22/2016 CU11/2016 CU12/2019/2019 CU1 Outlook Web Access privilege escalation
13061| [133223] Microsoft Azure DevOps Server 2019 Content Security Policy privilege escalation
13062| [133222] Microsoft Windows up to Server 2019 Remote Registry Service memory corruption
13063| [133221] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
13064| [133220] Microsoft Windows up to Server 2019 GDI Memory information disclosure
13065| [133219] Microsoft Windows up to Server 2019 Win32k Memory information disclosure
13066| [133218] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
13067| [133217] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
13068| [133216] Microsoft Windows up to Server 2019 Kernel Memory information disclosure
13069| [133215] Microsoft Windows up to Server 2019 VBScript Engine memory corruption
13070| [133214] Microsoft Windows up to Server 2019 AppX Deployment Service privilege escalation
13071| [133213] Microsoft Windows up to Server 2019 Kernel Memory information disclosure
13072| [133212] Microsoft Windows up to Server 2019 Terminal Services Memory information disclosure
13073| [133211] Microsoft Windows up to Server 2019 Task Scheduler information disclosure
13074| [133209] Microsoft Windows up to Server 2019 LUAFV Driver luafv.sys privilege escalation
13075| [133206] Microsoft SharePoint Enterprise Server 2010 SP2/2013 SP1/2016/2019 cross site scripting
13076| [133205] Microsoft SharePoint Enterprise Server 2013 SP1/2016/2019 cross site scripting
13077| [133204] Microsoft Office/Excel up to 2019 memory corruption
13078| [133203] Microsoft Office up to 2019 Access Connectivity Engine memory corruption
13079| [133202] Microsoft Office up to 2019 Access Connectivity Engine memory corruption
13080| [133201] Microsoft Office up to 2019 Access Connectivity Engine memory corruption
13081| [133200] Microsoft Office up to 2019 Access Connectivity Engine memory corruption
13082| [133199] Microsoft Office 2010 SP2 Access Connectivity Engine memory corruption
13083| [133198] Microsoft Exchange Server up to 2019 CU1 Outlook Web Access cross site scripting
13084| [133197] Microsoft ASP.NET Core 2.2 Request denial of service
13085| [133196] Microsoft Windows up to Server 2019 Win32k information disclosure
13086| [133195] Microsoft Windows up to Server 2019 LUAFV Driver luafv.sys privilege escalation
13087| [133194] Microsoft Windows up to Server 2019 GDI Memory information disclosure
13088| [133193] Microsoft Windows up to Server 2019 LUAFV Driver luafv.sys privilege escalation
13089| [133192] Microsoft Windows up to Server 2019 OLE Automation privilege escalation
13090| [133189] Microsoft Windows up to Server 2019 CSRSS memory corruption
13091| [133188] Microsoft Windows up to Server 2019 LUAFV Driver luafv.sys privilege escalation
13092| [133187] Microsoft Windows up to Server 2019 LUAFV Driver luafv.sys privilege escalation
13093| [133186] Microsoft Windows up to Server 2019 TCP/IP Stack Fragmented IP Packet information disclosure
13094| [133185] Microsoft Windows up to Server 2019 Win32k memory corruption
13095| [133184] Microsoft Office 2016 for Mac/2019/365 ProPlus Graphics Component memory corruption
13096| [133183] Microsoft Windows up to Server 2019 Win32k memory corruption
13097| [133182] Microsoft Windows up to Server 2019 Win32k memory corruption
13098| [133181] Microsoft Office/Excel/PowerPoint up to 2019 URL Document Code Execution
13099| [133180] Microsoft Windows up to Server 2019 MS XML Code Execution
13100| [133179] Microsoft Windows up to Server 2019 MS XML Code Execution
13101| [133177] Microsoft Windows up to Server 2019 Device Guard luafv.sys privilege escalation
13102| [133174] Microsoft Windows up to Server 2019 GDI+ privilege escalation
13103| [133173] Microsoft Windows up to Server 2019 IOleCvt Interface privilege escalation
13104| [133166] Microsoft Windows up to Server 2019 MS XML Code Execution
13105| [133165] Microsoft Windows up to Server 2019 MS XML Code Execution
13106| [133164] Microsoft Windows up to Server 2019 MS XML Code Execution
13107| [133163] Microsoft Windows up to Server 2019 MS XML Code Execution
13108| [133162] Microsoft Windows up to Server 2019 MS XML Code Execution
13109| [131687] Microsoft Team Foundation Server 2017 Update 3.1/2018 Update 3.2/2018 Updated 1.2 cross site scripting
13110| [131685] Microsoft Windows up to Server 2019 SMB information disclosure
13111| [131684] Microsoft Visual Studio 2017 Version 15.9 C++ Redistributable Installer privilege escalation
13112| [131681] Microsoft Windows up to Server 2019 Win32k memory corruption
13113| [131679] Microsoft Windows up to Server 2019 Kernel information disclosure
13114| [131675] Microsoft SharePoint 2013 SP1/2016 cross site scripting
13115| [131674] Microsoft Windows up to Server 2019 Win32k information disclosure
13116| [131673] Microsoft Windows up to Server 2019 Kernel information disclosure
13117| [131672] Microsoft Windows up to Server 2019 GDI information disclosure
13118| [131671] Microsoft Windows up to Server 2019 VBScript Engine memory corruption
13119| [131668] Microsoft Windows up to Server 2019 AppX Deployment Server privilege escalation
13120| [131667] Microsoft Windows up to Server 2019 Comctl32.dll memory corruption
13121| [131663] Microsoft Windows up to Server 2019 Print Spooler information disclosure
13122| [131658] Microsoft Windows up to Server 2019 information disclosure
13123| [131657] Microsoft Windows up to Server 2019 denial of service
13124| [131656] Microsoft Office 2010 SP2 Connectivity Engine memory corruption
13125| [131653] Microsoft Windows up to Server 2019 SMB information disclosure
13126| [131652] Microsoft Windows up to Server 2019 SMB information disclosure
13127| [131651] Microsoft Windows up to Server 2019 Kernel information disclosure
13128| [131650] Microsoft Windows 10 1803/10 1809/Server 2019/Server 1803 Hyper-V denial of service
13129| [131649] Microsoft Windows up to Server 2019 Kernel memory corruption
13130| [131648] Microsoft Windows up to Server 2019 Hyper-V denial of service
13131| [131644] Microsoft Windows up to Server 2019 Hyper-V denial of service
13132| [131638] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
13133| [131632] Microsoft Windows 10 1803/10 1809/Server 2019/Server 1803 DHCP Client memory corruption
13134| [131631] Microsoft Windows 10 1803/10 1809/Server 2019/Server 1803 DHCP Client memory corruption
13135| [131630] Microsoft Windows 10 1803/10 1809/Server 2019/Server 1803 DHCP Client memory corruption
13136| [131629] Microsoft Windows up to Server 2019 Deployment Services TFTP Server memory corruption
13137| [131628] Microsoft Windows up to Server 2019 ActiveX memory corruption
13138| [131619] Microsoft Windows up to Server 2019 MS XML privilege escalation
13139| [131334] Microsoft Team Foundation Server 2018 Update 3.2 cross site scripting
13140| [131333] Microsoft Team Foundation Server 2018 Update 3.2 cross site scripting
13141| [131330] Microsoft Exchange Server 2010 SP3 UR26/2013 CU22/2016 CU12/2019 CU1 privilege escalation
13142| [131329] Microsoft Excel 2010 SP2/2013 SP1/2013 RT SP1/2016 information disclosure
13143| [131328] Microsoft Windows up to Server 2016 Kernel information disclosure
13144| [130832] Microsoft 2013 SP1 spoofing
13145| [130828] Microsoft Exchange Server 2010 SP3/2013 CU22/2016 CU12/2019 CU1 EWS privilege escalation
13146| [130826] Microsoft Office 2010 SP2 Connectivity Engine memory corruption
13147| [130825] Microsoft Office up to 2019 Connectivity Engine memory corruption
13148| [130824] Microsoft Office up to 2019 Connectivity Engine memory corruption
13149| [130823] Microsoft Office up to 2019 Connectivity Engine privilege escalation
13150| [130822] Microsoft Office up to 2019 Connectivity Engine privilege escalation
13151| [130821] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
13152| [130820] Microsoft Windows up to Server 2012 R2 GDI information disclosure
13153| [130818] Microsoft Windows up to Server 2019 GDI information disclosure
13154| [130817] Microsoft Windows up to Server 2019 Storage Service privilege escalation
13155| [130814] Microsoft Windows up to Server 2019 privilege escalation
13156| [130809] Microsoft Windows up to Server 2019 Defender Firewall Security privilege escalation
13157| [130808] Microsoft Windows up to Server 2019 information disclosure
13158| [130807] Microsoft Windows up to Server 2019 Hyper-V information disclosure
13159| [130806] Microsoft Windows up to Server 2019 SMB privilege escalation
13160| [130805] Microsoft Windows up to Server 2019 Device Guard privilege escalation
13161| [130804] Microsoft Windows up to Server 2019 Device Guard privilege escalation
13162| [130803] Microsoft Windows up to Server 2019 SMB privilege escalation
13163| [130802] Microsoft Windows up to Server 2019 Win32k information disclosure
13164| [130801] Microsoft Windows up to Server 2019 Device Guard privilege escalation
13165| [130800] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
13166| [130799] Microsoft Windows up to Server 2016 Win32k memory corruption
13167| [130798] Microsoft Windows up to Server 2019 GDI information disclosure
13168| [130797] Microsoft Windows up to Server 2019 GDI information disclosure
13169| [130796] Microsoft Windows up to Server 2019 GDI information disclosure
13170| [130793] Microsoft Windows up to Server 2019 GDI information disclosure
13171| [130792] Microsoft Windows up to Server 2019 HID information disclosure
13172| [130791] Microsoft Windows up to Server 2019 HID information disclosure
13173| [130790] Microsoft Windows up to Server 2016 JET Database Engine memory corruption
13174| [130789] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
13175| [130788] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
13176| [130787] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
13177| [130786] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
13178| [130785] Microsoft Office 2010 SP2/2013 SP1/2016/2019/365 ProPlus Security Feature Phishing spoofing
13179| [130784] Microsoft Windows up to Server 2019 GDI+ memory corruption
13180| [130782] Microsoft Windows up to Server 2019 DHCP Server memory corruption
13181| [130781] Microsoft Windows up to Server 2019 GDI+ memory corruption
13182| [129847] Microsoft Team Foundation Server 2017 Update 3.1/2018 Update 1.2/2018 Update 3.2 information disclosure
13183| [129846] Microsoft Team Foundation Server 2018 Update 3.2 cross site scripting
13184| [129845] Microsoft Skype for Business 2015 CU 8 Request cross site scripting
13185| [128765] Microsoft Visual Studio 2017 Version 15.9 C++ Construct privilege escalation
13186| [128764] Microsoft Exchange Server 2010 SP3/2013 CU21/2016 CU10/2016 CU11/2019 PowerShell API information disclosure
13187| [128762] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016/365 ProPlus Word memory corruption
13188| [128761] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
13189| [128760] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
13190| [128759] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
13191| [128758] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
13192| [128757] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
13193| [128756] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
13194| [128755] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
13195| [128754] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
13196| [128753] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
13197| [128752] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
13198| [128751] Microsoft Windows up to Server 2019 Data Sharing Service privilege escalation
13199| [128750] Microsoft Windows up to Server 2019 Runtime privilege escalation
13200| [128749] Microsoft Windows up to Server 2019 Kernel information disclosure
13201| [128747] Microsoft ASP.NET Core 2.1 Web Request denial of service
13202| [128746] Microsoft SharePoint Enterprise Server 2013 SP1/2016/2019 cross site scripting
13203| [128745] Microsoft Office up to 2019 Word Macro information disclosure
13204| [128744] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016/365 ProPlus information disclosure
13205| [128743] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016/365 ProPlus information disclosure
13206| [128742] Microsoft SharePoint Enterprise Server 2013 SP1/2016/2019 cross site scripting
13207| [128741] Microsoft SharePoint Enterprise Server 2016 cross site scripting
13208| [128740] Microsoft SharePoint Enterprise Server 2013 SP1 cross site scripting
13209| [128739] Microsoft Windows up to Server 2019 Kernel information disclosure
13210| [128738] Microsoft Windows up to Server 2019 Subsystem for Linux information disclosure
13211| [128737] Microsoft Windows up to Server 2019 COM Desktop Broker privilege escalation
13212| [128736] Microsoft Windows up to Server 2019 Kernel information disclosure
13213| [128735] Microsoft ASP.NET Core 2.1/2.2 Web Request denial of service
13214| [128733] Microsoft Windows up to Server 2019 Authentication Request privilege escalation
13215| [128732] Microsoft Office 2010 SP2/2013 SP1/2016/2019/365 ProPlus MSHTML Engine privilege escalation
13216| [128729] Microsoft Visual Studio 2010 SP1/2012 Update 5 vscontent File information disclosure
13217| [128728] Microsoft Windows up to Server 2019 Kernel information disclosure
13218| [128727] Microsoft Windows up to Server 2019 Data Sharing Service privilege escalation
13219| [128726] Microsoft Windows up to Server 2019 Data Sharing Service privilege escalation
13220| [128725] Microsoft Windows up to Server 2019 Data Sharing Service privilege escalation
13221| [128718] Microsoft Windows up to Server 2019 Hyper-V memory corruption
13222| [128717] Microsoft Windows 10 1803/10 1809/Server 2019/Server 1803 Hyper-V memory corruption
13223| [127925] Microsoft SharePoint Enterprise Server 2016 Web Request cross site scripting
13224| [127882] Microsoft Dynamics NAV 2016/2017 Web Request cross site scripting
13225| [127881] Microsoft Windows 10 1809/Server 2019 Object denial of service
13226| [127880] Microsoft Windows up to Server 2019 Win32k Object memory corruption
13227| [127828] Microsoft Windows up to Server 2019 Win32k memory corruption
13228| [127827] Microsoft Windows 10 1809/Server 2019 DirectX information disclosure
13229| [127826] Microsoft Windows 10 1803/10 1809/Server 2019/Server 1803 Win32k ASLR privilege escalation
13230| [127825] Microsoft SharePoint Enterprise Server 2010 SP2/2013 SP1/2016 privilege escalation
13231| [127824] Microsoft Excel up to 2019 Out-of-Bounds memory corruption
13232| [127823] Microsoft Windows up to Server 2012 R2 Kernel information disclosure
13233| [127821] Microsoft Windows up to Server 2019 Connected User Experiences and Telemetry Service denial of service
13234| [127820] Microsoft Windows up to Server 2019 Kernel memory corruption
13235| [127819] Microsoft Exchange Server 2016 CU10/2016 CU11 Profile Data privilege escalation
13236| [127817] Microsoft Excel up to 2019 information disclosure
13237| [127816] Microsoft Windows up to Server 2019 GDI information disclosure
13238| [127815] Microsoft Windows up to Server 2019 GDI information disclosure
13239| [127814] Microsoft SharePoint Enterprise Server 2010 SP2/2013 SP1/2016 Search cross site request forgery
13240| [127812] Microsoft Windows up to Server 2019 Remote Procedure Call information disclosure
13241| [127809] Microsoft PowerPoint 2010 SP2/2013 RT SP1/2013 SP1/2016/365 ProPlus memory corruption
13242| [127806] Microsoft Outlook up to 2019 memory corruption
13243| [127805] Microsoft Excel up to 2019 memory corruption
13244| [127804] Microsoft Excel up to 2019 memory corruption
13245| [127803] Microsoft Windows up to Server 2019 Text-To-Speech memory corruption
13246| [127801] Microsoft Windows up to Server 2019 DNS Server privilege escalation
13247| [126938] Microsoft Team Foundation Server 2018 Update 1.1/2018 Update 3 Code Execution
13248| [126755] Microsoft .NET Core 2.1 privilege escalation
13249| [126754] Microsoft Skype for Business/Lync Server 2013 SP1/2016 Emoji denial of service
13250| [126750] Microsoft Windows up to Server 2019 ALPC privilege escalation
13251| [126749] Microsoft Exchange Server 2010/2013/2016/2019 privilege escalation
13252| [126748] Microsoft Office 2019/365 ProPlus Outlook Message information disclosure
13253| [126747] Microsoft SharePoint Enterprise Server 2013 SP1 Folder information disclosure
13254| [126746] Microsoft Outlook 2010 SP2/2013 SP1/2013 RT SP1/2016 memory corruption
13255| [126745] Microsoft Project 2010 SP2/2013 SP1/2016 memory corruption
13256| [126744] Microsoft Office up to 2019 Word memory corruption
13257| [126743] Microsoft SharePoint Enterprise Server 2013 SP1/2016/2019 cross site scripting
13258| [126742] Microsoft SharePoint Enterprise Server 2013 SP1/2016/2019 cross site scripting
13259| [126739] Microsoft Windows up to Server 2012 R2 Win32k information disclosure
13260| [126737] Microsoft Windows up to Server 2012 R2 DirectX information disclosure
13261| [126736] Microsoft Windows up to Server 2019 Win32k memory corruption
13262| [126735] Microsoft Windows up to Server 2019 DirectX privilege escalation
13263| [126734] Microsoft Office 2019/365 ProPlus information disclosure
13264| [126733] Microsoft Windows 10 1803/10 1809/Server 2019/Server 1803 DirectX memory corruption
13265| [126730] Microsoft Windows up to Server 2019 Active Directory Federation Services cross site scripting
13266| [126728] Microsoft Office/SharePoint 2010 SP2 Word memory corruption
13267| [126727] Microsoft Outlook 2010 SP2/2013 SP1/2013 RT SP1/2016 memory corruption
13268| [126726] Microsoft Outlook 2010 SP2/2013 SP1/2013 RT SP1/2016 memory corruption
13269| [126725] Microsoft Windows up to Server 2019 DirectX memory corruption
13270| [126722] Microsoft Windows up to Server 2019 PowerShell privilege escalation
13271| [126718] Microsoft Windows up to Server 2016 Search memory corruption
13272| [126717] Microsoft Outlook 2010 SP2/2013 SP1/2013 RT SP1/2016/2019 memory corruption
13273| [126716] Microsoft Office up to 2019 Excel memory corruption
13274| [126715] Microsoft Office 2016/2019/365 ProPlus Excel memory corruption
13275| [126714] Microsoft Windows up to Server 2019 PowerShell unknown vulnerability
13276| [126713] Microsoft Windows up to Server 2019 VBScript Engine memory corruption
13277| [126712] Microsoft Windows up to Server 2016 Graphics Component memory corruption
13278| [126711] Microsoft Windows up to Server 2019 Deployment Services TFTP Server memory corruption
13279| [125123] Microsoft Windows up to Server 2019 Codecs Library information disclosure
13280| [125122] Microsoft Windows up to Server 2016 TCP/IP information disclosure
13281| [125121] Microsoft Windows up to Server 2019 DirectX memory corruption
13282| [125120] Microsoft Windows up to Server 2019 Windows Media Player information disclosure
13283| [125119] Microsoft Windows up to Server 2019 Windows Media Player information disclosure
13284| [125116] Microsoft Exchange Server 2013 CU21/2016 CU10 privilege escalation
13285| [125115] Microsoft Windows up to Server 2019 Theme API privilege escalation
13286| [125114] Microsoft Windows up to Server 2019 Windows Shell privilege escalation
13287| [125113] Microsoft Windows up to Server 2019 Kernel memory corruption
13288| [125111] Microsoft Windows up to Server 2019 Device Guard Code Integrity Policy privilege escalation
13289| [125110] Microsoft Windows up to Server 2019 DNS Global Blocklist privilege escalation
13290| [125109] Microsoft Windows up to Server 2019 NTFS privilege escalation
13291| [125108] Microsoft Windows up to Server 2019 Filter Manager memory corruption
13292| [125107] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
13293| [125106] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
13294| [125105] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
13295| [125104] Microsoft SharePoint Enterprise Server 2016 cross site scripting
13296| [125102] Microsoft Office/Word 2010 SP2/2013 RT SP1/2013 SP1/2016/2019 Protected View memory corruption
13297| [125100] Microsoft Office/Powerpoint 2010 SP2/2013 RT SP1/2013 SP1/2016/2019 Protected View memory corruption
13298| [125099] Microsoft Office/Excel up to 2019 Protected View memory corruption
13299| [125098] Microsoft Windows up to Server 2019 JET Database Engine privilege escalation
13300| [125097] Microsoft Windows up to Server 2019 DirectX Graphics memory corruption
13301| [125096] Microsoft Windows up to Server 2019 Win32k memory corruption
13302| [125095] Microsoft Exchange Server 2013 CU21/2016 CU10 Outlook Web Access cross site scripting
13303| [125093] Microsoft Windows up to Server 2019 Hyper-V memory corruption
13304| [125092] Microsoft Windows up to Server 2019 Hyper-V memory corruption
13305| [125091] Microsoft Windows up to Server 2019 MS XML privilege escalation
13306| [124371] Microsoft Exchange Server up to 2010 SP3 Outlook Web Access /owa/auth/logon.aspx Parameter Server-Side Request Forgery
13307| [124217] Microsoft Windows Server 2012/Server 2016 Active Directory Federation Services /adfs/ls Server-Side Request Forgery
13308| [123995] Microsoft Lync 2011 on Mac Security Feature Messages Download privilege escalation
13309| [123881] Microsoft Windows up to Server 2016 Sandbox privilege escalation
13310| [123874] Microsoft Windows up to Server 2016 Kernel information disclosure
13311| [123872] Microsoft Windows 8.1/RT 8.1/10/Server 2012/Server 2012 R2 SMB information disclosure
13312| [123868] Microsoft Windows up to Server 2016 Hyper-V denial of service
13313| [123864] Microsoft Windows up to Server 2016 Hyper-V information disclosure
13314| [123862] Microsoft SharePoint Enterprise Server 2010 SP2/2013 SP1/2013 RT SP1/2016 cross site scripting
13315| [123861] Microsoft Excel 2010 SP2/2013 SP1/2013 RT SP1/2016/2016 C2R information disclosure
13316| [123860] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
13317| [123859] Microsoft SharePoint Enterprise Server 2010 SP2/2013 SP1/2016 cross site scripting
13318| [123851] Microsoft Windows up to Server 2016 ALPC privilege escalation
13319| [123849] Microsoft Windows up to Server 2016 SMB denial of service
13320| [123846] Microsoft Office 2016 on Win/Mac memory corruption
13321| [123844] Microsoft Word 2013 SP1/2013 RT SP1/2016 PDF File memory corruption
13322| [123843] Microsoft Windows up to Server 2016 JET Database Engine memory corruption
13323| [123842] Microsoft Windows up to Server 2016 JET Database Engine memory corruption
13324| [123830] Microsoft Windows up to Server 2016 Hyper-V memory corruption
13325| [123828] Microsoft Windows up to Server 2016 Win32k Graphics privilege escalation
13326| [123827] Microsoft Windows up to Server 2016 Image memory corruption
13327| [123825] Microsoft Windows up to Server 2016 MSXML Parser privilege escalation
13328| [123823] Microsoft Windows up to Server 2016 Hyper-V privilege escalation
13329| [122887] Microsoft Office 2016 on Mac AutoUpdate memory corruption
13330| [122886] Microsoft Windows up to Server 2016 DirectX Graphics memory corruption
13331| [122885] Microsoft Windows up to Server 2016 DirectX Graphics memory corruption
13332| [122884] Microsoft Windows up to Server 2016 Win32k memory corruption
13333| [122883] Microsoft Windows up to Server 2016 DirectX Graphics memory corruption
13334| [122875] Microsoft Excel 2010 SP2/2013 SP1/2013 RT SP1/2016/2016 C2R information disclosure
13335| [122874] Microsoft Excel 2010 SP2/2013 SP1/2013 RT SP1/2016/2016 C2R memory corruption
13336| [122873] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R information disclosure
13337| [122872] Microsoft SharePoint Enterprise Server 2013 SP1/2016 information disclosure
13338| [122871] Microsoft PowerPoint 2010 SP2 memory corruption
13339| [122870] Microsoft Excel 2010 SP2/2013 RT SP1/2013 SP1/2016/2016 C2R memory corruption
13340| [122861] Microsoft Windows up to Server 2016 Microsoft COM for Windows privilege escalation
13341| [122850] Microsoft Visual Studio 2015 Update 3/2017/2017 Version 15.8 Diagnostic Hub privilege escalation
13342| [122849] Microsoft Windows up to Server 2016 Diagnostic Hub privilege escalation
13343| [122848] Microsoft Windows Security Feature 2FA weak authentication
13344| [122834] Microsoft Windows up to Server 2016 LNK memory corruption
13345| [122825] Microsoft Windows up to Server 2016 Graphics memory corruption
13346| [122823] Microsoft SQL Server 2016 SP1/2016 SP2/2017 memory corruption
13347| [121208] Microsoft Outlook 2010 SP2/2013 SP1/2013 RT SP1/2016/2016 C2R Attachment privilege escalation
13348| [121118] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
13349| [121116] Microsoft Windows up to Server 2016 Sandbox privilege escalation
13350| [121114] Microsoft Access 2013 SP1/2016/2016 C2R memory corruption
13351| [121111] Microsoft Windows up to Server 2016 Kernel memory corruption
13352| [121110] Microsoft Windows up to Server 2016 Wordpad privilege escalation
13353| [121107] Microsoft Windows up to Server 2016 DNSAPI DNSAPI.dll denial of service
13354| [121106] Microsoft SharePoint Enterprise Server 2013 SP1/2016 privilege escalation
13355| [121105] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
13356| [121098] Microsoft Office 2016/2016 C2R memory corruption
13357| [121092] Microsoft Windows up to Server 2016 FTP Server denial of service
13358| [121090] Microsoft Visual Studio up to 2017 Version 15.8 Preview privilege escalation
13359| [119479] Microsoft Office 2010 SP2/2013 RT SP1/2013 SP1/2016 memory corruption
13360| [119477] Microsoft Excel 2010 SP2/2013 RT SP1/2013 SP1/2016 information disclosure
13361| [119476] Microsoft Publisher 2010 SP2 OLE Object PUB File privilege escalation
13362| [119475] Microsoft Outlook 2010 SP2/2013 RT SP1/2013 SP1/2016 Attachment privilege escalation
13363| [119474] Microsoft Windows up to Server 2016 GDI information disclosure
13364| [119470] Microsoft Windows up to Server 2016 HTTP HTTP.sys denial of service
13365| [119468] Microsoft Windows up to Server 2016 Device Guard Code Integrity Policy privilege escalation
13366| [119467] Microsoft Windows up to Server 2016 Hypervisor privilege escalation
13367| [119465] Microsoft Windows up to Server 2016 Device Guard Code Integrity Policy privilege escalation
13368| [119464] Microsoft Windows up to Server 2016 Device Guard Code Integrity Policy privilege escalation
13369| [119463] Microsoft Windows up to Server 2016 Device Guard Code Integrity Policy privilege escalation
13370| [119461] Microsoft Windows up to Server 2016 Device Guard Code Integrity Policy privilege escalation
13371| [119460] Microsoft Windows up to Server 2016 Device Guard Code Integrity Policy privilege escalation
13372| [119459] Microsoft Windows up to Server 2016 memory corruption
13373| [119457] Microsoft Windows up to Server 2016 Desktop Bridge privilege escalation
13374| [119456] Microsoft Windows up to Server 2016 Kernel information disclosure
13375| [119455] Microsoft Windows up to Server 2016 denial of service
13376| [119454] Microsoft Windows up to Server 2016 Device Guard Code Integrity Policy privilege escalation
13377| [119452] Microsoft Windows up to Server 2016 HIDParser memory corruption
13378| [119448] Microsoft Windows up to Server 2016 Code Integrity Module denial of service
13379| [119447] Microsoft Windows up to Server 2016 NTFS privilege escalation
13380| [119441] Microsoft Windows up to Server 2016 Media Foundation memory corruption
13381| [119437] Microsoft Windows up to Server 2016 HTTP Protocol Stack Http.sys memory corruption
13382| [119436] Microsoft Windows up to Server 2016 memory corruption
13383| [119431] Microsoft Windows up to Server 2016 DNSAPI DNSAPI.dll DNS Response privilege escalation
13384| [118120] Microsoft Office 2016 on Mac XML Data Code Execution
13385| [117561] Microsoft SharePoint Enterprise Server 2010 SP2/2013 SP1 Web Request cross site scripting
13386| [117560] Microsoft Exchange Server up to 2016 CU9 Code Execution memory corruption
13387| [117559] Microsoft Exchange Server 2016 CU8/2016 CU9 Outlook Web Access Web Request cross site scripting
13388| [117558] Microsoft Windows up to Server 2016 Code Execution memory corruption
13389| [117507] Microsoft Infopath 2013 SP1 memory corruption
13390| [117505] Microsoft Excel 2010 SP2/2013 SP1/2013 RT SP1/2016/2016 C2R information disclosure
13391| [117504] Microsoft Office 2010 SP2 information disclosure
13392| [117503] Microsoft Exchange Server 2013 CU19/2013 CU20/2016 CU8/2016 CU9 Outlook Web Access cross site scripting
13393| [117502] Microsoft SharePoint Enterprise Server 2010 SP2/2013 SP1/2016 cross site scripting
13394| [117501] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
13395| [117500] Microsoft Exchange Server 2016 CU8/2016 CU9 Outlook Web Access cross site scripting
13396| [117499] Microsoft Exchange Server up to 2016 CU9 information disclosure
13397| [117498] Microsoft Office 2016 C2R Security Feature privilege escalation
13398| [117497] Microsoft SharePoint Enterprise Server 2010/2013 SP1/2016 cross site scripting
13399| [117480] Microsoft Windows up to Server 2016 COM Serialized privilege escalation
13400| [117473] Microsoft Excel 2010 SP2/2013 SP1/2013 RT SP1/2016/2016 C2R memory corruption
13401| [117472] Microsoft Office 2010 SP2/2013 SP1/2013 RT SP1/2016/2016 C2R memory corruption
13402| [117471] Microsoft Office 2010 SP2/2013 SP1/2013 RT SP1/2016/2016 C2R memory corruption
13403| [117470] Microsoft Office 2010 SP2/2013 SP1/2013 RT SP1/2016/2016 C2R memory corruption
13404| [117469] Microsoft Excel 2010 SP2/2013 SP1/2013 RT SP1/2016/2016 C2R memory corruption
13405| [117468] Microsoft Excel 2010 SP2/2013 SP1/2013 RT SP1/2016/2016 C2R memory corruption
13406| [117444] Microsoft Windows up to Server 2016 Hyper-V vSMB memory corruption
13407| [117443] Microsoft Windows up to Server 2016 Hyper-V memory corruption
13408| [117442] Microsoft Windows up to Server 2016 VBScript Engine memory corruption
13409| [116132] Microsoft Office 2016 Memory information disclosure
13410| [116051] Microsoft SharePoint Enterprise Server 2016 cross site scripting
13411| [116050] Microsoft SharePoint Enterprise Server 2010 SP2/2013/2016 cross site scripting
13412| [116049] Microsoft SharePoint Enterprise Server 2013/2016 privilege escalation
13413| [116048] Microsoft Windows up to Server 2016 DirectX Graphics Kernel Subsystem memory corruption
13414| [116047] Microsoft Windows up to Server 2016 OpenType Font Driver atmfd.dll memory corruption
13415| [116046] Microsoft SharePoint Enterprise Server 2013/2016 Share cross site scripting
13416| [116045] Microsoft Windows up to Server 2016 JET Database Engine memory corruption
13417| [116039] Microsoft Windows up to Server 2016 Remote Desktop Protocol denial of service
13418| [116031] Microsoft Windows up to Server 2016 Kernel ASLR information disclosure
13419| [116030] Microsoft Windows up to Server 2016 SNMP Service denial of service
13420| [116026] Microsoft Windows up to Server 2016 Kernel information disclosure
13421| [116024] Microsoft Windows up to Server 2016 HTTP.sys denial of service
13422| [116023] Microsoft Office up to 2016 C2R information disclosure
13423| [116022] Microsoft Excel 2010 SP2 memory corruption
13424| [116020] Microsoft Windows 10 1607/10 1703/10 1709/Server 2016/Server 1709 Active Directory privilege escalation
13425| [116019] Microsoft Windows up to Server 2016 Kernel information disclosure
13426| [116018] Microsoft Office 2013 SP1/2013 RT SP1/2016/2016 C2R memory corruption
13427| [116017] Microsoft Excel up to 2016 C2R memory corruption
13428| [116016] Microsoft Office 2010 SP2/2013 SP1/2013 RT SP1/2016 Graphics memory corruption
13429| [116014] Microsoft Office 2013 SP1/2013 RT SP1/2016/2016 C2R memory corruption
13430| [116013] Microsoft Excel 2010 SP2/2013 RT SP1/2013 SP1 memory corruption
13431| [116008] Microsoft Windows up to Server 2016 Graphics memory corruption
13432| [116007] Microsoft Windows up to Server 2016 Graphics memory corruption
13433| [116006] Microsoft Windows up to Server 2016 Graphics memory corruption
13434| [116005] Microsoft Windows up to Server 2016 Graphics memory corruption
13435| [116004] Microsoft Windows up to Server 2016 Graphics memory corruption
13436| [116003] Microsoft Windows up to Server 2016 VBScript Engine memory corruption
13437| [115994] Microsoft Windows up to Server 2016 Malware Protection Engine memory corruption
13438| [115804] Microsoft Windows up to Server 2016 Malware Protection Engine privilege escalation
13439| [114579] Microsoft Exchange Server up to 2017 CU8 Outlook Web Access information disclosure
13440| [114574] Microsoft SharePoint Enterprise Server 2016 privilege escalation
13441| [114573] Microsoft SharePoint Enterprise Server 2016 cross site scripting
13442| [114571] Microsoft Exchange Server 2016 CU7/2016 CU8 Outlook Web Access information disclosure
13443| [114570] Microsoft Exchange Server 2010 SP3/2013 CU18/2013 CU19/2016 CU7/2016 CU8 Outlook Web Access Fake privilege escalation
13444| [114565] Microsoft Windows 10 1607/10 1703/10 1709/Server 2016/Server 1709 Kernel information disclosure
13445| [114564] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
13446| [114562] Microsoft SharePoint Enterprise Server 2016 cross site scripting
13447| [114560] Microsoft SharePoint Enterprise Server 2016 cross site scripting
13448| [114559] Microsoft SharePoint Enterprise Server 2016 cross site scripting
13449| [114558] Microsoft SharePoint Enterprise Server 2016 cross site scripting
13450| [114557] Microsoft SharePoint Enterprise Server 2016 cross site scripting
13451| [114556] Microsoft SharePoint Enterprise Server 2016 cross site scripting
13452| [114555] Microsoft SharePoint Enterprise Server 2016 cross site scripting
13453| [114554] Microsoft SharePoint Enterprise Server 2016 cross site scripting
13454| [114553] Microsoft SharePoint Enterprise Server 2016 cross site scripting
13455| [114552] Microsoft SharePoint Enterprise Server 2016 cross site scripting
13456| [114551] Microsoft Excel up to 2016 C2R Security Feature privilege escalation
13457| [114549] Microsoft Access 2010 SP2/2013 SP1/2016 memory corruption
13458| [114548] Microsoft Windows up to Server 2016 CNG Security Feature cng.sys privilege escalation
13459| [114547] Microsoft Windows up to Server 2016 Kernel information disclosure
13460| [114546] Microsoft Windows up to Server 2016 Kernel information disclosure
13461| [114545] Microsoft Windows up to Server 2016 Kernel information disclosure
13462| [114544] Microsoft Windows up to Server 2016 Kernel information disclosure
13463| [114543] Microsoft Windows up to Server 2016 Kernel information disclosure
13464| [114542] Microsoft Windows up to Server 2016 Kernel information disclosure
13465| [114541] Microsoft Windows up to Server 2016 Kernel information disclosure
13466| [114540] Microsoft Windows up to Server 2016 Kernel information disclosure
13467| [114536] Microsoft Windows up to Server 2016 CredSSP privilege escalation
13468| [114535] Microsoft Windows up to Server 2016 Hyper-V denial of service
13469| [114531] Microsoft Windows up to Server 2016 Windows Installer privilege escalation
13470| [114530] Microsoft Windows up to Server 2016 GDI privilege escalation
13471| [114529] Microsoft Windows up to Server 2016 GDI privilege escalation
13472| [114527] Microsoft Windows up to Server 2016 Kernel information disclosure
13473| [114526] Microsoft Windows up to Server 2016 Kernel information disclosure
13474| [114525] Microsoft Windows up to Server 2016 Kernel information disclosure
13475| [114522] Microsoft Windows 10 1607/10 1703/Server 2016 Desktop Bridge privilege escalation
13476| [114521] Microsoft Windows up to Server 2016 Video Control privilege escalation
13477| [114520] Microsoft Windows 10/Server 2016/Server 1709 Desktop Bridge privilege escalation
13478| [114518] Microsoft Windows up to Server 2016 Remote Assistance information disclosure
13479| [114517] Microsoft Windows 10/Server 2016/Server 1709 Desktop Bridge VFS privilege escalation
13480| [114516] Microsoft Windows up to Server 2016 Windows Shell privilege escalation
13481| [113835] Microsoft Identity Manager 2016 SP1 cross site scripting
13482| [113264] Microsoft Windows 8.1/RT 8.1/Server 2012 R2 SMBv2/SMBv3 denial of service
13483| [113260] Microsoft Windows up to Server 2016 Kernel memory corruption
13484| [113259] Microsoft Windows 10/Server 2016/Server 1709 NTFS privilege escalation
13485| [113254] Microsoft Windows up to Server 2016 Kernel information disclosure
13486| [113253] Microsoft Windows 10/Server 2016/Server 1709 Kernel memory corruption
13487| [113252] Microsoft Windows up to Server 2016 Kernel memory corruption
13488| [113250] Microsoft Windows 10/Server 2016/Server 1709 Kernel memory corruption
13489| [113249] Microsoft Windows up to Server 2016 Kernel memory corruption
13490| [113248] Microsoft Windows up to Server 2016 Kernel information disclosure
13491| [113243] Microsoft Windows 10/Server 2016 MultiPoint Management privilege escalation
13492| [113242] Microsoft Windows up to Server 2016 Common Log File System Driver memory corruption
13493| [113241] Microsoft Windows up to Server 2016 Common Log File System Driver memory corruption
13494| [113240] Microsoft Windows 10/Server 2016/Server 1709 AppContainer privilege escalation
13495| [113237] Microsoft SharePoint Enterprise Server 2016 cross site scripting
13496| [113236] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
13497| [113233] Microsoft Office 2010 SP2/2013 SP1/2013 RT SP1/2016 Uninitialized Memory information disclosure
13498| [113232] Microsoft Excel 2016 memory corruption
13499| [113230] Microsoft Windows up to Server 2016 Scripting Engine information disclosure
13500| [113229] Microsoft Windows up to Server 2016 StructuredQuery memory corruption
13501| [111580] Microsoft Office 2016 on Mac Email Attachment spoofing
13502| [111571] Microsoft SharePoint Enterprise Server 2013/2016 Access cross site scripting
13503| [111567] Microsoft Office 2010/2013/2016 memory corruption
13504| [111564] Microsoft Word 2016 memory corruption
13505| [111562] Microsoft SharePoint Server 2010/2013/2016 Web Request cross site scripting
13506| [111561] Microsoft SharePoint Server 2010/2013/2016 Web Request cross site scripting
13507| [128730] Microsoft Windows up to Server 2019 JET Database Engine memory corruption
13508| [111358] Microsoft Windows up to Server 2016 IPsec denial of service
13509| [110553] Microsoft Office 2016 C2R information disclosure
13510| [110552] Microsoft SharePoint Enterprise Server 2016 Web Request privilege escalation
13511| [110551] Microsoft Excel 2016 C2R memory corruption
13512| [110550] Microsoft PowerPoint 2013 SP1/2013 RT SP1/2016 information disclosure
13513| [110549] Microsoft Exchange Server 2016 CU6/2016 CU7 Outlook Web Access privilege escalation
13514| [110547] Microsoft Windows up to Server 2016 its:// Protocol information disclosure
13515| [110531] Microsoft Windows 10/Server 2016 Device Guard privilege escalation
13516| [110522] Microsoft Windows up to Server 2016 RRAS privilege escalation
13517| [110350] Microsoft Windows up to Server 2016 Malware Protection Engine memory corruption
13518| [110318] Microsoft Windows up to Server 2016 Malware Protection Engine memory corruption
13519| [109391] Microsoft SharePoint Enterprise Server 2016 Project Server cross site request forgery
13520| [109389] Microsoft Excel 2016 Click-to-Run memory corruption
13521| [109360] Microsoft Windows up to Server 2016 Windows Search denial of service
13522| [107759] Microsoft Windows up to Server 2016 SMB denial of service
13523| [107757] Microsoft Windows up to Server 2016 JET Database Engine memory corruption
13524| [107756] Microsoft Windows up to Server 2016 JET Database Engine memory corruption
13525| [107753] Microsoft Windows 10/Server 2016 SMB privilege escalation
13526| [107744] Microsoft Windows up to Server 2016 DNSAPI DNSAPI.dll DNS Response privilege escalation
13527| [107741] Microsoft Outlook 2016 Secure Connection Mail information disclosure
13528| [107740] Microsoft Windows up to Server 2016 Graphics memory corruption
13529| [107739] Microsoft Windows up to Server 2016 Graphics memory corruption
13530| [107738] Microsoft Windows up to Server 2016 Search information disclosure
13531| [107734] Microsoft Windows 10/Server 2016 SMB privilege escalation
13532| [107732] Microsoft Outlook 2010 SP2/2013 SP1/2013 RT SP1/2016 Bypass privilege escalation
13533| [107730] Microsoft Windows up to Server 2016 Search Remote memory corruption
13534| [107729] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
13535| [107728] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
13536| [107727] Microsoft SharePoint Enterprise Server 2013 SP1/2016 cross site scripting
13537| [107724] Microsoft Windows up to Server 2016 Text Services Framework memory corruption
13538| [107723] Microsoft Windows up to Server 2016 SMB information disclosure
13539| [107698] Microsoft Office 2016 memory corruption
13540| [107593] InFocus Mondopad 2.2.08 Excel Spreadsheet Microsoft Office Document Credentials information disclosure
13541| [106544] Microsoft Exchange Server 2016 Outlook Web Access cross site scripting
13542| [106531] Microsoft SharePoint Foundation 2013 SP1 cross site scripting
13543| [106529] Microsoft PowerPoint 2016 memory corruption
13544| [106523] Microsoft Windows up to Server 2016 PDF Library memory corruption
13545| [106518] Microsoft Edge on Win10/Server 2016 memory corruption
13546| [106516] Microsoft Windows up to Server 2016 PDF Library memory corruption
13547| [106498] Microsoft Windows up to Server 2016 Shell privilege escalation
13548| [106496] Microsoft Windows up to Server 2016 Uniscribe information disclosure
13549| [106495] Microsoft Windows up to Server 2012 R2 Uniscribe memory corruption
13550| [106492] Microsoft Windows Server 2012/Server 2012 R2/Server 2016 DHCP Service memory corruption
13551| [106489] Microsoft Windows up to Server 2016 Graphics Win32k win32k!fsc_CalcGrayRow memory corruption
13552| [106474] Microsoft Office 2016 memory corruption
13553| [106473] Microsoft SharePoint Server 2013 SP1 cross site scripting
13554| [106472] Microsoft Windows up to Server 2016 Bluetooth Driver Object BlueBorne spoofing
13555| [106470] Microsoft Excel 2011 on Mac memory corruption
13556| [106455] Microsoft Exchange Server 2013/2016 information disclosure
13557| [106454] Microsoft Windows up to Server 2016 Windows NetBT Session Services race condition memory corruption
13558| [105048] Microsoft Edge on Win10/Server 2016 Scripting Engine memory corruption
13559| [105047] Microsoft Edge on Win10/Server 2016 Scripting Engine EntryCall memory corruption
13560| [105046] Microsoft Edge on Win10/Server 2016 Javascript Engine memory corruption
13561| [105040] Microsoft Edge on Win10/Server 2016 Scripting Engine memory corruption
13562| [105038] Microsoft Edge on Win10/Server 2016 Javascript Engine Out-of-Bounds memory corruption
13563| [105037] Microsoft Edge on Win10/Server 2016 Javascript Engine PreVisitCatch memory corruption
13564| [105035] Microsoft SharePoint Server 2010 SP2 cross site scripting
13565| [105033] Microsoft Edge 38.14393.1066.0 on Win10/Server 2016 Use-After-Free information disclosure
13566| [105029] Microsoft Edge on Win10/Server 2016 Javascript Engine ProcessLinkFailedAsmJsModule memory corruption
13567| [105027] Microsoft Edge on Win10/Server 2016 _SelectValueInternal information disclosure
13568| [105024] Microsoft Edge on Win10/Server 2016 Javascript Engine memory corruption
13569| [105023] Microsoft Edge on Win10/Server 2016 Javascript Engine memory corruption
13570| [105017] Microsoft Windows up to Server 2016 Error Reporting information disclosure
13571| [105013] Microsoft Windows 10 1607/10 1703/Server 2016 Hyper-V denial of service
13572| [105011] Microsoft Windows up to Server 2016 Windows Search memory corruption
13573| [105010] Microsoft Windows up to Server 2016 Win32k memory corruption
13574| [105009] Microsoft Windows up to Server 2016 Input Method Editor memory corruption
13575| [105008] Microsoft SQL Server 2012/2014/2016 Analysis Services information disclosure
13576| [104990] Microsoft Windows up to Server 2016 JET Database Engine memory corruption
13577| [104989] Microsoft Windows up to Server 2016 NetBIOS denial of service
13578| [104584] Microsoft Outlook up to 2016 C2R Document File privilege escalation
13579| [104583] Microsoft Outlook up to 2016 C2R Email memory corruption
13580| [104582] Microsoft Outlook up to 2016 C2R Object memory corruption
13581| [103468] Microsoft Exchange Server 2010 SP3/2013 SP3/2013 CU16/2016 CU5 Open Redirect
13582| [103446] Microsoft Windows up to Server 2016 Search Object privilege escalation
13583| [103445] Microsoft Windows up to Server 2016 Wordpad privilege escalation
13584| [103444] Microsoft Windows up to Server 2016 Explorer denial of service
13585| [103442] Microsoft Windows 10/Server 2016 HoloLens WiFi Packet privilege escalation
13586| [103441] Microsoft Windows up to Server 2016 Object HTTP.sys information disclosure
13587| [103431] Microsoft Windows up to Server 2016 PowerShell PSObject Object privilege escalation
13588| [103429] Microsoft Windows up to Server 2016 Kerberos weak authentication
13589| [103426] Microsoft Exchange Server 2010 SP3/2013 SP3/2013 CU16/2016 CU5 OWA Request cross site scripting
13590| [103425] Microsoft Exchange Server 2010 SP3/2013 SP3/2013 CU16/2016 CU5 OWA Request cross site scripting
13591| [103420] Microsoft Windows up to Server 2016 Kerberos Bypass privilege escalation
13592| [103417] Microsoft Windows up to Server 2016 Windows Shell privilege escalation
13593| [102544] Microsoft Edge on Win10/Server 2016 Fetch API information disclosure
13594| [102543] Microsoft Edge on Win10/Server 2016 Javascript XML DOM Object information disclosure
13595| [102463] Microsoft Project Server 2013 SP1 cross site scripting
13596| [102460] Microsoft Outlook 2016 on Mac HTML spoofing
13597| [102448] Microsoft SharePoint Enterprise Server 2016 Reflected cross site scripting
13598| [102446] Microsoft Office up to 2016 privilege escalation
13599| [102445] Microsoft Office 2010 SP2/2011/2013 SP1/2013 RT SP1/2016 privilege escalation
13600| [102443] Microsoft Office up to 2016 privilege escalation
13601| [102412] Microsoft Windows up to Server 2016 PDF information disclosure
13602| [102397] Microsoft Outlook 2010 SP1/2013 SP1/2016 DLL Loader privilege escalation
13603| [102396] Microsoft Office 2013 SP1/2016 DLL Loader privilege escalation
13604| [102386] Microsoft Windows up to Server 2012 R2 Uniscribe privilege escalation
13605| [102385] Microsoft Windows up to Server 2016 Font Library privilege escalation
13606| [102376] Microsoft Windows up to Server 2016 CAB File privilege escalation
13607| [102375] Microsoft Windows up to Server 2016 PDF Parser privilege escalation
13608| [102374] Microsoft Windows up to Server 2016 PDF Parser privilege escalation
13609| [102373] Microsoft Windows up to Server 2016 Uniscribe Font USP10!MergeLigRecords memory corruption
13610| [101817] Microsoft Windows up to Server 2016 Malware Protection Engine denial of service
13611| [101816] Microsoft Windows up to Server 2016 Malware Protection Engine setCaller memory corruption
13612| [101815] Microsoft Windows up to Server 2016 Malware Protection Engine Use-After-Free memory corruption
13613| [101814] Microsoft Windows up to Server 2016 Malware Protection Engine denial of service
13614| [101813] Microsoft Windows up to Server 2016 Malware Protection Engine memory corruption
13615| [101812] Microsoft Windows up to Server 2016 Malware Protection Engine denial of service
13616| [101811] Microsoft Windows up to Server 2016 Malware Protection Engine denial of service
13617| [101810] Microsoft Windows up to Server 2016 Malware Protection Engine denial of service
13618| [101028] Microsoft Windows 10/Server 2016 Hyper-V vSMB privilege escalation
13619| [101020] Microsoft SharePoint Foundation 2013 SP1 cross site scripting
13620| [101019] Microsoft Skype for Business 2016 memory corruption
13621| [101018] Microsoft SharePoint 2010 SP2/2013 SP1/2016 memory corruption
13622| [101016] Microsoft PowerPoint 2011 on Mac memory corruption
13623| [101015] Microsoft PowerPoint 2011 on Mac memory corruption
13624| [101014] Microsoft Office 2010 SP2/2016 memory corruption
13625| [101013] Microsoft Office 2010 SP2/2016 memory corruption
13626| [101002] Microsoft Windows up to Server 2016 SMBv1 Server memory corruption
13627| [101001] Microsoft Windows up to Server 2016 SMBv1 Server memory corruption
13628| [101000] Microsoft Windows up to Server 2016 SMBv1 Server memory corruption
13629| [100999] Microsoft Windows up to Server 2016 SMBv1 Server memory corruption
13630| [100918] Microsoft Windows 8/8.1/10/Server 2012/Server 2016 Malware Protection Service Type Confusion privilege escalation
13631| [99697] Microsoft SharePoint Server 2010 SP1/2010 SP2 Excel Services cross site scripting
13632| [99683] Microsoft Windows 10 1607/10 1703/Server 2012 R2/Server 2016 Active Directory Lockout privilege escalation
13633| [99682] Microsoft Outlook 2011 on Mac HTML Tag Validator spoofing
13634| [99681] Microsoft Windows up to Server 2016 OLE Integrity-Level Check privilege escalation
13635| [99667] Microsoft Windows 10/Server 2016 Active Directory Service Unresponsive denial of service
13636| [98272] Microsoft Windows up to 10/Server 2016 Local Session privilege escalation
13637| [98096] Microsoft Exchange 2013 SP1 privilege escalation
13638| [98095] Microsoft Lync for Mac 2011 Certificate Validation weak authentication
13639| [98094] Microsoft SharePoint Server 2013 SP1 cross site scripting
13640| [98093] Microsoft SharePoint Server/Office Web Apps 2010 SP2 memory corruption
13641| [98091] Microsoft SharePoint Server/Office Web Apps 2010 SP2 memory corruption
13642| [98090] Microsoft SharePoint Server 2010 SP2/2013 SP1 information disclosure
13643| [98089] Microsoft Office Web Apps 2013 SP1 memory corruption
13644| [98082] Microsoft Office 2010 SP2/2013 SP1/2013 RT SP1/2016 denial of service
13645| [98081] Microsoft Excel up to 2016 information disclosure
13646| [98080] Microsoft Excel 2010 SP2/2013 SP1/2013 RT SP1/2016 memory corruption
13647| [98079] Microsoft Word 2016 memory corruption
13648| [98076] Microsoft Lync/Skype for Business 2010/2013/2016 Graphics Component privilege escalation
13649| [98075] Microsoft Lync/Skype for Business 2010/2013/2016 GDI+ information disclosure
13650| [98074] Microsoft Lync/Skype for Business 2010/2013/2016 GDI+ information disclosure
13651| [98073] Microsoft Office 2010 SP2/Word Viewer Graphics Component information disclosure
13652| [98069] Microsoft Windows up to Server 2012 R2 Color Management memory corruption
13653| [98056] Microsoft Windows up to Server 2016 DNS Query information disclosure
13654| [98054] Microsoft Windows up to Server 2016 SMBv2/SMBv3 NULL Pointer Dereference memory corruption
13655| [98017] Microsoft Windows up to Server 2016 PDF memory corruption
13656| [98015] Microsoft Windows 10/Server 2016 Hyper-V denial of service
13657| [98013] Microsoft Windows 10/Server 2016 Hyper-V vSMB memory corruption
13658| [98007] Microsoft Windows 10/Server 2016 Hyper-V Network Switch denial of service
13659| [98006] Microsoft Windows 10/Server 2016 Hyper-V vSMB memory corruption
13660| [96521] Microsoft Windows 8.1/10/Server 2012/Server 2016 SMB Response mrxsmb20.sys denial of service
13661| [95781] Microsoft PowerPoint 2016 Java Embedded Object privilege escalation
13662| [95125] Microsoft Word/SharePoint Enterprise Server 2016 Document privilege escalation
13663| [94451] Microsoft Office 2011 memory corruption
13664| [94447] Microsoft Office 2010 SP2 memory corruption
13665| [94446] Microsoft Office 2016 memory corruption
13666| [94444] Microsoft Office 2010 SP2/2013 SP1/2013 RT SP1/2016 OLE DLL Loader memory corruption
13667| [94443] Microsoft Office up to 2016 information disclosure
13668| [94442] Microsoft Office 2010 SP2/2013 SP1/2013 RT SP1/2016 privilege escalation
13669| [93964] Microsoft Windows 7 Excel Starter 2010 XXE information disclosure
13670| [93543] Microsoft SQL Server 2016 FILESTREAM Path privilege escalation
13671| [93540] Microsoft Excel 2010 SP2/2011/2016 memory corruption
13672| [93416] Microsoft SQL Server up to 2012 SP3/2014 SP2/2016 Server Agent atxcore.dll privilege escalation
13673| [93415] Microsoft SQL Server 2016 MDS API cross site scripting
13674| [93414] Microsoft SQL Server up to 2012 SP3 RDBMS Engine privilege escalation
13675| [93413] Microsoft SQL Server up to 2014 SP2/2016 RDBMS Engine privilege escalation
13676| [93412] Microsoft SQL Server 2016 RDBMS Engine privilege escalation
13677| [93393] Microsoft Office up to 2016 memory corruption
13678| [93392] Microsoft Office up to 2016 memory corruption
13679| [93391] Microsoft Office up to 2016 memory corruption
13680| [93389] Microsoft Windows up to Server 2016 Media Foundation memory corruption
13681| [93388] Microsoft Windows up to Server 2016 Animation Manager Stylesheets memory corruption
13682| [92587] Microsoft Windows 8.1/RT 8.1/10/Server 2012/Server 2012 R2 Transaction Manager privilege escalation
13683| [92584] Microsoft Office up to 2016 memory corruption
13684| [91571] Microsoft Windows 8.1/RT 8.1/10/Server 2012/Server 2012 R2 PDF Library information disclosure
13685| [91570] Microsoft Windows 8.1/RT 8.1/10/Server 2012/Server 2012 R2 PDF Library information disclosure
13686| [91556] Microsoft Exchange 2016 Meeting Invation cross site scripting
13687| [91555] Microsoft Exchange 2013/2016 Link spoofing
13688| [91550] Microsoft Office 2016 memory corruption
13689| [91547] Microsoft Office 2010 memory corruption
13690| [91543] Microsoft Office up to 2016 memory corruption
13691| [91541] Microsoft Office 2013/2016 APP-V ASLR privilege escalation
13692| [90711] Microsoft Windows 8.1/RT 8.1/10/Server 2012/Server 2012 R2 PDF privilege escalation
13693| [90710] Microsoft Windows 8.1/RT 8.1/Server 2012/Server 2012 R2 Netlogon privilege escalation
13694| [90704] Microsoft Office 2013/2013 RT/2016 memory corruption
13695| [89043] Microsoft Office up to 2016 memory corruption
13696| [89041] Microsoft Office up to 2016 memory corruption
13697| [89040] Microsoft Office 2010 SP2/2011/2013 SP1/2013 RT SP1/2016 memory corruption
13698| [89038] Microsoft Office 2010 SP2/2013 SP1/2013 RT SP1/2016 Security Feature privilege escalation
13699| [89037] Microsoft Office 2010 SP2/2013 SP1/2013 RT SP1/2016 memory corruption
13700| [87961] Microsoft Windows up to Server 2012 R2 Search denial of service
13701| [87959] Microsoft Windows 8.1/10/Server 2012/Server 2012 R2 PDF information disclosure
13702| [87958] Microsoft Windows 8.1/10/Server 2012/Server 2012 R2 PDF memory corruption
13703| [87957] Microsoft Windows 8.1/10/Server 2012/Server 2012 R2 PDF information disclosure
13704| [87956] Microsoft Exchange 2013/2016 Oracle Outside In Libraries information disclosure
13705| [87944] Microsoft Windows Server 2012/Server 2012 R2 Virtual PCI Memory information disclosure
13706| [87940] Microsoft Windows Server 2012/Server 2012 R2 DNS Server Use-After-Free memory corruption
13707| [87936] Microsoft Office up to 2016 memory corruption
13708| [87166] Microsoft Windows up to Server 2012 R2 DirectX Graphics Kernel Subsystem privilege escalation
13709| [87156] Microsoft Windows 8.1/RT 8.1/10/Server 2012 R2 Shell memory corruption
13710| [87149] Microsoft Office up to 2016 memory corruption
13711| [87148] Microsoft Office 2010 Graphics memory corruption
13712| [87146] Microsoft Office 2011/2013/2013 RT/2016 memory corruption
13713| [82229] Microsoft Excel 2010 SP2 Office Document memory corruption
13714| [82223] Microsoft Windows 8.1/10/Server 2012 R2 Hyper-V Memory information disclosure
13715| [82222] Microsoft Windows 8.1/10/Server 2012/Server 2012 R2 Memory information disclosure
13716| [82221] Microsoft Windows 8.1/10/Server 2012/Server 2012 R2 Hyper-V privilege escalation
13717| [81274] Microsoft Office up to 2016 memory corruption
13718| [81270] Microsoft Windows 8.1/RT 8.1/10/Server 2012/Server 2012 R2 PDF Library memory corruption
13719| [81269] Microsoft Windows up to Server 2012 R2 Media Parser memory corruption
13720| [81268] Microsoft Windows up to Server 2012 R2 Media Parser memory corruption
13721| [80886] Microsoft SharePoint Foundation 2013 SP1 cross site scripting
13722| [80885] Microsoft Windows 7 SP1/8.1/10/Server 2012/Server 2012 R2 RDP memory corruption
13723| [80878] Microsoft Windows Server 2012 R2 Active Directory Federation Service denial of service
13724| [80874] Microsoft Windows 7 SP1/8.1/10/Server 2012/Server 2012 R2 RDP privilege escalation
13725| [80870] Microsoft Office up to 2016 memory corruption
13726| [80868] Microsoft Office up to 2016 memory corruption
13727| [80867] Microsoft Office up to 2016 memory corruption
13728| [80865] Microsoft Windows 8.1/RT 8.1/Server 2012/Server 2012 R2 DLL Loader memory corruption
13729| [80860] Microsoft Windows 8.1/10/Server 2012/Server 2012 R2 Reader memory corruption
13730| [80859] Microsoft Windows 8.1/10/Server 2012/Server 2012 R2 PDF Library memory corruption
13731| [80231] Microsoft Excel up to 2016 Office Document memory corruption
13732| [80229] Microsoft Exchange Server 2013 SP1/2013 CU 10/2013 CU 11/2016 Outlook Web Access cross site scripting
13733| [80228] Microsoft Exchange Server 2016 Outlook Web Access cross site scripting
13734| [80227] Microsoft Exchange Server 2013 SP1/2013 CU 10/2016 Outlook Web Access cross site scripting
13735| [80226] Microsoft Exchange Server 2016 Outlook Web Access cross site scripting
13736| [80218] Microsoft Office up to 2016 ASLR privilege escalation
13737| [80217] Microsoft SharePoint Foundation 2013 SP1 Access Control Policy cross site scripting
13738| [80216] Microsoft Office up to 2016 Office Document memory corruption
13739| [80206] Microsoft SharePoint Foundation 2013 SP1 Access Control Policy cross site scripting
13740| [128763] Microsoft Exchange Server 2016 CU10/2016 CU11/2019 memory corruption
13741| [79508] Microsoft Windows up to Server 2012 R2 Library Loader memory corruption
13742| [79500] Microsoft Office 2010/2011/2016 memory corruption
13743| [79183] Microsoft Windows up to Server 2012 R2 IPsec denial of service
13744| [79173] Microsoft Windows up to Server 2012 R2 Graphics information disclosure
13745| [79117] Microsoft Outlook 2011/2016 on Mac HTML spoofing
13746| [78375] Microsoft SharePoint Server/SharePoint Foundation 2013 SP1 cross site scripting
13747| [77645] Microsoft Exchange Server 2013 CU8/2013 CU9 Outlook Web Access cross site scripting
13748| [77644] Microsoft Exchange Server 2013 CU8/2013 CU9 Outlook Web Access cross site scripting
13749| [77638] Microsoft Lync Server 2013 cross site scripting
13750| [77628] Microsoft SharePoint Foundation 2013 SP1 cross site scripting
13751| [77612] Microsoft Exchange Server 2013 CU8/2013 CU9 Outlook Web Access Stack-Based information disclosure
13752| [77050] Microsoft Office up to 2016 memory corruption
13753| [77037] Microsoft Windows Server 2012/Server 2012 R2 System Center Operations Manager cross site scripting
13754| [76461] Microsoft Windows up to Server 2012 R2 Domain-Controller Communication Credentials information disclosure
13755| [76460] Microsoft Windows 7 SP1/8/Server 2012 RDP Server Service memory corruption
13756| [76448] Microsoft Windows 8.1/Server 2012 R2 Hyper-V memory corruption
13757| [75793] Microsoft Exchange Server 2013 CU8 cross site scripting
13758| [75792] Microsoft Exchange Server 2013 SP1 CU8 cross site request forgery
13759| [75791] Microsoft Office 2013 SP1 Office Document Uninitialized Memory memory corruption
13760| [75787] Microsoft Exchange Server 2013 SP1 CU8 Same Origin Policy privilege escalation
13761| [75786] Microsoft Office 2010 SP2/2013 SP1/2013 RT SP1 Office Document memory corruption
13762| [66976] Microsoft Access 2010 VBA Datatype denial of service
13763| [74848] Microsoft SharePoint Foundation/SharePoint Server 2013 SP1 cross site scripting
13764| [74842] Microsoft Windows 8.1/Server 2012 R2 Hyper-V denial of service
13765| [74836] Microsoft Project Server 2010 SP2/2013 SP1 cross site scripting
13766| [74835] Microsoft Office 2011 on Mac Use-After-Free cross site scripting
13767| [74834] Microsoft Windows Server 2012 R2 Active Directory Federation Services 3.0 privilege escalation
13768| [74833] Microsoft Windows 7 SP1/8/8.1/Server 2012/Server 2012 R2 HTTP Request HTTP.sys privilege escalation
13769| [74393] Microsoft SharePoint Server 2013 Foundation cross site scripting
13770| [73967] Microsoft Office up to 2013 SP1 Office File memory corruption
13771| [73966] Microsoft Office up to 2013 SP1 RTF File memory corruption
13772| [73965] Microsoft Office up to 2013 SP1 Use-After-Free memory corruption
13773| [73961] Microsoft Windows 7 SP1/8/8.1/Server 2012/Server 2012 R2 Remote Desktop Protocol Object Management denial of service
13774| [69162] Microsoft System Center Virtual Machine Manager 2012 privilege escalation
13775| [69160] Microsoft Windows up to Server 2012 Process privilege escalation
13776| [69156] Microsoft Office 2010 Object memory corruption
13777| [68593] Microsoft Windows up to Server 2012 Network Location Awareness Service privilege escalation
13778| [68417] Microsoft Exchange 2013 Outlook Web Access Token spoofing
13779| [68191] Microsoft SharePoint 2010 cross site scripting
13780| [67828] Microsoft ASP.NET MVC 2/3/4/5/5.1 System.Web.Mvc.dll cross site scripting
13781| [67518] Microsoft Lync 2013 denial of service
13782| [67517] Microsoft Lync 2013 Script Reflected cross site scripting
13783| [67516] Microsoft Lync 2010/2013 denial of service
13784| [67362] Microsoft Windows up to Server 2012 R2 Remote Procedure Call privilege escalation
13785| [67360] Microsoft SharePoint 2013 App Permission Management cross site scripting
13786| [13549] Microsoft Windows 7/8/8.1/Server 2012 Remote Desktop Protocol weak encryption
13787| [13547] Microsoft Lync 2010/2013 Meeting cross site scripting
13788| [13228] Microsoft Office 2013 Document privilege escalation
13789| [68577] Microsoft ASP.NET 2014.3.1209 Telerik UI RadAsyncUpload directory traversal
13790| [12267] Microsoft Forefront Security for Exchange Server 2010 Mail memory corruption
13791| [12263] Microsoft Windows up to Server 2012 Direct2D 2D Geometric Figure memory corruption
13792| [12238] Microsoft Windows 8/Server 2012/RT IPv6 denial of service
13793| [12185] Microsoft .NET Framework 2/4 HMAC weak authentication
13794| [12183] Microsoft .NET Framework 2/4 DTD denial of service
13795| [11673] Microsoft Windows Live Movie Maker 2011 WAV File denial of service
13796| [11468] Microsoft Exchange 2010/2013 cross site scripting
13797| [11466] Microsoft Office 2013 File Response information disclosure
13798| [11457] Microsoft SharePoint Server/Office Web Apps 2010 SP1/2010 SP2/2013 W3WP Service Account privilege escalation
13799| [11150] Microsoft Windows 8/Server 2012 Hyper-V Data Structure Value Crash privilege escalation
13800| [11004] Microsoft Windows Server 2012 R2 RDP Restricted Admin Mode weak authentication
13801| [10250] Microsoft SharePoint Server up to 2013 W3WP Process denial of service
13802| [10249] Microsoft SharePoint 2010/2003/2007/2.0/3.0 Workflow memory corruption
13803| [10248] Microsoft SharePoint Server up to 2013 cross site scripting
13804| [9943] Microsoft Windows Server 2012 NAT Driver ICMP Packet denial of service
13805| [8739] Microsoft Windows Essentials up to 2012 Windows Writer Eingabe information disclosure
13806| [8725] Microsoft Lync 2010/2013 Use-After-Free memory corruption
13807| [8722] Microsoft Windows 8/Server 2012/RT HTTP.sys denial of service
13808| [8206] Microsoft SharePoint Server 2010 SP1 HTML Sanitization Component cross site scripting
13809| [8203] Microsoft Windows up to 2012 AD LDAP Query denial of service
13810| [8200] Microsoft SharePoint Server 2013 ACL information disclosure
13811| [7971] Microsoft Office for Mac 2011 up to 14.3.1 on Mac HTML5 Mail Message Parser File information disclosure
13812| [7969] Microsoft OneNote 2010 SP1 ONE File information disclosure
13813| [7968] Microsoft SharePoint Server 2010 SP1 Input Validator Eingabe Crash denial of service
13814| [7967] Microsoft SharePoint Server 2010 SP1 User Account Eingabe Crash information disclosure
13815| [7966] Microsoft SharePoint Server 2010 SP1 Eingabe Crash cross site scripting
13816| [7965] Microsoft SharePoint Server 2010 SP1 User Account Callback URL privilege escalation
13817| [7964] Microsoft Visio 2010 Tree Object Type File memory corruption
13818| [7343] Microsoft Lync 2012 HTTP Format String
13819| [7258] Microsoft Windows up to 8/Server 2012 SSL/TLS race condition
13820| [7230] Microsoft Excel 2010 SP1 on 32-bit XLS File Formatting Information Crash denial of service
13821| [6831] Microsoft Office Picture Manager 2010 File memory corruption
13822| [62720] EMC NetWorker Module for Microsoft Applications up to 2.2.0 memory corruption
13823| [6624] Microsoft SQL Server up to 2012 Report Manager cross site scripting
13824| [62238] Microsoft Visual Studio Team Foundation Server 2010 cross site scripting
13825| [5946] Microsoft Visio/Visio Viewer up to 2010 SP1 File memory corruption
13826| [5644] Microsoft SharePoint 2010 scriptesx.ashx cross site scripting
13827| [5641] Microsoft SharePoint 2010 cross site scripting
13828| [60943] Microsoft Dynamics AX 2012 Enterprise Portal cross site scripting
13829| [12311] Microsoft Lync 2010 Search race condition
13830| [60570] Microsoft Forefront Unified Access Gateway 2010 information disclosure
13831| [60569] Microsoft Forefront Unified Access Gateway 2010 spoofing
13832| [60208] Microsoft Visio Viewer 2010 memory corruption
13833| [60207] Microsoft Visio Viewer 2010 memory corruption
13834| [60206] Microsoft Visio Viewer 2010 memory corruption
13835| [4640] Microsoft SharePoint 2010 inplview.aspx cross site scripting
13836| [4636] Microsoft SharePoint 2010 wizardlist.aspx cross site scripting
13837| [4635] Microsoft SharePoint 2010 themeweb.aspx cross site scripting
13838| [59008] Microsoft Forefront Unified Access Gateway 2010 Crash denial of service
13839| [58995] Microsoft Forefront Unified Access Gateway 2010 memory corruption
13840| [58994] Microsoft Forefront Unified Access Gateway 2010 Reflected cross site scripting
13841| [58993] Microsoft Forefront Unified Access Gateway 2010 Reflected cross site scripting
13842| [4424] Microsoft Host Integration Server up to 2010 denial of service
13843| [4420] Microsoft Forefront Unified Access Gateway 2010 memory corruption
13844| [58487] Microsoft SharePoint Foundation 2010 cross site scripting
13845| [58486] Microsoft SharePoint Foundation 2010 Reflected cross site scripting
13846| [58485] Microsoft SharePoint Foundation 2010 EditForm.aspx cross site scripting
13847| [4414] Microsoft SharePoint 2010 cross site scripting
13848| [4413] Microsoft SharePoint 2010/2007/3.0 XML/XLS Designfehler
13849| [91971] Microsoft Skype 2.2.x/5.2.x/5.3.x denial of service
13850| [57693] Microsoft Forefront Threat Management Gateway 2010 NSPLookupServiceNext memory corruption
13851| [4332] Microsoft PowerPoint 2010/2007 memory corruption
13852| [56028] Microsoft Data Access Components 2.8 memory corruption
13853| [55777] Microsoft Windows Movie Maker 2.6 memory corruption
13854| [55424] Microsoft Forefront Unified Access Gateway 2010 Signurl.asp cross site scripting
13855| [55415] Microsoft Forefront Unified Access Gateway 2010 cross site scripting
13856| [55414] Microsoft Forefront Unified Access Gateway 2010 cross site scripting
13857| [55413] Microsoft Forefront Unified Access Gateway 2010 spoofing
13858| [54341] Microsoft Windows Movie Maker 2.1 memory corruption
13859| [54549] Microsoft PowerPoint 2010 pptimpconv.dll memory corruption
13860| [4009] Microsoft NET Framework 2.x/3.x denial of service
13861| [45681] Microsoft Internet Explorer 8 Beta 2 privilege escalation
13862| [45449] Microsoft Internet Explorer 8 Beta 2 XSS Filter cross site scripting
13863| [45448] Microsoft Internet Explorer 8 Beta 2 XSS Filter cross site scripting
13864| [45446] Microsoft Internet Explorer 8 Beta 2 XSS Filter cross site scripting
13865| [2927] Microsoft Data Access Components 2.x ADODB.Connection ActiveX Control memory corruption
13866| [32692] Microsoft XML Core Services up to 2.6 memory corruption
13867| [32691] Microsoft XML Core Services up to 2.6 memory corruption
13868| [29608] Microsoft Data Access Components 2.7 memory corruption
13869|
13870| MITRE CVE - https://cve.mitre.org:
13871| [CVE-2013-3661] The EPATHOBJ::bFlatten function in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not check whether linked-list traversal is continually accessing the same list member, which allows local users to cause a denial of service (infinite traversal) via vectors that trigger a crafted PATHRECORD chain.
13872| [CVE-2013-3660] The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, and Windows Server 2012 does not properly initialize a pointer for the next object in a certain list, which allows local users to obtain write access to the PATHRECORD chain, and consequently gain privileges, by triggering excessive consumption of paged memory and then making many FlattenPath function calls, aka "Win32k Read AV Vulnerability."
13873| [CVE-2013-3174] DirectShow in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, and Windows Server 2012 allows remote attackers to execute arbitrary code via a crafted GIF file, aka "DirectShow Arbitrary Memory Overwrite Vulnerability."
13874| [CVE-2013-3173] Buffer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages improper handling of objects in memory, aka "Win32k Buffer Overwrite Vulnerability."
13875| [CVE-2013-3172] Buffer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to cause a denial of service (system hang) via a crafted application that leverages improper handling of objects in memory, aka "Win32k Buffer Overflow Vulnerability."
13876| [CVE-2013-3171] The serialization functionality in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5 does not properly check the permissions of delegate objects, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application that leverages a partial-trust relationship, aka "Delegate Serialization Vulnerability."
13877| [CVE-2013-3167] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Win32k Information Disclosure Vulnerability."
13878| [CVE-2013-3154] The signature-update functionality in Windows Defender on Microsoft Windows 7 and Windows Server 2008 R2 relies on an incorrect pathname, which allows local users to gain privileges via a Trojan horse application in the %SYSTEMDRIVE% top-level directory, aka "Microsoft Windows 7 Defender Improper Pathname Vulnerability."
13879| [CVE-2013-3138] Integer overflow in the TCP/IP kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allows remote attackers to cause a denial of service (system hang) via crafted TCP packets, aka "TCP/IP Integer Overflow Vulnerability."
13880| [CVE-2013-3136] The kernel in Microsoft Windows XP SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, and Windows 8 on 32-bit platforms does not properly handle unspecified page-fault system calls, which allows local users to obtain sensitive information from kernel memory via a crafted application, aka "Kernel Information Disclosure Vulnerability."
13881| [CVE-2013-3134] The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 on 64-bit platforms does not properly allocate arrays of structures, which allows remote attackers to execute arbitrary code via a crafted .NET Framework application that changes array data, aka "Array Allocation Vulnerability."
13882| [CVE-2013-3133] Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check the permissions of objects that use reflection, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application, aka "Anonymous Method Injection Vulnerability."
13883| [CVE-2013-3132] Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check the permissions of objects that use reflection, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application, aka "Delegate Reflection Bypass Vulnerability."
13884| [CVE-2013-3131] Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5, and Silverlight 5 before 5.1.20513.0, does not properly prevent changes to data in multidimensional arrays of structures, which allows remote attackers to execute arbitrary code via (1) a crafted .NET Framework application or (2) a crafted Silverlight application, aka "Array Access Violation Vulnerability."
13885| [CVE-2013-1345] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Win32k Vulnerability."
13886| [CVE-2013-1340] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Win32k Dereference Vulnerability."
13887| [CVE-2013-1339] The Print Spooler in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly manage memory during deletion of printer connections, which allows remote authenticated users to execute arbitrary code via a crafted request, aka "Print Spooler Vulnerability."
13888| [CVE-2013-1336] The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check signatures, which allows remote attackers to make undetected changes to signed XML documents via unspecified vectors that preserve signature validity, aka "XML Digital Signature Spoofing Vulnerability."
13889| [CVE-2013-1335] Microsoft Word 2003 SP3 and Word Viewer allow remote attackers to execute arbitrary code via crafted shape data in a Word document, aka "Word Shape Corruption Vulnerability."
13890| [CVE-2013-1334] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Win32k Window Handle Vulnerability."
13891| [CVE-2013-1332] dxgkrnl.sys (aka the DirectX graphics kernel subsystem) in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "DirectX Graphics Kernel Subsystem Double Fetch Vulnerability."
13892| [CVE-2013-1331] Buffer overflow in Microsoft Office 2003 SP3 and Office 2011 for Mac allows remote attackers to execute arbitrary code via crafted PNG data in an Office document, leading to improper memory allocation, aka "Office Buffer Overflow Vulnerability."
13893| [CVE-2013-1329] Integer signedness error in Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers a buffer underflow, aka "Publisher Buffer Underflow Vulnerability."
13894| [CVE-2013-1328] Microsoft Publisher 2003 SP3, 2007 SP3, and 2010 SP1 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers incorrect pointer handling, aka "Publisher Pointer Handling Vulnerability."
13895| [CVE-2013-1327] Integer signedness error in Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers an improper memory allocation, aka "Publisher Signed Integer Vulnerability."
13896| [CVE-2013-1323] Microsoft Publisher 2003 SP3 does not properly handle NULL values for unspecified data items, which allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Incorrect NULL Value Handling Vulnerability."
13897| [CVE-2013-1322] Microsoft Publisher 2003 SP3 does not properly check table range data, which allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Invalid Range Check Vulnerability."
13898| [CVE-2013-1321] Microsoft Publisher 2003 SP3 does not properly check the data type of an unspecified return value, which allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Return Value Validation Vulnerability."
13899| [CVE-2013-1320] Buffer overflow in Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Buffer Overflow Vulnerability."
13900| [CVE-2013-1319] Microsoft Publisher 2003 SP3 does not properly check the return value of an unspecified method, which allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Return Value Handling Vulnerability."
13901| [CVE-2013-1318] Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers access to an invalid pointer, aka "Publisher Corrupt Interface Pointer Vulnerability."
13902| [CVE-2013-1317] Integer overflow in Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers an improper allocation-size calculation, aka "Publisher Integer Overflow Vulnerability."
13903| [CVE-2013-1316] Microsoft Publisher 2003 SP3 does not properly validate the size of an unspecified array, which allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Negative Value Allocation Vulnerability."
13904| [CVE-2013-1302] Microsoft Communicator 2007 R2, Lync 2010, Lync 2010 Attendee, and Lync Server 2013 do not properly handle objects in memory, which allows remote attackers to execute arbitrary code via an invitation that triggers access to a deleted object, aka "Lync RCE Vulnerability."
13905| [CVE-2013-1301] Microsoft Visio 2003 SP3 2007 SP3, and 2010 SP1 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, aka "XML External Entities Resolution Vulnerability."
13906| [CVE-2013-1300] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Win32k Memory Allocation Vulnerability."
13907| [CVE-2013-1295] The Client/Server Run-time Subsystem (CSRSS) in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP2, and Server 2008 SP2 does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "CSRSS Memory Corruption Vulnerability."
13908| [CVE-2013-1294] Race condition in the kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages improper handling of objects in memory, aka "Kernel Race Condition Vulnerability."
13909| [CVE-2013-1293] The NTFS kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via a crafted application that leverages improper handling of objects in memory, aka "NTFS NULL Pointer Dereference Vulnerability."
13910| [CVE-2013-1292] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages improper handling of objects in memory, aka "Win32k Race Condition Vulnerability."
13911| [CVE-2013-1291] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, Windows 7 Gold and SP1, and Windows 8 allows local users to cause a denial of service (reboot) via a crafted OpenType font, aka "OpenType Font Parsing Vulnerability" or "Win32k Font Parsing Vulnerability."
13912| [CVE-2013-1287] The USB kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 do not properly handle objects in memory, which allows physically proximate attackers to execute arbitrary code by connecting a crafted USB device, aka "Windows USB Descriptor Vulnerability," a different vulnerability than CVE-2013-1285 and CVE-2013-1286.
13913| [CVE-2013-1286] The USB kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 do not properly handle objects in memory, which allows physically proximate attackers to execute arbitrary code by connecting a crafted USB device, aka "Windows USB Descriptor Vulnerability," a different vulnerability than CVE-2013-1285 and CVE-2013-1287.
13914| [CVE-2013-1285] The USB kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 do not properly handle objects in memory, which allows physically proximate attackers to execute arbitrary code by connecting a crafted USB device, aka "Windows USB Descriptor Vulnerability," a different vulnerability than CVE-2013-1286 and CVE-2013-1287.
13915| [CVE-2013-1283] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages improper handling of objects in memory, aka "Win32k Race Condition Vulnerability."
13916| [CVE-2013-1281] The NFS server in Microsoft Windows Server 2008 R2 and R2 SP1 and Server 2012 allows remote attackers to cause a denial of service (NULL pointer dereference and reboot) via an attempted renaming of a file or folder located on a read-only share, aka "NULL Dereference Vulnerability."
13917| [CVE-2013-1280] The kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Reference Count Vulnerability."
13918| [CVE-2013-1279] Race condition in the kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages incorrect handling of objects in memory, aka "Kernel Race Condition Vulnerability," a different vulnerability than CVE-2013-1278.
13919| [CVE-2013-1278] Race condition in the kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages incorrect handling of objects in memory, aka "Kernel Race Condition Vulnerability," a different vulnerability than CVE-2013-1279.
13920| [CVE-2013-1277] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
13921| [CVE-2013-1276] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
13922| [CVE-2013-1275] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
13923| [CVE-2013-1274] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
13924| [CVE-2013-1273] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
13925| [CVE-2013-1272] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
13926| [CVE-2013-1271] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
13927| [CVE-2013-1270] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
13928| [CVE-2013-1269] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
13929| [CVE-2013-1268] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
13930| [CVE-2013-1267] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
13931| [CVE-2013-1266] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
13932| [CVE-2013-1265] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
13933| [CVE-2013-1264] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
13934| [CVE-2013-1263] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
13935| [CVE-2013-1262] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
13936| [CVE-2013-1261] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
13937| [CVE-2013-1260] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
13938| [CVE-2013-1259] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
13939| [CVE-2013-1258] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
13940| [CVE-2013-1257] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
13941| [CVE-2013-1256] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
13942| [CVE-2013-1255] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
13943| [CVE-2013-1254] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
13944| [CVE-2013-1253] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
13945| [CVE-2013-1252] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
13946| [CVE-2013-1251] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
13947| [CVE-2013-1250] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
13948| [CVE-2013-1249] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
13949| [CVE-2013-1248] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
13950| [CVE-2013-0095] Outlook in Microsoft Office for Mac 2008 before 12.3.6 and Office for Mac 2011 before 14.3.2 allows remote attackers to trigger access to a remote URL and consequently confirm the rendering of an HTML e-mail message by including unspecified HTML5 elements and leveraging the installation of a WebKit browser on the victim's machine, aka "Unintended Content Loading Vulnerability."
13951| [CVE-2013-0077] Quartz.dll in DirectShow in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows remote attackers to execute arbitrary code via crafted media content in (1) a media file, (2) a media stream, or (3) a Microsoft Office document, aka "Media Decompression Vulnerability."
13952| [CVE-2013-0076] The Client/Server Run-time Subsystem (CSRSS) in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Reference Count Vulnerability."
13953| [CVE-2013-0075] The TCP/IP implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows remote attackers to cause a denial of service (reboot) via a crafted packet that terminates a TCP connection, aka "TCP FIN WAIT Vulnerability."
13954| [CVE-2013-0073] The Windows Forms (aka WinForms) component in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly restrict the privileges of a callback function during object creation, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application, aka "WinForms Callback Elevation Vulnerability."
13955| [CVE-2013-0013] The SSL provider component in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle encrypted packets, which allows man-in-the-middle attackers to conduct SSLv2 downgrade attacks against (1) SSLv3 sessions or (2) TLS sessions by intercepting handshakes and injecting content, aka "Microsoft SSL Version 3 and TLS Protocol Security Feature Bypass Vulnerability."
13956| [CVE-2013-0011] The Print Spooler in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted print job, aka "Windows Print Spooler Components Vulnerability."
13957| [CVE-2013-0010] Cross-site scripting (XSS) vulnerability in Microsoft System Center Operations Manager 2007 SP1 and R2 allows remote attackers to inject arbitrary web script or HTML via crafted input, aka "System Center Operations Manager Web Console XSS Vulnerability," a different vulnerability than CVE-2013-0009.
13958| [CVE-2013-0009] Cross-site scripting (XSS) vulnerability in Microsoft System Center Operations Manager 2007 SP1 and R2 allows remote attackers to inject arbitrary web script or HTML via crafted input, aka "System Center Operations Manager Web Console XSS Vulnerability," a different vulnerability than CVE-2013-0010.
13959| [CVE-2013-0008] win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle window broadcast messages, which allows local users to gain privileges via a crafted application, aka "Win32k Improper Message Handling Vulnerability."
13960| [CVE-2013-0004] Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly validate the permissions of objects in memory, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application, aka "Double Construction Vulnerability."
13961| [CVE-2013-0003] Buffer overflow in a System.DirectoryServices.Protocols (S.DS.P) namespace method in Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, and 4.5 allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application that leverages a missing array-size check during a memory copy operation, aka "S.DS.P Buffer Overflow Vulnerability."
13962| [CVE-2013-0002] Buffer overflow in the Windows Forms (aka WinForms) component in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, and 4.5 allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application that leverages improper counting of objects during a memory copy operation, aka "WinForms Buffer Overflow Vulnerability."
13963| [CVE-2013-0001] The Windows Forms (aka WinForms) component in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 4, and 4.5 does not properly initialize memory arrays, which allows remote attackers to obtain sensitive information via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application that leverages a pointer to an unmanaged memory location, aka "System Drawing Information Disclosure Vulnerability."
13964| [CVE-2012-5672] Microsoft Excel Viewer (aka Xlview.exe) and Excel in Microsoft Office 2007 (aka Office 12) allow remote attackers to cause a denial of service (read access violation and application crash) via a crafted spreadsheet file, as demonstrated by a .xls file with battery voltage data.
13965| [CVE-2012-4791] Microsoft Exchange Server 2007 SP3 and 2010 SP1 and SP2 allows remote authenticated users to cause a denial of service (Information Store service hang) by subscribing to a crafted RSS feed, aka "RSS Feed May Cause Exchange DoS Vulnerability."
13966| [CVE-2012-4786] The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allow remote attackers to execute arbitrary code via a crafted TrueType Font (TTF) file, aka "TrueType Font Parsing Vulnerability."
13967| [CVE-2012-4776] The Web Proxy Auto-Discovery (WPAD) functionality in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not validate configuration data that is returned during acquisition of proxy settings, which allows remote attackers to execute arbitrary JavaScript code by providing crafted data during execution of (1) an XAML browser application (aka XBAP) or (2) a .NET Framework application, aka "Web Proxy Auto-Discovery Vulnerability."
13968| [CVE-2012-4774] Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allow remote attackers to execute arbitrary code via a crafted (1) file name or (2) subfolder name that triggers use of unallocated memory as the destination of a copy operation, aka "Windows Filename Parsing Vulnerability."
13969| [CVE-2012-2897] The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT, as used by Google Chrome before 22.0.1229.79 and other programs, do not properly handle objects in memory, which allows remote attackers to execute arbitrary code via a crafted TrueType font file, aka "Windows Font Parsing Vulnerability" or "TrueType Font Parsing Vulnerability."
13970| [CVE-2012-2556] The OpenType Font (OTF) driver in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows remote attackers to execute arbitrary code via a crafted OpenType font file, aka "OpenType Font Parsing Vulnerability."
13971| [CVE-2012-2553] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application, aka "Win32k Use After Free Vulnerability."
13972| [CVE-2012-2552] Cross-site scripting (XSS) vulnerability in the SQL Server Report Manager in Microsoft SQL Server 2000 Reporting Services SP2 and SQL Server 2005 SP4, 2008 SP2 and SP3, 2008 R2 SP1, and 2012 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka "Reflected XSS Vulnerability."
13973| [CVE-2012-2551] The server in Kerberos in Microsoft Windows Server 2008 R2 and R2 SP1, and Windows 7 Gold and SP1, allows remote attackers to cause a denial of service (NULL pointer dereference and reboot) via a crafted session request, aka "Kerberos NULL Dereference Vulnerability."
13974| [CVE-2012-2543] Stack-based buffer overflow in Microsoft Excel 2007 SP2 and SP3 and 2010 SP1
13975| [CVE-2012-2539] Microsoft Word 2003 SP3, 2007 SP2 and SP3, and 2010 SP1
13976| [CVE-2012-2536] Cross-site scripting (XSS) vulnerability in Microsoft Systems Management Server 2003 SP3 and System Center Configuration Manager 2007 SP2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Reflected XSS Vulnerability."
13977| [CVE-2012-2530] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application, aka "Win32k Use After Free Vulnerability."
13978| [CVE-2012-2529] Integer overflow in the kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages improper handling of objects in memory, aka "Windows Kernel Integer Overflow Vulnerability."
13979| [CVE-2012-2528] Use-after-free vulnerability in Microsoft Word 2003 SP3, 2007 SP2 and SP3, and 2010 SP1
13980| [CVE-2012-2527] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application, aka "Win32k Use After Free Vulnerability."
13981| [CVE-2012-2524] Microsoft Office 2007 SP2 and SP3 and 2010 SP1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Computer Graphics Metafile (CGM) file, aka "CGM File Format Memory Corruption Vulnerability."
13982| [CVE-2012-2520] Cross-site scripting (XSS) vulnerability in Microsoft InfoPath 2007 SP2 and SP3 and 2010 SP1, Communicator 2007 R2, Lync 2010 and 2010 Attendee, SharePoint Server 2007 SP2 and SP3 and 2010 SP1, Groove Server 2010 SP1, Windows SharePoint Services 3.0 SP2, SharePoint Foundation 2010 SP1, and Office Web Apps 2010 SP1 allows remote attackers to inject arbitrary web script or HTML via a crafted string, aka "HTML Sanitization Vulnerability."
13983| [CVE-2012-2519] Untrusted search path vulnerability in Entity Framework in ADO.NET in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, and 4 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .NET application, aka ".NET Framework Insecure Library Loading Vulnerability."
13984| [CVE-2012-1896] Microsoft .NET Framework 2.0 SP2 and 3.5.1 does not properly consider trust levels during construction of output data, which allows remote attackers to obtain sensitive information via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework application, aka "Code Access Security Info Disclosure Vulnerability."
13985| [CVE-2012-1895] The reflection implementation in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5.1, and 4 does not properly enforce object permissions, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework application, aka "Reflection Bypass Vulnerability."
13986| [CVE-2012-1893] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly validate callback parameters during creation of a hook procedure, which allows local users to gain privileges via a crafted application, aka "Win32k Incorrect Type Handling Vulnerability."
13987| [CVE-2012-1890] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle keyboard-layout files, which allows local users to gain privileges via a crafted application, aka "Keyboard Layout Vulnerability."
13988| [CVE-2012-1887] Use-after-free vulnerability in Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 SP1, and Office 2008 and 2011 for Mac, allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel SST Invalid Length Use After Free Vulnerability."
13989| [CVE-2012-1886] Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 SP1
13990| [CVE-2012-1885] Heap-based buffer overflow in Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 SP1
13991| [CVE-2012-1870] The CBC mode in the TLS protocol, as used in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and other products, allows remote web servers to obtain plaintext data by triggering multiple requests to a third-party HTTPS server and sniffing the network during the resulting HTTPS session, aka "TLS Protocol Vulnerability."
13992| [CVE-2012-1867] Integer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted TrueType font file that triggers incorrect memory allocation, aka "Font Resource Refcount Integer Overflow Vulnerability."
13993| [CVE-2012-1866] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle user-mode input passed to kernel mode for driver objects, which allows local users to gain privileges via a crafted application, aka "Clipboard Format Atom Name Handling Vulnerability."
13994| [CVE-2012-1865] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle user-mode input passed to kernel mode for driver objects, which allows local users to gain privileges via a crafted application, aka "String Atom Class Name Handling Vulnerability," a different vulnerability than CVE-2012-1864.
13995| [CVE-2012-1864] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle user-mode input passed to kernel mode for driver objects, which allows local users to gain privileges via a crafted application, aka "String Atom Class Name Handling Vulnerability," a different vulnerability than CVE-2012-1865.
13996| [CVE-2012-1863] Cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint Server 2007 SP2 and SP3 Windows SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via crafted JavaScript elements in a URL, aka "SharePoint Reflected List Parameter Vulnerability."
13997| [CVE-2012-1862] Open redirect vulnerability in Microsoft Office SharePoint Server 2007 SP2 and SP3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL, aka "SharePoint URL Redirection Vulnerability."
13998| [CVE-2012-1860] Microsoft Office SharePoint Server 2007 SP2 and SP3, SharePoint Server 2010 Gold and SP1, and Office Web Apps 2010 Gold and SP1 do not properly check permissions for search scopes, which allows remote authenticated users to obtain sensitive information or cause a denial of service (data modification) by changing a parameter in a search-scope URL, aka "SharePoint Search Scope Vulnerability."
13999| [CVE-2012-1858] The toStaticHTML API (aka the SafeHTML component) in Microsoft Internet Explorer 8 and 9, Communicator 2007 R2, and Lync 2010 and 2010 Attendee does not properly handle event attributes and script, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted HTML document, aka "HTML Sanitization Vulnerability."
14000| [CVE-2012-1856] The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office 2003 SP3, Office 2003 Web Components SP3, Office 2007 SP2 and SP3, Office 2010 SP1, SQL Server 2000 SP4, SQL Server 2005 SP4, SQL Server 2008 SP2, SP3, R2, R2 SP1, and R2 SP2, Commerce Server 2002 SP4, Commerce Server 2007 SP2, Commerce Server 2009 Gold and R2, Host Integration Server 2004 SP1, Visual FoxPro 8.0 SP1, Visual FoxPro 9.0 SP2, and Visual Basic 6.0 Runtime allows remote attackers to execute arbitrary code via a crafted (1) document or (2) web page that triggers system-state corruption, aka "MSCOMCTL.OCX RCE Vulnerability."
14001| [CVE-2012-1855] Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly handle function pointers, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework application, aka ".NET Framework Memory Access Vulnerability."
14002| [CVE-2012-1854] Untrusted search path vulnerability in VBE6.dll in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1
14003| [CVE-2012-1851] Format string vulnerability in the Print Spooler service in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted response, aka "Print Spooler Service Format String Vulnerability."
14004| [CVE-2012-1850] The Remote Administration Protocol (RAP) implementation in the LanmanWorkstation service in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle RAP responses, which allows remote attackers to cause a denial of service (service hang) via crafted RAP packets, aka "Remote Administration Protocol Denial of Service Vulnerability."
14005| [CVE-2012-1848] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview does not properly handle user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application, aka "Scrollbar Calculation Vulnerability."
14006| [CVE-2012-1847] Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1
14007| [CVE-2012-1537] Heap-based buffer overflow in DirectPlay in DirectX 9.0 through 11.1 in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 allows remote attackers to execute arbitrary code via a crafted Office document, aka "DirectPlay Heap Overflow Vulnerability."
14008| [CVE-2012-1528] Integer overflow in Windows Shell in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 allows local users to gain privileges via a crafted briefcase, aka "Windows Briefcase Integer Overflow Vulnerability."
14009| [CVE-2012-1527] Integer underflow in Windows Shell in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 allows local users to gain privileges via a crafted briefcase, aka "Windows Briefcase Integer Underflow Vulnerability."
14010| [CVE-2012-1459] The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, ClamAV 0.96.4, Command Antivirus 5.2.11.5, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, F-Prot Antivirus 4.6.2.117, F-Secure Anti-Virus 9.0.16160.0, Fortinet Antivirus 4.2.254.0, G Data AntiVirus 21, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, nProtect Anti-Virus 2011-01-17.01, Panda Antivirus 10.0.2.7, PC Tools AntiVirus 7.0.3.5, Rising Antivirus 22.83.00.03, Sophos Anti-Virus 4.61.0, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, Trend Micro HouseCall 9.120.0.1004, VBA32 3.12.14.2, and VirusBuster 13.6.151.0 allows remote attackers to bypass malware detection via a TAR archive entry with a length field corresponding to that entire entry, plus part of the header of the next entry. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.
14011| [CVE-2012-1457] The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, ClamAV 0.96.4, Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, G Data AntiVirus 21, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, PC Tools AntiVirus 7.0.3.5, Rising Antivirus 22.83.00.03, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, Trend Micro HouseCall 9.120.0.1004, VBA32 3.12.14.2, and VirusBuster 13.6.151.0 allows remote attackers to bypass malware detection via a TAR archive entry with a length field that exceeds the total TAR file size. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.
14012| [CVE-2012-1453] The CAB file parser in Dr.Web 5.0.2.03300, Trend Micro HouseCall 9.120.0.1004, Kaspersky Anti-Virus 7.0.0.125, Sophos Anti-Virus 4.61.0, Trend Micro AntiVirus 9.120.0.1004, McAfee Gateway (formerly Webwasher) 2010.1C, Emsisoft Anti-Malware 5.1.0.1, CA eTrust Vet Antivirus 36.1.8511, Antiy Labs AVL SDK 2.0.3.7, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, Rising Antivirus 22.83.00.03, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via a CAB file with a modified coffFiles field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different CAB parser implementations.
14013| [CVE-2012-1443] The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Command Antivirus 5.2.11.5, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Emsisoft Anti-Malware 5.1.0.1, PC Tools AntiVirus 7.0.3.5, F-Prot Antivirus 4.6.2.117, VirusBuster 13.6.151.0, Fortinet Antivirus 4.2.254.0, Antiy Labs AVL SDK 2.0.3.7, K7 AntiVirus 9.77.3565, Trend Micro HouseCall 9.120.0.1004, Kaspersky Anti-Virus 7.0.0.125, Jiangmin Antivirus 13.0.900, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, Sophos Anti-Virus 4.61.0, NOD32 Antivirus 5795, Avira AntiVir 7.11.1.163, Norman Antivirus 6.06.12, McAfee Anti-Virus Scanning Engine 5.400.0.1158, Panda Antivirus 10.0.2.7, McAfee Gateway (formerly Webwasher) 2010.1C, Trend Micro AntiVirus 9.120.0.1004, Comodo Antivirus 7424, Bitdefender 7.2, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.0, nProtect Anti-Virus 2011-01-17.01, AhnLab V3 Internet Security 2011.01.18.00, AVG Anti-Virus 10.0.0.1190, avast! Antivirus 4.8.1351.0 and 5.0.677.0, and VBA32 3.12.14.2 allows user-assisted remote attackers to bypass malware detection via a RAR file with an initial MZ character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different RAR parser implementations.
14014| [CVE-2012-1420] The TAR file parser in Quick Heal (aka Cat QuickHeal) 11.00, Command Antivirus 5.2.11.5, F-Prot Antivirus 4.6.2.117, Fortinet Antivirus 4.2.254.0, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, Panda Antivirus 10.0.2.7, and Rising Antivirus 22.83.00.03 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial \7fELF character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.
14015| [CVE-2012-1194] The resolver in the DNS Server service in Microsoft Windows Server 2008 before R2 overwrites cached server names and TTL values in NS records during the processing of a response to an A record query, which allows remote attackers to trigger continued resolvability of revoked domain names via a "ghost domain names" attack.
14016| [CVE-2012-0185] Heap-based buffer overflow in Microsoft Excel 2007 SP2 and SP3 and 2010 Gold and SP1, Excel Viewer, and Office Compatibility Pack SP2 and SP3 allows remote attackers to execute arbitrary code via a crafted spreadsheet that triggers incorrect handling of memory during opening, aka "Excel MergeCells Record Heap Overflow Vulnerability."
14017| [CVE-2012-0184] Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1
14018| [CVE-2012-0183] Microsoft Word 2003 SP3 and 2007 SP2 and SP3, Office 2008 and 2011 for Mac, and Office Compatibility Pack SP2 and SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted RTF data, aka "RTF Mismatch Vulnerability."
14019| [CVE-2012-0182] Microsoft Word 2007 SP2 and SP3 does not properly handle memory during the parsing of Word documents, which allows remote attackers to execute arbitrary code via a crafted document, aka "Word PAPX Section Corruption Vulnerability."
14020| [CVE-2012-0181] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview does not properly manage Keyboard Layout files, which allows local users to gain privileges via a crafted application, aka "Keyboard Layout File Vulnerability."
14021| [CVE-2012-0180] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview does not properly handle user-mode input passed to kernel mode for (1) windows and (2) messages, which allows local users to gain privileges via a crafted application, aka "Windows and Messages Vulnerability."
14022| [CVE-2012-0179] Double free vulnerability in tcpip.sys in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that binds an IPv6 address to a local interface, aka "TCP/IP Double Free Vulnerability."
14023| [CVE-2012-0178] Race condition in partmgr.sys in Windows Partition Manager in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that makes multiple simultaneous Plug and Play (PnP) Configuration Manager function calls, aka "Plug and Play (PnP) Configuration Manager Vulnerability."
14024| [CVE-2012-0177] Heap-based buffer overflow in the Office Works File Converter in Microsoft Office 2007 SP2, Works 9, and Works 6-9 File Converter allows remote attackers to execute arbitrary code via a crafted Works (aka .wps) file, aka "Office WPS Converter Heap Overflow Vulnerability."
14025| [CVE-2012-0175] The Shell in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted name for a (1) file or (2) directory, aka "Command Injection Vulnerability."
14026| [CVE-2012-0174] Windows Firewall in tcpip.sys in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly enforce firewall rules for outbound broadcast packets, which allows remote attackers to obtain potentially sensitive information by observing broadcast traffic on a local network, aka "Windows Firewall Bypass Vulnerability."
14027| [CVE-2012-0173] The Remote Desktop Protocol (RDP) implementation in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly process packets in memory, which allows remote attackers to execute arbitrary code by sending crafted RDP packets triggering access to an object that (1) was not properly initialized or (2) is deleted, aka "Remote Desktop Protocol Vulnerability," a different vulnerability than CVE-2012-0002.
14028| [CVE-2012-0167] Heap-based buffer overflow in the Office GDI+ library in Microsoft Office 2003 SP3 and 2007 SP2 and SP3 allows remote attackers to execute arbitrary code via a crafted EMF image in an Office document, aka "GDI+ Heap Overflow Vulnerability."
14029| [CVE-2012-0165] GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2 and Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1 does not properly validate record types in EMF images, which allows remote attackers to execute arbitrary code via a crafted image, aka "GDI+ Record Type Vulnerability."
14030| [CVE-2012-0163] Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly validate function parameters, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka ".NET Framework Parameter Validation Vulnerability."
14031| [CVE-2012-0161] Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5 SP1, 3.5.1, and 4 does not properly handle an unspecified exception during use of partially trusted assemblies to serialize input data, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework application, aka ".NET Framework Serialization Vulnerability."
14032| [CVE-2012-0160] Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5 SP1, 3.5.1, and 4 does not properly serialize input data, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework application, aka ".NET Framework Serialization Vulnerability."
14033| [CVE-2012-0159] Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview
14034| [CVE-2012-0158] The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1
14035| [CVE-2012-0157] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle window messaging, which allows local users to gain privileges via a crafted application that calls the PostMessage function, aka "PostMessage Function Vulnerability."
14036| [CVE-2012-0156] DirectWrite in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly render Unicode characters, which allows remote attackers to cause a denial of service (application hang) via a (1) instant message or (2) web site, aka "DirectWrite Application Denial of Service Vulnerability."
14037| [CVE-2012-0154] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers keyboard layout errors, aka "Keyboard Layout Use After Free Vulnerability."
14038| [CVE-2012-0152] The Remote Desktop Protocol (RDP) service in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows remote attackers to cause a denial of service (application hang) via a series of crafted packets, aka "Terminal Server Denial of Service Vulnerability."
14039| [CVE-2012-0151] The Authenticode Signature Verification function in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview does not properly validate the digest of a signed portable executable (PE) file, which allows user-assisted remote attackers to execute arbitrary code via a modified file with additional content, aka "WinVerifyTrust Signature Validation Vulnerability."
14040| [CVE-2012-0150] Buffer overflow in msvcrt.dll in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted media file, aka "Msvcrt.dll Buffer Overflow Vulnerability."
14041| [CVE-2012-0149] afd.sys in the Ancillary Function Driver in Microsoft Windows Server 2003 SP2 does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application, aka "Ancillary Function Driver Elevation of Privilege Vulnerability."
14042| [CVE-2012-0148] afd.sys in the Ancillary Function Driver in Microsoft Windows XP SP2, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 on 64-bit platforms does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application, aka "AfdPoll Elevation of Privilege Vulnerability."
14043| [CVE-2012-0143] Microsoft Excel 2003 SP3 and Office 2008 for Mac do not properly handle memory during the opening of files, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel Memory Corruption Using Various Modified Bytes Vulnerability."
14044| [CVE-2012-0142] Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1
14045| [CVE-2012-0141] Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1
14046| [CVE-2012-0015] Microsoft .NET Framework 2.0 SP2 and 3.5.1 does not properly calculate the length of an unspecified buffer, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka ".NET Framework Heap Corruption Vulnerability."
14047| [CVE-2012-0014] Microsoft .NET Framework 2.0 SP2, 3.5.1, and 4, and Silverlight 4 before 4.1.10111, does not properly restrict access to memory associated with unmanaged objects, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, (3) a crafted .NET Framework application, or (4) a crafted Silverlight application, aka ".NET Framework Unmanaged Objects Vulnerability."
14048| [CVE-2012-0013] Incomplete blacklist vulnerability in the Windows Packager configuration in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted ClickOnce application in a Microsoft Office document, related to .application files, aka "Assembly Execution Vulnerability."
14049| [CVE-2012-0009] Untrusted search path vulnerability in the Windows Object Packager configuration in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a Trojan horse executable file in the current working directory, as demonstrated by a directory that contains a file with an embedded packaged object, aka "Object Packager Insecure Executable Launching Vulnerability."
14050| [CVE-2012-0008] Untrusted search path vulnerability in Microsoft Visual Studio 2008 SP1, 2010, and 2010 SP1 allows local users to gain privileges via a Trojan horse add-in in an unspecified directory, aka "Visual Studio Add-In Vulnerability."
14051| [CVE-2012-0006] The DNS server in Microsoft Windows Server 2003 SP2 and Server 2008 SP2, R2, and R2 SP1 does not properly handle objects in memory during record lookup, which allows remote attackers to cause a denial of service (daemon restart) via a crafted query, aka "DNS Denial of Service Vulnerability."
14052| [CVE-2012-0005] The Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP2, and Server 2008 SP2, when a Chinese, Japanese, or Korean system locale is used, can access uninitialized memory during the processing of Unicode characters, which allows local users to gain privileges via a crafted application, aka "CSRSS Elevation of Privilege Vulnerability."
14053| [CVE-2012-0004] Unspecified vulnerability in DirectShow in DirectX in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted media file, related to Quartz.dll, Qdvd.dll, closed captioning, and the Line21 DirectShow filter, aka "DirectShow Remote Code Execution Vulnerability."
14054| [CVE-2012-0003] Unspecified vulnerability in winmm.dll in Windows Multimedia Library in Windows Media Player (WMP) in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows remote attackers to execute arbitrary code via a crafted MIDI file, aka "MIDI Remote Code Execution Vulnerability."
14055| [CVE-2012-0002] The Remote Desktop Protocol (RDP) implementation in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly process packets in memory, which allows remote attackers to execute arbitrary code by sending crafted RDP packets triggering access to an object that (1) was not properly initialized or (2) is deleted, aka "Remote Desktop Protocol Vulnerability."
14056| [CVE-2012-0001] The kernel in Microsoft Windows XP SP2, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly load structured exception handling tables, which allows context-dependent attackers to bypass the SafeSEH security feature by leveraging a Visual C++ .NET 2003 application, aka "Windows Kernel SafeSEH Bypass Vulnerability."
14057| [CVE-2011-5046] The Graphics Device Interface (GDI) in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly validate user-mode input, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted data, as demonstrated by a large height attribute of an IFRAME element rendered by Safari, aka "GDI Access Violation Vulnerability."
14058| [CVE-2011-4434] Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 do not properly enforce AppLocker rules, which allows local users to bypass intended access restrictions via a (1) macro or (2) scripting feature in an application, as demonstrated by Microsoft Office applications and the SANDBOX_INERT and LOAD_IGNORE_CODE_AUTHZ_LEVEL flags.
14059| [CVE-2011-3417] The Forms Authentication feature in the ASP.NET subsystem in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0, when sliding expiry is enabled, does not properly handle cached content, which allows remote attackers to obtain access to arbitrary user accounts via a crafted URL, aka "ASP.NET Forms Authentication Ticket Caching Vulnerability."
14060| [CVE-2011-3416] The Forms Authentication feature in the ASP.NET subsystem in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0 allows remote authenticated users to obtain access to arbitrary user accounts via a crafted username, aka "ASP.Net Forms Authentication Bypass Vulnerability."
14061| [CVE-2011-3415] Open redirect vulnerability in the Forms Authentication feature in the ASP.NET subsystem in Microsoft .NET Framework 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted return URL, aka "Insecure Redirect in .NET Form Authentication Vulnerability."
14062| [CVE-2011-3414] The CaseInsensitiveHashProvider.getHashCode function in the HashTable implementation in the ASP.NET subsystem in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters, aka "Collisions in HashTable May Cause DoS Vulnerability."
14063| [CVE-2011-3413] Microsoft PowerPoint 2007 SP2
14064| [CVE-2011-3412] Microsoft Publisher 2003 SP3, and 2007 SP2 and SP3, allows remote attackers to execute arbitrary code via a crafted Publisher file that leverages incorrect memory handling, aka "Publisher Memory Corruption Vulnerability."
14065| [CVE-2011-3411] Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that leverages incorrect handling of values in memory, aka "Publisher Invalid Pointer Vulnerability."
14066| [CVE-2011-3410] Array index error in Microsoft Publisher 2003 SP3, and 2007 SP2 and SP3, allows remote attackers to execute arbitrary code via a crafted Publisher file that leverages incorrect handling of values in memory, aka "Publisher Out-of-bounds Array Index Vulnerability."
14067| [CVE-2011-3408] Csrsrv.dll in the Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly check permissions for sending inter-process device-event messages from low-integrity processes to high-integrity processes, which allows local users to gain privileges via a crafted application, aka "CSRSS Local Privilege Elevation Vulnerability."
14068| [CVE-2011-3406] Buffer overflow in Active Directory, Active Directory Application Mode (ADAM), and Active Directory Lightweight Directory Service (AD LDS) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote authenticated users to execute arbitrary code via a crafted query that leverages incorrect memory initialization, aka "Active Directory Buffer Overflow Vulnerability."
14069| [CVE-2011-3403] Microsoft Excel 2003 SP3 and Office 2004 for Mac do not properly handle objects in memory, which allows remote attackers to execute arbitrary code via a crafted Excel spreadsheet, aka "Record Memory Corruption Vulnerability."
14070| [CVE-2011-3402] Unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via crafted font data in a Word document or web page, as exploited in the wild in November 2011 by Duqu, aka "TrueType Font Parsing Vulnerability."
14071| [CVE-2011-3400] Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 do not properly handle OLE objects in memory, which allows remote attackers to execute arbitrary code via a crafted object in a file, aka "OLE Property Vulnerability."
14072| [CVE-2011-3397] The Microsoft Time component in DATIME.DLL in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted web site that leverages an unspecified "binary behavior" in Internet Explorer, aka "Microsoft Time Remote Code Execution Vulnerability."
14073| [CVE-2011-3396] Untrusted search path vulnerability in Microsoft PowerPoint 2007 SP2 and 2010 allows local users to gain privileges via a Trojan horse DLL in the current working directory, aka "PowerPoint Insecure Library Loading Vulnerability."
14074| [CVE-2011-2019] Untrusted search path vulnerability in Microsoft Internet Explorer 9 on Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains an HTML file, aka "Internet Explorer Insecure Library Loading Vulnerability."
14075| [CVE-2011-2018] The kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, and Windows 7 Gold and SP1 does not properly initialize objects, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Exception Handler Vulnerability."
14076| [CVE-2011-2016] Untrusted search path vulnerability in Windows Mail and Windows Meeting Space in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .eml or .wcinv file, aka "Windows Mail Insecure Library Loading Vulnerability."
14077| [CVE-2011-2014] The LDAP over SSL (aka LDAPS) implementation in Active Directory, Active Directory Application Mode (ADAM), and Active Directory Lightweight Directory Service (AD LDS) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not examine Certificate Revocation Lists (CRLs), which allows remote authenticated users to bypass intended certificate restrictions and access Active Directory resources by leveraging a revoked X.509 certificate for a domain account, aka "LDAPS Authentication Bypass Vulnerability."
14078| [CVE-2011-2013] Integer overflow in the TCP/IP implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code by sending a sequence of crafted UDP packets to a closed port, aka "Reference Counter Overflow Vulnerability."
14079| [CVE-2011-2011] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, aka "Win32k Use After Free Vulnerability."
14080| [CVE-2011-2008] Microsoft Host Integration Server (HIS) 2004 SP1, 2006 SP1, 2009, and 2010 allows remote attackers to cause a denial of service (SNA Server service outage) via crafted TCP or UDP traffic, aka "Access of Unallocated Memory DoS Vulnerability."
14081| [CVE-2011-2007] Microsoft Host Integration Server (HIS) 2004 SP1, 2006 SP1, 2009, and 2010 allows remote attackers to cause a denial of service (SNA Server service outage) via crafted TCP or UDP traffic, aka "Endless Loop DoS in snabase.exe Vulnerability."
14082| [CVE-2011-2005] afd.sys in the Ancillary Function Driver in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application, aka "Ancillary Function Driver Elevation of Privilege Vulnerability."
14083| [CVE-2011-2004] Array index error in win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows remote attackers to cause a denial of service (reboot) via a crafted TrueType font file, aka "TrueType Font Parsing Vulnerability," a different vulnerability than CVE-2011-3402.
14084| [CVE-2011-2003] Buffer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted .fon file, aka "Font Library File Buffer Overrun Vulnerability."
14085| [CVE-2011-2002] win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle TrueType fonts, which allows local users to cause a denial of service (system hang) via a crafted font file, aka "Win32k TrueType Font Type Translation Vulnerability."
14086| [CVE-2011-1991] Multiple untrusted search path vulnerabilities in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allow local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .doc, .rtf, or .txt file, related to (1) deskpan.dll in the Display Panning CPL Extension, (2) EAPHost Authenticator Service, (3) Folder Redirection, (4) HyperTerminal, (5) the Japanese Input Method Editor (IME), and (6) Microsoft Management Console (MMC), aka "Windows Components Insecure Library Loading Vulnerability."
14087| [CVE-2011-1990] Microsoft Excel 2007 SP2
14088| [CVE-2011-1989] Microsoft Excel 2003 SP3 and 2007 SP2
14089| [CVE-2011-1988] Microsoft Excel 2003 SP3 and 2007 SP2
14090| [CVE-2011-1987] Array index error in Microsoft Excel 2003 SP3 and 2007 SP2
14091| [CVE-2011-1986] Use-after-free vulnerability in Microsoft Excel 2003 SP3 allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel Use after Free WriteAV Vulnerability."
14092| [CVE-2011-1985] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly validate user-mode input, which allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via a crafted application, aka "Win32k Null Pointer De-reference Vulnerability."
14093| [CVE-2011-1984] WINS in Microsoft Windows Server 2003 SP2 and Server 2008 SP2, R2, and R2 SP1 allows local users to gain privileges by sending crafted packets over the loopback interface, aka "WINS Local Elevation of Privilege Vulnerability."
14094| [CVE-2011-1983] Use-after-free vulnerability in Microsoft Office 2007 SP2 and SP3, Office 2010 Gold and SP1, and Office for Mac 2011 allows remote attackers to execute arbitrary code via a crafted Word document, aka "Word Use After Free Vulnerability."
14095| [CVE-2011-1982] Microsoft Office 2007 SP2, and 2010 Gold and SP1, does not initialize an unspecified object pointer during the opening of Word documents, which allows remote attackers to execute arbitrary code via a crafted document, aka "Office Uninitialized Object Pointer Vulnerability."
14096| [CVE-2011-1980] Untrusted search path vulnerability in Microsoft Office 2003 SP3 and 2007 SP2 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .doc, .ppt, or .xls file, aka "Office Component Insecure Library Loading Vulnerability."
14097| [CVE-2011-1979] Microsoft Visio 2003 SP3 and 2007 SP2 does not properly validate objects in memory during Visio file parsing, which allows remote attackers to execute arbitrary code via a crafted file, aka "Move Around the Block RCE Vulnerability."
14098| [CVE-2011-1978] Microsoft .NET Framework 2.0 SP2, 3.5.1, and 4 does not properly validate the System.Net.Sockets trust level, which allows remote attackers to obtain sensitive information or trigger arbitrary outbound network traffic via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "Socket Restriction Bypass Vulnerability."
14099| [CVE-2011-1976] Cross-site scripting (XSS) vulnerability in the Report Viewer Control in Microsoft Visual Studio 2005 SP1 and Report Viewer 2005 SP1 allows remote attackers to inject arbitrary web script or HTML via a parameter in a data source, aka "Report Viewer Controls XSS Vulnerability."
14100| [CVE-2011-1975] Untrusted search path vulnerability in the Data Access Tracing component in Windows Data Access Components (Windows DAC) 6.0 in Microsoft Windows 7 Gold and SP1 and Windows Server 2008 R2 and R2 SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains an Excel .xlsx file, aka "Data Access Components Insecure Library Loading Vulnerability."
14101| [CVE-2011-1974] NDISTAPI.sys in the NDISTAPI driver in Remote Access Service (RAS) in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP2 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "NDISTAPI Elevation of Privilege Vulnerability."
14102| [CVE-2011-1972] Microsoft Visio 2003 SP3, 2007 SP2, and 2010 Gold and SP1 does not properly validate objects in memory during Visio file parsing, which allows remote attackers to execute arbitrary code via a crafted file, aka "pStream Release RCE Vulnerability."
14103| [CVE-2011-1971] The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly parse file metadata, which allows local users to cause a denial of service (reboot) via a crafted file, aka "Windows Kernel Metadata Parsing DOS Vulnerability."
14104| [CVE-2011-1970] The DNS server in Microsoft Windows Server 2003 SP2 and Windows Server 2008 SP2, R2, and R2 SP1 does not properly initialize memory, which allows remote attackers to cause a denial of service (service outage) via a query for a nonexistent domain, aka "DNS Uninitialized Memory Corruption Vulnerability."
14105| [CVE-2011-1968] The Remote Desktop Protocol (RDP) implementation in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP2 does not properly process packets in memory, which allows remote attackers to cause a denial of service (reboot) by sending crafted RDP packets triggering access to an object that (1) was not properly initialized or (2) is deleted, as exploited in the wild in 2011, aka "Remote Desktop Protocol Vulnerability."
14106| [CVE-2011-1967] Winsrv.dll in the Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly check permissions for sending inter-process device-event messages from low-integrity processes to high-integrity processes, which allows local users to gain privileges via a crafted application, aka "CSRSS Vulnerability."
14107| [CVE-2011-1966] The DNS server in Microsoft Windows Server 2008 SP2, R2, and R2 SP1 does not properly handle NAPTR queries that trigger recursive processing, which allows remote attackers to execute arbitrary code via a crafted query, aka "DNS NAPTR Query Vulnerability."
14108| [CVE-2011-1965] Tcpip.sys in the TCP/IP stack in Microsoft Windows 7 Gold and SP1 and Windows Server 2008 R2 and R2 SP1 does not properly implement URL-based QoS, which allows remote attackers to cause a denial of service (reboot) via a crafted URL to a web server, aka "TCP/IP QOS Denial of Service Vulnerability."
14109| [CVE-2011-1894] The MHTML protocol handler in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle a MIME format in a request for embedded content in an HTML document, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted EMBED element in a web page that is visited in Internet Explorer, aka "MHTML Mime-Formatted Request Vulnerability."
14110| [CVE-2011-1893] Cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint Server 2010, Windows SharePoint Services 2.0 and 3.0 SP2, and SharePoint Foundation 2010 allows remote attackers to inject arbitrary web script or HTML via the URI, aka "SharePoint XSS Vulnerability."
14111| [CVE-2011-1892] Microsoft Office Groove 2007 SP2, SharePoint Workspace 2010 Gold and SP1, Office Forms Server 2007 SP2, Office SharePoint Server 2007 SP2, Office SharePoint Server 2010 Gold and SP1, Office Groove Data Bridge Server 2007 SP2, Office Groove Management Server 2007 SP2, Groove Server 2010 Gold and SP1, Windows SharePoint Services 3.0 SP2, SharePoint Foundation 2010, and Office Web Apps 2010 Gold and SP1 do not properly handle Web Parts containing XML classes referencing external entities, which allows remote authenticated users to read arbitrary files via a crafted XML and XSL file, aka "SharePoint Remote File Disclosure Vulnerability."
14112| [CVE-2011-1888] win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Null Pointer De-reference Vulnerability."
14113| [CVE-2011-1887] win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Null Pointer De-reference Vulnerability."
14114| [CVE-2011-1885] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Null Pointer De-reference Vulnerability."
14115| [CVE-2011-1884] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Use After Free Vulnerability."
14116| [CVE-2011-1883] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Use After Free Vulnerability."
14117| [CVE-2011-1882] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Use After Free Vulnerability."
14118| [CVE-2011-1881] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Null Pointer De-reference Vulnerability."
14119| [CVE-2011-1880] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Null Pointer De-reference Vulnerability."
14120| [CVE-2011-1879] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Use After Free Vulnerability."
14121| [CVE-2011-1878] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Use After Free Vulnerability."
14122| [CVE-2011-1877] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, aka "Win32k Use After Free Vulnerability."
14123| [CVE-2011-1876] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Use After Free Vulnerability."
14124| [CVE-2011-1875] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Use After Free Vulnerability."
14125| [CVE-2011-1874] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other CVEs listed in MS11-054, aka "Win32k Use After Free Vulnerability."
14126| [CVE-2011-1873] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 on 64-bit platforms does not properly validate pointers during the parsing of OpenType (aka OTF) fonts, which allows remote attackers to execute arbitrary code via a crafted font file, aka "Win32k OTF Validation Vulnerability."
14127| [CVE-2011-1872] Hyper-V in Microsoft Windows Server 2008 Gold, SP2, R2, and R2 SP1 allows guest OS users to cause a denial of service (host OS infinite loop) via malformed machine instructions in a VMBus packet, aka "VMBus Persistent DoS Vulnerability."
14128| [CVE-2011-1871] Tcpip.sys in the TCP/IP stack in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to cause a denial of service (reboot) via a series of crafted ICMP messages, aka "ICMP Denial of Service Vulnerability."
14129| [CVE-2011-1870] Integer overflow in the Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, and Windows Server 2003 SP2, allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application that triggers an incorrect memory assignment for a user transaction, aka "CSRSS Local EOP SrvWriteConsoleOutputString Vulnerability."
14130| [CVE-2011-1869] The Distributed File System (DFS) implementation in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote DFS servers to cause a denial of service (system hang) via a crafted referral response, aka "DFS Referral Response Vulnerability."
14131| [CVE-2011-1868] The Distributed File System (DFS) implementation in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly validate fields in DFS responses, which allows remote DFS servers to execute arbitrary code via a crafted response, aka "DFS Memory Corruption Vulnerability."
14132| [CVE-2011-1508] Microsoft Publisher 2003 SP3, and 2007 SP2 and SP3, does not properly manage memory allocations for function pointers, which allows user-assisted remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Function Pointer Overwrite Vulnerability."
14133| [CVE-2011-1284] Integer overflow in the Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application that triggers an incorrect memory assignment for a user transaction, aka "CSRSS Local EOP SrvWriteConsoleOutput Vulnerability."
14134| [CVE-2011-1283] The Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, and Windows Server 2008 Gold and SP2 does not ensure that an unspecified array index has a non-negative value before performing read and write operations, which allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application that triggers an incorrect memory assignment for a user transaction, aka "CSRSS Local EOP SrvSetConsoleNumberOfCommand Vulnerability."
14135| [CVE-2011-1282] The Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly initialize memory and consequently uses a NULL pointer in an unspecified function call, which allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application that triggers an incorrect memory assignment for a user transaction, aka "CSRSS Local EOP SrvSetConsoleLocalEUDC Vulnerability."
14136| [CVE-2011-1281] The Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly restrict the number of console objects for a process, which allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application that triggers an incorrect memory assignment for a user transaction, aka "CSRSS Local EOP AllocConsole Vulnerability."
14137| [CVE-2011-1280] The XML Editor in Microsoft InfoPath 2007 SP2 and 2010
14138| [CVE-2011-1279] Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information during parsing of Excel spreadsheets, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted spreadsheet, aka "Excel Out of Bounds WriteAV Vulnerability."
14139| [CVE-2011-1278] Microsoft Excel 2002 SP3 and Office 2004 for Mac do not properly validate record information during parsing of Excel spreadsheets, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted spreadsheet, aka "Excel WriteAV Vulnerability."
14140| [CVE-2011-1277] Microsoft Excel 2002 SP3, Office 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information during parsing of Excel spreadsheets, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted spreadsheet, aka "Excel Memory Corruption Vulnerability."
14141| [CVE-2011-1276] Buffer overflow in Microsoft Excel 2002 SP3, 2003 SP3, and 2007 SP2
14142| [CVE-2011-1275] Microsoft Excel 2002 SP3
14143| [CVE-2011-1274] Microsoft Excel 2002 SP3, 2003 SP3, and 2007 SP2
14144| [CVE-2011-1273] Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP2, and 2010
14145| [CVE-2011-1272] Microsoft Excel 2002 SP3, 2003 SP3, and 2007 SP2
14146| [CVE-2011-1270] Buffer overflow in Microsoft PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "Presentation Buffer Overrun RCE Vulnerability."
14147| [CVE-2011-1269] Microsoft PowerPoint 2002 SP3, 2003 SP3, and 2007 SP2
14148| [CVE-2011-1268] The SMB client in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote SMB servers to execute arbitrary code via a crafted (1) SMBv1 or (2) SMBv2 response, aka "SMB Response Parsing Vulnerability."
14149| [CVE-2011-1267] The SMB server in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to cause a denial of service (system hang) via a crafted (1) SMBv1 or (2) SMBv2 request, aka "SMB Request Parsing Vulnerability."
14150| [CVE-2011-1264] Cross-site scripting (XSS) vulnerability in Active Directory Certificate Services Web Enrollment in Microsoft Windows Server 2003 SP2 and Server 2008 Gold, SP2, R2, and R2 SP1 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka "Active Directory Certificate Services Vulnerability."
14151| [CVE-2011-1263] Cross-site scripting (XSS) vulnerability in the logon page in Remote Desktop Web Access (RD Web Access) in Microsoft Windows Server 2008 R2 and R2 SP1 allows remote attackers to inject arbitrary web script or HTML via the URI, aka "Remote Desktop Web Access Vulnerability."
14152| [CVE-2011-1253] Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5.1, and 4, and Silverlight 4 before 4.0.60831, does not properly restrict inheritance, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, (3) a crafted .NET Framework application, or (4) a crafted Silverlight application, aka ".NET Framework Class Inheritance Vulnerability."
14153| [CVE-2011-1252] Cross-site scripting (XSS) vulnerability in the SafeHTML function in the toStaticHTML API in Microsoft Internet Explorer 7 and 8, Office SharePoint Server 2007 SP2, Office SharePoint Server 2010 Gold and SP1, Groove Server 2010 Gold and SP1, Windows SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via unspecified strings, aka "toStaticHTML Information Disclosure Vulnerability" or "HTML Sanitization Vulnerability."
14154| [CVE-2011-1249] The Ancillary Function Driver (AFD) in afd.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Ancillary Function Driver Elevation of Privilege Vulnerability."
14155| [CVE-2011-1248] WINS in Microsoft Windows Server 2003 SP2 and Server 2008 Gold, SP2, R2, and R2 SP1 does not properly handle socket send exceptions, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted packets, related to unintended stack-frame values and buffer passing, aka "WINS Service Failed Response Vulnerability."
14156| [CVE-2011-1247] Untrusted search path vulnerability in the Microsoft Active Accessibility component in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, aka "Active Accessibility Insecure Library Loading Vulnerability."
14157| [CVE-2011-1242] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
14158| [CVE-2011-1241] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
14159| [CVE-2011-1240] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
14160| [CVE-2011-1239] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
14161| [CVE-2011-1238] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
14162| [CVE-2011-1237] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
14163| [CVE-2011-1236] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
14164| [CVE-2011-1235] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
14165| [CVE-2011-1234] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
14166| [CVE-2011-1233] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
14167| [CVE-2011-1232] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
14168| [CVE-2011-1231] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
14169| [CVE-2011-1230] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
14170| [CVE-2011-1229] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
14171| [CVE-2011-1228] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
14172| [CVE-2011-1227] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
14173| [CVE-2011-1226] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
14174| [CVE-2011-1225] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
14175| [CVE-2011-0980] Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly parse Office Art objects, which allows remote attackers to execute arbitrary code via vectors related to a function pointer, aka "Excel Dangling Pointer Vulnerability."
14176| [CVE-2011-0979] Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP2, and 2010
14177| [CVE-2011-0978] Stack-based buffer overflow in Microsoft Excel 2002 SP3, 2003 SP3, and 2007 SP2
14178| [CVE-2011-0977] Use-after-free vulnerability in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via malformed shape data in the Office drawing file format, aka "Microsoft Office Graphic Object Dereferencing Vulnerability."
14179| [CVE-2011-0976] Microsoft PowerPoint 2002 SP3, 2003 SP3, and 2007 SP2
14180| [CVE-2011-0677] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
14181| [CVE-2011-0676] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
14182| [CVE-2011-0675] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
14183| [CVE-2011-0674] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
14184| [CVE-2011-0672] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
14185| [CVE-2011-0671] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
14186| [CVE-2011-0670] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
14187| [CVE-2011-0667] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
14188| [CVE-2011-0666] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
14189| [CVE-2011-0665] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
14190| [CVE-2011-0664] Microsoft .NET Framework 2.0 SP1 and SP2, 3.5 Gold and SP1, 3.5.1, and 4.0, and Silverlight 4 before 4.0.60531.0, does not properly validate arguments to unspecified networking API functions, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, (3) a crafted .NET Framework application, or (4) a crafted Silverlight application, aka ".NET Framework Array Offset Vulnerability."
14191| [CVE-2011-0662] Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."
14192| [CVE-2011-0661] The SMB Server service in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly validate fields in SMB requests, which allows remote attackers to execute arbitrary code via a malformed request in a (1) SMBv1 or (2) SMBv2 packet, aka "SMB Transaction Parsing Vulnerability."
14193| [CVE-2011-0660] The SMB client in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote SMB servers to execute arbitrary code via a crafted (1) SMBv1 or (2) SMBv2 response, aka "SMB Client Response Parsing Vulnerability."
14194| [CVE-2011-0658] Integer underflow in the OLE Automation protocol implementation in VBScript.dll in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted WMF file, aka "OLE Automation Underflow Vulnerability."
14195| [CVE-2011-0657] DNSAPI.dll in the DNS client in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly process DNS queries, which allows remote attackers to execute arbitrary code via (1) a crafted LLMNR broadcast query or (2) a crafted application, aka "DNS Query Vulnerability."
14196| [CVE-2011-0656] Microsoft PowerPoint 2002 SP3, 2003 SP3, 2007 SP2, and 2010
14197| [CVE-2011-0655] Microsoft PowerPoint 2007 SP2 and 2010
14198| [CVE-2011-0654] Integer underflow in the BowserWriteErrorLogEntry function in the Common Internet File System (CIFS) browser service in Mrxsmb.sys or bowser.sys in Active Directory in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code or cause a denial of service (system crash) via a malformed BROWSER ELECTION message, leading to a heap-based buffer overflow, aka "Browser Pool Corruption Vulnerability." NOTE: some of these details are obtained from third party information.
14199| [CVE-2011-0107] Untrusted search path vulnerability in Microsoft Office XP SP3, Office 2003 SP3, and Office 2007 SP2 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .docx file, aka "Office Component Insecure Library Loading Vulnerability."
14200| [CVE-2011-0105] Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac obtain a certain length value from an uninitialized memory location, which allows remote attackers to trigger a buffer overflow and execute arbitrary code via a crafted Excel file, aka "Excel Data Initialization Vulnerability."
14201| [CVE-2011-0104] Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted HLink record in an Excel file, aka "Excel Buffer Overwrite Vulnerability."
14202| [CVE-2011-0103] Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted record information in an Excel file, aka "Excel Memory Corruption Vulnerability."
14203| [CVE-2011-0101] Microsoft Excel 2002 SP3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted RealTimeData record, related to a stTopic field, doubly-byte characters, and an incorrect pointer calculation, aka "Excel Record Parsing WriteAV Vulnerability."
14204| [CVE-2011-0098] Integer signedness error in Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP2, and 2010
14205| [CVE-2011-0097] Integer underflow in Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP2, and 2010
14206| [CVE-2011-0096] The MHTML protocol handler in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle a MIME format in a request for content blocks in a document, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted web site that is visited in Internet Explorer, aka "MHTML Mime-Formatted Request Vulnerability."
14207| [CVE-2011-0093] ELEMENTS.DLL in Microsoft Visio 2002 SP2, 2003 SP3, and 2007 SP2 does not properly parse structures during the opening of a Visio file, which allows remote attackers to execute arbitrary code via a file containing a malformed structure, aka "Visio Data Type Memory Corruption Vulnerability."
14208| [CVE-2011-0092] The LZW stream decompression functionality in ORMELEMS.DLL in Microsoft Visio 2002 SP2, 2003 SP3, and 2007 SP2 allows remote attackers to execute arbitrary code via a Visio file with a malformed VisioDocument stream that triggers an exception handler that accesses an object that has not been fully initialized, which triggers memory corruption, aka "Visio Object Memory Corruption Vulnerability."
14209| [CVE-2011-0091] Kerberos in Microsoft Windows Server 2008 R2 and Windows 7 does not prevent a session from changing from strong encryption to DES encryption, which allows man-in-the-middle attackers to spoof network traffic and obtain sensitive information via a DES downgrade, aka "Kerberos Spoofing Vulnerability."
14210| [CVE-2011-0090] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Win32k Memory Corruption Vulnerability."
14211| [CVE-2011-0089] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Win32k Window Class Improper Pointer Validation Vulnerability."
14212| [CVE-2011-0088] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Win32k Window Class Pointer Confusion Vulnerability."
14213| [CVE-2011-0087] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Win32k Insufficient User Input Validation Vulnerability."
14214| [CVE-2011-0086] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Win32k Improper User Input Validation Vulnerability."
14215| [CVE-2011-0043] Kerberos in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 supports weak hashing algorithms, which allows local users to gain privileges by operating a service that sends crafted service tickets, as demonstrated by the CRC32 algorithm, aka "Kerberos Unkeyed Checksum Vulnerability."
14216| [CVE-2011-0042] SBE.dll in the Stream Buffer Engine in Windows Media Player and Windows Media Center in Microsoft Windows XP SP2 and SP3, Windows XP Media Center Edition 2005 SP3, Windows Vista SP1 and SP2, Windows 7 Gold and SP1, and Windows Media Center TV Pack for Windows Vista does not properly parse Digital Video Recording (.dvr-ms) files, which allows remote attackers to execute arbitrary code via a crafted file, aka "DVR-MS Vulnerability."
14217| [CVE-2011-0041] Integer overflow in gdiplus.dll in GDI+ in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold and SP2, and Office XP SP3 allows remote attackers to execute arbitrary code via a crafted EMF image, aka "GDI+ Integer Overflow Vulnerability."
14218| [CVE-2011-0040] The server in Microsoft Active Directory on Windows Server 2003 SP2 does not properly handle an update request for a service principal name (SPN), which allows remote attackers to cause a denial of service (authentication downgrade or outage) via a crafted request that triggers name collisions, aka "Active Directory SPN Validation Vulnerability."
14219| [CVE-2011-0039] The Local Security Authority Subsystem Service (LSASS) in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly process authentication requests, which allows local users to gain privileges via a request with a crafted length, aka "LSASS Length Validation Vulnerability."
14220| [CVE-2011-0034] Stack-based buffer overflow in the OpenType Compact Font Format (aka OTF or CFF) driver in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via crafted parameter values in an OpenType font, aka "OpenType Font Stack Overflow Vulnerability."
14221| [CVE-2011-0033] The OpenType Compact Font Format (CFF) driver in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate parameter values in OpenType fonts, which allows remote attackers to execute arbitrary code via a crafted font, aka "OpenType Font Encoded Character Vulnerability."
14222| [CVE-2011-0032] Untrusted search path vulnerability in DirectShow in Microsoft Windows Vista SP1 and SP2, Windows 7 Gold and SP1, Windows Server 2008 R2 and R2 SP1, and Windows Media Center TV Pack for Windows Vista allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a Digital Video Recording (.dvr-ms), Windows Recorded TV Show (.wtv), or .mpg file, aka "DirectShow Insecure Library Loading Vulnerability."
14223| [CVE-2011-0031] The (1) JScript 5.8 and (2) VBScript 5.8 scripting engines in Microsoft Windows Server 2008 R2 and Windows 7 do not properly load decoded scripts obtained from web pages, which allows remote attackers to trigger memory corruption and consequently obtain sensitive information via a crafted web site, aka "Scripting Engines Information Disclosure Vulnerability."
14224| [CVE-2011-0030] The Client/Server Run-time Subsystem (CSRSS) in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly kill processes after a logout, which allows local users to obtain sensitive information or gain privileges via a crafted application that continues to execute throughout the logout of one user and the login session of the next user, aka "CSRSS Elevation of Privilege Vulnerability," a different vulnerability than CVE-2010-0023.
14225| [CVE-2011-0028] WordPad in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly parse fields in Word documents, which allows remote attackers to execute arbitrary code via a crafted .doc file, aka "WordPad Converter Parsing Vulnerability."
14226| [CVE-2010-5082] Untrusted search path vulnerability in colorcpl.exe 6.0.6000.16386 in the Color Control Panel in Microsoft Windows Server 2008 SP2, R2, and R2 SP1 allows local users to gain privileges via a Trojan horse sti.dll file in the current working directory, as demonstrated by a directory that contains a .camp, .cdmp, .gmmp, .icc, or .icm file, aka "Color Control Panel Insecure Library Loading Vulnerability."
14227| [CVE-2010-4701] Heap-based buffer overflow in the CDrawPoly::Serialize function in fxscover.exe in Microsoft Windows Fax Services Cover Page Editor 5.2 r2 in Windows XP Professional SP3, Server 2003 R2 Enterprise Edition SP2, and Windows 7 Professional allows remote attackers to execute arbitrary code via a long record in a Fax Cover Page (.cov) file. NOTE: some of these details are obtained from third party information.
14228| [CVE-2010-4669] The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Microsoft Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, and Windows 7 allows remote attackers to cause a denial of service (CPU consumption and system hang) by sending many Router Advertisement (RA) messages with different source addresses, as demonstrated by the flood_router6 program in the thc-ipv6 package.
14229| [CVE-2010-4562] Microsoft Windows 2008, 7, Vista, 2003, 2000, and XP, when using IPv6, allows remote attackers to determine whether a host is sniffing the network by sending an ICMPv6 Echo Request to a multicast address and determining whether an Echo Reply is sent, as demonstrated by thcping. NOTE: due to a typo, some sources map CVE-2010-4562 to a ProFTPd mod_sql vulnerability, but that issue is covered by CVE-2010-4652.
14230| [CVE-2010-4398] Stack-based buffer overflow in the RtlQueryRegistryValues function in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges, and bypass the User Account Control (UAC) feature, via a crafted REG_BINARY value for a SystemDefaultEUDCFont registry key, aka "Driver Improper Interaction with Windows Kernel Vulnerability."
14231| [CVE-2010-4182] Untrusted search path vulnerability in the Data Access Objects (DAO) library (dao360.dll) in Microsoft Windows XP Professional SP3, Windows Server 2003 R2 Enterprise Edition SP3, Windows Vista Business SP1, and Windows 7 Professional allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse msjet49.dll that is located in the same folder as a file that is processed by dao360.dll. NOTE: the provenance of this information is unknown
14232| [CVE-2010-3974] fxscover.exe in the Fax Cover Page Editor in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly parse FAX cover pages, which allows remote attackers to execute arbitrary code via a crafted .cov file, aka "Fax Cover Page Editor Memory Corruption Vulnerability."
14233| [CVE-2010-3970] Stack-based buffer overflow in the CreateSizedDIBSECTION function in shimgvw.dll in the Windows Shell graphics processor (aka graphics rendering engine) in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a crafted .MIC or unspecified Office document containing a thumbnail bitmap with a negative biClrUsed value, as reported by Moti and Xu Hao, aka "Windows Shell Graphics Processing Overrun Vulnerability."
14234| [CVE-2010-3966] Untrusted search path vulnerability in Microsoft Windows Server 2008 R2 and Windows 7, when BranchCache is supported, allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains an EML file, an RSS file, or a WPOST file, aka "BranchCache Insecure Library Loading Vulnerability."
14235| [CVE-2010-3965] Untrusted search path vulnerability in Windows Media Encoder 9 on Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, and Windows Server 2008 Gold and SP2 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a Windows Media Profile (PRX) file, aka "Insecure Library Loading Vulnerability."
14236| [CVE-2010-3964] Unrestricted file upload vulnerability in the Document Conversions Launcher Service in Microsoft Office SharePoint Server 2007 SP2, when the Document Conversions Load Balancer Service is enabled, allows remote attackers to execute arbitrary code via a crafted SOAP request to TCP port 8082, aka "Malformed Request Code Execution Vulnerability."
14237| [CVE-2010-3963] Buffer overflow in the Routing and Remote Access NDProxy component in the kernel in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a crafted application, related to the Routing and Remote Access service (RRAS) and improper copying from user mode to the kernel, aka "Kernel NDProxy Buffer Overflow Vulnerability."
14238| [CVE-2010-3961] The Consent User Interface (UI) in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly handle an unspecified registry-key value, which allows local users with SeImpersonatePrivilege rights to gain privileges via a crafted application, aka "Consent UI Impersonation Vulnerability."
14239| [CVE-2010-3960] Hyper-V in Microsoft Windows Server 2008 Gold, SP2, and R2 allows guest OS users to cause a denial of service (host OS hang) by sending a crafted encapsulated packet over the VMBus, aka "Hyper-V VMBus Vulnerability."
14240| [CVE-2010-3959] The OpenType Font (OTF) driver in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges via a crafted CMAP table in an OpenType font, aka "OpenType CMAP Table Vulnerability."
14241| [CVE-2010-3958] The x86 JIT compiler in Microsoft .NET Framework 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0 does not properly compile function calls, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka ".NET Framework Stack Corruption Vulnerability."
14242| [CVE-2010-3957] Double free vulnerability in the OpenType Font (OTF) driver in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges via a crafted OpenType font, aka "OpenType Font Double Free Vulnerability."
14243| [CVE-2010-3956] The OpenType Font (OTF) driver in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly perform array indexing, which allows local users to gain privileges via a crafted OpenType font, aka "OpenType Font Index Vulnerability."
14244| [CVE-2010-3955] pubconv.dll (aka the Publisher Converter DLL) in Microsoft Publisher 2002 SP3 does not properly perform array indexing, which allows remote attackers to execute arbitrary code via a crafted Publisher file that uses an old file format, aka "Array Indexing Memory Corruption Vulnerability."
14245| [CVE-2010-3954] Microsoft Publisher 2002 SP3, 2003 SP3, and 2010 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Publisher file, aka "Microsoft Publisher Memory Corruption Vulnerability."
14246| [CVE-2010-3946] Integer overflow in the PICT image converter in the graphics filters in Microsoft Office XP SP3, Office 2003 SP3, and Office Converter Pack allows remote attackers to execute arbitrary code via a crafted PICT image in an Office document, aka "PICT Image Converter Integer Overflow Vulnerability."
14247| [CVE-2010-3945] Buffer overflow in the CGM image converter in the graphics filters in Microsoft Office XP SP3, Office 2003 SP3, and Office Converter Pack allows remote attackers to execute arbitrary code via a crafted CGM image in an Office document, aka "CGM Image Converter Buffer Overrun Vulnerability."
14248| [CVE-2010-3944] win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2008 R2 and Windows 7 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Win32k Memory Corruption Vulnerability."
14249| [CVE-2010-3943] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly link driver objects, which allows local users to gain privileges via a crafted application that triggers linked-list corruption, aka "Win32k Cursor Linking Vulnerability."
14250| [CVE-2010-3942] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly allocate memory for copies from user mode, which allows local users to gain privileges via a crafted application, aka "Win32k WriteAV Vulnerability."
14251| [CVE-2010-3941] Double free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold and SP2, and Windows 7 allows local users to gain privileges via a crafted application, aka "Win32k Double Free Vulnerability."
14252| [CVE-2010-3940] Double free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges via a crafted application, aka "Win32k PFE Pointer Double Free Vulnerability."
14253| [CVE-2010-3939] Buffer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges via vectors related to improper memory allocation for copies from user mode, aka "Win32k Buffer Overflow Vulnerability."
14254| [CVE-2010-3937] Microsoft Exchange Server 2007 SP2 on the x64 platform allows remote authenticated users to cause a denial of service (infinite loop and MSExchangeIS outage) via a crafted RPC request, aka "Exchange Server Infinite Loop Vulnerability."
14255| [CVE-2010-3338] The Windows Task Scheduler in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly determine the security context of scheduled tasks, which allows local users to gain privileges via a crafted application, aka "Task Scheduler Vulnerability." NOTE: this might overlap CVE-2010-3888.
14256| [CVE-2010-3337] Untrusted search path vulnerability in Microsoft Office 2007 SP2 and 2010 allows local users to gain privileges via a Trojan horse DLL in the current working directory, aka "Insecure Library Loading Vulnerability." NOTE: this might overlap CVE-2010-3141 and CVE-2010-3142.
14257| [CVE-2010-3336] Microsoft Office XP SP3, Office 2004 and 2008 for Mac, Office for Mac 2011, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code via a crafted Office document that triggers memory corruption, aka "MSO Large SPID Read AV Vulnerability."
14258| [CVE-2010-3335] Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2008 for Mac, Office for Mac 2011, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code via a crafted Office document that triggers memory corruption, aka "Drawing Exception Handling Vulnerability."
14259| [CVE-2010-3334] Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2008 for Mac, Office for Mac 2011, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code via an Office document containing an Office Art Drawing record with crafted msofbtSp records and unspecified flags, which triggers memory corruption, aka "Office Art Drawing Records Vulnerability."
14260| [CVE-2010-3333] Stack-based buffer overflow in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2008 for Mac, Office for Mac 2011, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via crafted RTF data, aka "RTF Stack Buffer Overflow Vulnerability."
14261| [CVE-2010-3332] Microsoft .NET Framework 1.1 SP1, 2.0 SP1 and SP2, 3.5, 3.5 SP1, 3.5.1, and 4.0, as used for ASP.NET in Microsoft Internet Information Services (IIS), provides detailed error codes during decryption attempts, which allows remote attackers to decrypt and modify encrypted View State (aka __VIEWSTATE) form data, and possibly forge cookies or read application files, via a padding oracle attack, aka "ASP.NET Padding Oracle Vulnerability."
14262| [CVE-2010-3324] The toStaticHTML function in Microsoft Internet Explorer 8, and the SafeHTML function in Microsoft Windows SharePoint Services 3.0 SP2, SharePoint Foundation 2010, Office SharePoint Server 2007 SP2, Groove Server 2010, and Office Web Apps, allows remote attackers to bypass the cross-site scripting (XSS) protection mechanism and conduct XSS attacks via a crafted use of the Cascading Style Sheets (CSS) @import rule, aka "HTML Sanitization Vulnerability," a different vulnerability than CVE-2010-1257.
14263| [CVE-2010-3243] Cross-site scripting (XSS) vulnerability in the toStaticHTML function in Microsoft Internet Explorer 8, and the SafeHTML function in Microsoft Windows SharePoint Services 3.0 SP2 and Office SharePoint Server 2007 SP2, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "HTML Sanitization Vulnerability."
14264| [CVE-2010-3242] Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Ghost Record Type Parsing Vulnerability."
14265| [CVE-2010-3241] Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate binary file-format information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Out-of-Bounds Memory Write in Parsing Vulnerability."
14266| [CVE-2010-3240] Microsoft Excel 2002 SP3 and 2007 SP2
14267| [CVE-2010-3239] Microsoft Excel 2002 SP3 does not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Extra Out of Boundary Record Parsing Vulnerability."
14268| [CVE-2010-3238] Microsoft Excel 2002 SP3 and 2003 SP3, and Office 2004 for Mac, does not properly validate binary file-format information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Negative Future Function Vulnerability."
14269| [CVE-2010-3237] Microsoft Excel 2002 SP3 and Office 2004 for Mac do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Merge Cell Record Pointer Vulnerability."
14270| [CVE-2010-3236] Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Out Of Bounds Array Vulnerability."
14271| [CVE-2010-3235] Microsoft Excel 2002 SP3 does not properly validate formula information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Formula Biff Record Vulnerability."
14272| [CVE-2010-3234] Microsoft Excel 2002 SP3 does not properly validate formula information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Formula Substream Memory Corruption Vulnerability."
14273| [CVE-2010-3233] Microsoft Excel 2002 SP3 and 2003 SP3 does not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted .wk3 (aka Lotus 1-2-3 workbook) file, aka "Lotus 1-2-3 Workbook Parsing Vulnerability."
14274| [CVE-2010-3232] Microsoft Excel 2003 SP3 and 2007 SP2
14275| [CVE-2010-3231] Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Excel Record Parsing Memory Corruption Vulnerability."
14276| [CVE-2010-3230] Integer overflow in Microsoft Excel 2002 SP3 allows remote attackers to execute arbitrary code via an Excel document with crafted record information, aka "Excel Record Parsing Integer Overflow Vulnerability."
14277| [CVE-2010-3229] The Secure Channel (aka SChannel) security package in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, when IIS 7.x is used, does not properly process client certificates during SSL and TLS handshakes, which allows remote attackers to cause a denial of service (LSASS outage and reboot) via a crafted packet, aka "TLSv1 Denial of Service Vulnerability."
14278| [CVE-2010-3227] Stack-based buffer overflow in the UpdateFrameTitleForDocument method in the CFrameWnd class in mfc42.dll in the Microsoft Foundation Class (MFC) Library in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows context-dependent attackers to execute arbitrary code via a long window title that this library attempts to create at the request of an application, as demonstrated by the Trident PowerZip 7.2 Build 4010 application, aka "Windows MFC Document Title Updating Buffer Overflow Vulnerability."
14279| [CVE-2010-3223] The user interface in Microsoft Cluster Service (MSCS) in Microsoft Windows Server 2008 R2 does not properly set administrative-share permissions for new cluster disks that are shared as part of a failover cluster, which allows remote attackers to read or modify data on these disks via requests to the associated share, aka "Permissions on New Cluster Disks Vulnerability."
14280| [CVE-2010-3222] Stack-based buffer overflow in the Remote Procedure Call Subsystem (RPCSS) in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a crafted LPC message that requests an LRPC connection from an LPC server to a client, aka "LPC Message Buffer Overrun Vulnerability."
14281| [CVE-2010-3221] Microsoft Word 2002 SP3 and 2003 SP3, Office 2004 for Mac, and Word Viewer do not properly handle a malformed record during parsing of a Word document, which allows remote attackers to execute arbitrary code via a crafted document that triggers memory corruption, aka "Word Parsing Vulnerability."
14282| [CVE-2010-3220] Unspecified vulnerability in Microsoft Word 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Word document that triggers memory corruption, aka "Word Parsing Vulnerability."
14283| [CVE-2010-3219] Array index vulnerability in Microsoft Word 2002 SP3 allows remote attackers to execute arbitrary code via a crafted Word document that triggers memory corruption, aka "Word Index Parsing Vulnerability."
14284| [CVE-2010-3218] Heap-based buffer overflow in Microsoft Word 2002 SP3 allows remote attackers to execute arbitrary code via malformed records in a Word document, aka "Word Heap Overflow Vulnerability."
14285| [CVE-2010-3217] Double free vulnerability in Microsoft Word 2002 SP3 allows remote attackers to execute arbitrary code via a Word document with crafted List Format Override (LFO) records, aka "Word Pointer Vulnerability."
14286| [CVE-2010-3216] Microsoft Word 2002 SP3 and Office 2004 for Mac allow remote attackers to execute arbitrary code via a crafted Word document containing bookmarks that trigger use of an invalid pointer and memory corruption, aka "Word Bookmarks Vulnerability."
14287| [CVE-2010-3215] Microsoft Word 2002 SP3 and Office 2004 for Mac do not properly handle unspecified return values during parsing of a Word document, which allows remote attackers to execute arbitrary code via a crafted document that triggers memory corruption, aka "Word Return Value Vulnerability."
14288| [CVE-2010-3214] Stack-based buffer overflow in Microsoft Word 2002 SP3, 2003 SP3, 2007 SP2, and 2010
14289| [CVE-2010-3213] Cross-site request forgery (CSRF) vulnerability in Microsoft Outlook Web Access (owa/ev.owa) 2007 through SP2 allows remote attackers to hijack the authentication of e-mail users for requests that perform Outlook requests, as demonstrated by setting the auto-forward rule.
14290| [CVE-2010-3200] MSO.dll in Microsoft Word 2003 SP3 11.8326.11.8324 allows remote attackers to cause a denial of service (NULL pointer dereference and multiple-instance application crash) via a crafted buffer in a Word document, as demonstrated by word_crash_11.8326.8324_poc.doc.
14291| [CVE-2010-3190] Untrusted search path vulnerability in the Microsoft Foundation Class (MFC) Library in Microsoft Visual Studio .NET 2003 SP1
14292| [CVE-2010-3148] Untrusted search path vulnerability in Microsoft Visio 2003 SP3 allows local users to gain privileges via a Trojan horse mfc71enu.dll file in the current working directory, as demonstrated by a directory that contains a .vsd, .vdx, .vst, or .vtx file, aka "Microsoft Visio Insecure Library Loading Vulnerability."
14293| [CVE-2010-3147] Untrusted search path vulnerability in wab.exe 6.00.2900.5512 in Windows Address Book in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges via a Trojan horse wab32res.dll file in the current working directory, as demonstrated by a directory that contains a Windows Address Book (WAB), VCF (aka vCard), or P7C file, aka "Insecure Library Loading Vulnerability." NOTE: the codebase for this product may overlap the codebase for the product referenced in CVE-2010-3143.
14294| [CVE-2010-3146] Multiple untrusted search path vulnerabilities in Microsoft Groove 2007 SP2 allow local users to gain privileges via a Trojan horse (1) mso.dll or (2) GroovePerfmon.dll file in the current working directory, as demonstrated by a directory that contains a Groove vCard (.vcg) or Groove Tool Archive (.gta) file, aka "Microsoft Groove Insecure Library Loading Vulnerability."
14295| [CVE-2010-3144] Untrusted search path vulnerability in the Internet Connection Signup Wizard in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a Trojan horse smmscrpt.dll file in the current working directory, as demonstrated by a directory that contains an ISP or INS file, aka "Internet Connection Signup Wizard Insecure Library Loading Vulnerability."
14296| [CVE-2010-3142] Untrusted search path vulnerability in Microsoft Office PowerPoint 2007 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse rpawinet.dll that is located in the same folder as a .odp, .pothtml, .potm, .potx, .ppa, .ppam, .pps, .ppt, .ppthtml, .pptm, .pptxml, .pwz, .sldm, .sldx, and .thmx file.
14297| [CVE-2010-2750] Array index error in Microsoft Word 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Word document that triggers memory corruption, aka "Word Index Vulnerability."
14298| [CVE-2010-2748] Microsoft Word 2002 SP3 and Office 2004 for Mac do not properly check an unspecified boundary during parsing of a Word document, which allows remote attackers to execute arbitrary code via a crafted document that triggers memory corruption, aka "Word Boundary Check Vulnerability."
14299| [CVE-2010-2747] Microsoft Word 2002 SP3 and Office 2004 for Mac do not properly handle an uninitialized pointer during parsing of a Word document, which allows remote attackers to execute arbitrary code via a crafted document that triggers memory corruption, aka "Word Uninitialized Pointer Vulnerability."
14300| [CVE-2010-2746] Heap-based buffer overflow in Comctl32.dll (aka the common control library) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, when a third-party SVG viewer is used, allows remote attackers to execute arbitrary code via a crafted HTML document that triggers unspecified messages from this viewer, aka "Comctl32 Heap Overflow Vulnerability."
14301| [CVE-2010-2744] The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 do not properly manage a window class, which allows local users to gain privileges by creating a window, then using (1) the SetWindowLongPtr function to modify the popup menu structure, or (2) the SwitchWndProc function with a switch window information pointer, which is not re-initialized when a WM_NCCREATE message is processed, aka "Win32k Window Class Vulnerability."
14302| [CVE-2010-2742] The Netlogon RPC Service in Microsoft Windows Server 2003 SP2 and Server 2008 Gold, SP2, and R2, when the domain controller role is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and reboot) via a crafted RPC packet, aka "Netlogon RPC Null dereference DOS Vulnerability."
14303| [CVE-2010-2741] The OpenType Font (OTF) format driver in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 performs an incorrect integer calculation during font processing, which allows local users to gain privileges via a crafted application, aka "OpenType Font Validation Vulnerability."
14304| [CVE-2010-2740] The OpenType Font (OTF) format driver in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly perform memory allocation during font parsing, which allows local users to gain privileges via a crafted application, aka "OpenType Font Parsing Vulnerability."
14305| [CVE-2010-2739] Buffer overflow in the CreateDIBPalette function in win32k.sys in Microsoft Windows XP SP3, Server 2003 R2 Enterprise SP2, Vista Business SP1, Windows 7, and Server 2008 SP2 allows local users to cause a denial of service (crash) and possibly execute arbitrary code by performing a clipboard operation (GetClipboardData API function) with a crafted bitmap with a palette that contains a large number of colors.
14306| [CVE-2010-2738] The Uniscribe (aka new Unicode Script Processor) implementation in USP10.DLL in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2, and Microsoft Office XP SP3, 2003 SP3, and 2007 SP2, does not properly validate tables associated with malformed OpenType fonts, which allows remote attackers to execute arbitrary code via a crafted (1) web site or (2) Office document, aka "Uniscribe Font Parsing Engine Memory Corruption Vulnerability."
14307| [CVE-2010-2729] The Print Spooler service in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, when printer sharing is enabled, does not properly validate spooler access permissions, which allows remote attackers to create files in a system directory, and consequently execute arbitrary code, by sending a crafted print request over RPC, as exploited in the wild in September 2010, aka "Print Spooler Service Impersonation Vulnerability."
14308| [CVE-2010-2728] Heap-based buffer overflow in Microsoft Outlook 2002 SP3, 2003 SP3, and 2007 SP2, when Online Mode for an Exchange Server is enabled, allows remote attackers to execute arbitrary code via a crafted e-mail message, aka "Heap Based Buffer Overflow in Outlook Vulnerability."
14309| [CVE-2010-2573] Integer underflow in Microsoft PowerPoint 2002 SP3 and 2003 SP3, PowerPoint Viewer SP2, and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint Integer Underflow Causes Heap Corruption Vulnerability."
14310| [CVE-2010-2572] Buffer overflow in Microsoft PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint 95 document, aka "PowerPoint Parsing Buffer Overflow Vulnerability."
14311| [CVE-2010-2571] Array index error in pubconv.dll (aka the Publisher Converter DLL) in Microsoft Publisher 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher 97 file, aka "Memory Corruption Due To Invalid Index Into Array in Pubconv.dll Vulnerability."
14312| [CVE-2010-2570] Heap-based buffer overflow in pubconv.dll (aka the Publisher Converter DLL) in Microsoft Publisher 2002 SP3, 2003 SP3, 2007 SP2, and 2010 allows remote attackers to execute arbitrary code via a crafted Publisher file that uses an old file format, aka "Heap Overrun in pubconv.dll Vulnerability."
14313| [CVE-2010-2569] pubconv.dll (aka the Publisher Converter DLL) in Microsoft Publisher 2002 SP3, 2003 SP3, and 2007 SP2 does not properly handle an unspecified size field in certain older file formats, which allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted Publisher file, aka "Size Value Heap Corruption in pubconv.dll Vulnerability."
14314| [CVE-2010-2568] Windows Shell in Microsoft Windows XP SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 allows local users or remote attackers to execute arbitrary code via a crafted (1) .LNK or (2) .PIF shortcut file, which is not properly handled during icon display in Windows Explorer, as demonstrated in the wild in July 2010, and originally reported for malware that leverages CVE-2010-2772 in Siemens WinCC SCADA systems.
14315| [CVE-2010-2567] The RPC client implementation in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly allocate memory during the parsing of responses, which allows remote RPC servers and man-in-the-middle attackers to execute arbitrary code via a malformed response, aka "RPC Memory Corruption Vulnerability."
14316| [CVE-2010-2566] The Secure Channel (aka SChannel) security package in Microsoft Windows XP SP2 and SP3, and Windows Server 2003 SP2, does not properly validate certificate request messages from TLS and SSL servers, which allows remote servers to execute arbitrary code via a crafted SSL response, aka "SChannel Malformed Certificate Request Remote Code Execution Vulnerability."
14317| [CVE-2010-2563] The Word 97 text converter in the WordPad Text Converters in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly parse malformed structures in Word 97 documents, which allows remote attackers to execute arbitrary code via a crafted document containing an unspecified value that is used in a loop counter, aka "WordPad Word 97 Text Converter Memory Corruption Vulnerability."
14318| [CVE-2010-2562] Microsoft Office Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Excel file, aka "Excel Memory Corruption Vulnerability."
14319| [CVE-2010-2555] The Tracing Feature for Services in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly determine the length of strings in the registry, which allows local users to gain privileges or cause a denial of service (memory corruption) via vectors involving a long string, aka "Tracing Memory Corruption Vulnerability."
14320| [CVE-2010-2554] The Tracing Feature for Services in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 has incorrect ACLs on its registry keys, which allows local users to gain privileges via vectors involving a named pipe and impersonation, aka "Tracing Registry Key ACL Vulnerability."
14321| [CVE-2010-2552] Stack consumption vulnerability in the SMB Server in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows remote attackers to cause a denial of service (system hang) via a malformed SMBv2 compounded request, aka "SMB Stack Exhaustion Vulnerability."
14322| [CVE-2010-2551] The SMB Server in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate an internal variable in an SMB packet, which allows remote attackers to cause a denial of service (system hang) via a crafted (1) SMBv1 or (2) SMBv2 packet, aka "SMB Variable Validation Vulnerability."
14323| [CVE-2010-2550] The SMB Server in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate fields in an SMB request, which allows remote attackers to execute arbitrary code via a crafted SMB packet, aka "SMB Pool Overflow Vulnerability."
14324| [CVE-2010-2549] Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Vista SP1 and SP2 and Server 2008 Gold and SP2 allows local users to gain privileges or cause a denial of service (system crash) by using a large number of calls to the NtUserCheckAccessForIntegrityLevel function to trigger a failure in the LockProcessByClientId function, leading to deletion of an in-use process object, aka "Win32k Reference Count Vulnerability."
14325| [CVE-2010-2265] Cross-site scripting (XSS) vulnerability in the GetServerName function in sysinfo/commonFunc.js in Microsoft Windows Help and Support Center for Windows XP and Windows Server 2003 allows remote attackers to inject arbitrary web script or HTML via the svr parameter to sysinfo/sysinfomain.htm. NOTE: this can be leveraged with CVE-2010-1885 to execute arbitrary commands without user interaction.
14326| [CVE-2010-2091] Microsoft Outlook Web Access (OWA) 8.2.254.0, when Internet Explorer 7 on Windows Server 2003 is used, does not properly handle the id parameter in a Folder IPF.Note action to the default URI, which might allow remote attackers to obtain sensitive information or conduct cross-site scripting (XSS) attacks via an invalid value.
14327| [CVE-2010-2084] Microsoft ASP.NET 2.0 does not prevent setting the InnerHtml property on a control that inherits from HtmlContainerControl, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to an attribute.
14328| [CVE-2010-1903] Microsoft Office Word 2002 SP3 and 2003 SP3, and Office Word Viewer, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a malformed record in a Word file, aka "Word HTML Linked Objects Memory Corruption Vulnerability."
14329| [CVE-2010-1902] Buffer overflow in Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP2
14330| [CVE-2010-1901] Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP2
14331| [CVE-2010-1900] Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP2
14332| [CVE-2010-1898] The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP1, 2.0 SP2, 3.5, 3.5 SP1, and 3.5.1, and Microsoft Silverlight 2 and 3 before 3.0.50611.0 on Windows and before 3.0.41130.0 on Mac OS X, does not properly handle interfaces and delegations to virtual methods, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "Microsoft Silverlight and Microsoft .NET Framework CLR Virtual Method Delegate Vulnerability."
14333| [CVE-2010-1897] The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 do not properly validate pseudo-handle values in callback parameters during window creation, which allows local users to gain privileges via a crafted application, aka "Win32k Window Creation Vulnerability."
14334| [CVE-2010-1896] The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, and Windows Server 2008 Gold and SP2 do not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application, aka "Win32k User Input Validation Vulnerability."
14335| [CVE-2010-1895] The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, and Windows Server 2003 SP2, do not properly perform memory allocation before copying user-mode data to kernel mode, which allows local users to gain privileges via a crafted application, aka "Win32k Pool Overflow Vulnerability."
14336| [CVE-2010-1894] The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, and Windows Server 2003 SP2, do not properly handle unspecified exceptions, which allows local users to gain privileges via a crafted application, aka "Win32k Exception Handling Vulnerability."
14337| [CVE-2010-1893] Integer overflow in the TCP/IP stack in Microsoft Windows Vista SP1, Windows Server 2008 Gold and R2, and Windows 7 allows local users to gain privileges via a buffer of user-mode data that is copied to kernel mode, aka "Integer Overflow in Windows Networking Vulnerability."
14338| [CVE-2010-1892] The TCP/IP stack in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly handle malformed IPv6 packets, which allows remote attackers to cause a denial of service (system hang) via multiple crafted packets, aka "IPv6 Memory Corruption Vulnerability."
14339| [CVE-2010-1891] The Client/Server Runtime Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2, when a Chinese, Japanese, or Korean locale is enabled, does not properly allocate memory for transactions, which allows local users to gain privileges via a crafted application, aka "CSRSS Local Elevation of Privilege Vulnerability."
14340| [CVE-2010-1890] The kernel in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate ACLs on kernel objects, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Improper Validation Vulnerability."
14341| [CVE-2010-1889] Double free vulnerability in the kernel in Microsoft Windows Vista SP1 and SP2, and Windows Server 2008 Gold and SP2, allows local users to gain privileges via a crafted application, related to object initialization during error handling, aka "Windows Kernel Double Free Vulnerability."
14342| [CVE-2010-1887] The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 do not properly validate an unspecified system-call argument, which allows local users to cause a denial of service (system hang) via a crafted application, aka "Win32k Bounds Checking Vulnerability."
14343| [CVE-2010-1886] Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 SP2 and R2, and Windows 7 allow local users to gain privileges by leveraging access to a process with NetworkService credentials, as demonstrated by TAPI Server, SQL Server, and IIS processes, and related to the Windows Service Isolation feature. NOTE: the vendor states that privilege escalation from NetworkService to LocalSystem does not cross a "security boundary."
14344| [CVE-2010-1885] The MPC::HexToNum function in helpctr.exe in Microsoft Windows Help and Support Center in Windows XP and Windows Server 2003 does not properly handle malformed escape sequences, which allows remote attackers to bypass the trusted documents whitelist (fromHCP option) and execute arbitrary commands via a crafted hcp:// URL, aka "Help Center URL Validation Vulnerability."
14345| [CVE-2010-1883] Integer overflow in the Embedded OpenType (EOT) Font Engine in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows remote attackers to execute arbitrary code via a crafted table in an embedded font, aka "Embedded OpenType Font Integer Overflow Vulnerability."
14346| [CVE-2010-1882] Multiple buffer overflows in the MPEG Layer-3 Audio Codec for Microsoft DirectShow in l3codecx.ax in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allow remote attackers to execute arbitrary code via an MPEG Layer-3 audio stream in (1) a crafted media file or (2) crafted streaming content, aka "MPEG Layer-3 Audio Decoder Buffer Overflow Vulnerability."
14347| [CVE-2010-1881] The FieldList ActiveX control in the Microsoft Access Wizard Controls in ACCWIZ.dll in Microsoft Office Access 2003 SP3 does not properly interact with the memory-access approach used by Internet Explorer and Office during instantiation, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via an HTML document that references this control along with crafted persistent storage data, aka "ACCWIZ.dll Uninitialized Variable Vulnerability."
14348| [CVE-2010-1880] Unspecified vulnerability in Quartz.dll for DirectShow on Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1, and Server 2008 allows remote attackers to execute arbitrary code via a media file with crafted compression data, aka "MJPEG Media Decompression Vulnerability."
14349| [CVE-2010-1735] The SfnLOGONNOTIFY function in win32k.sys in the kernel in Microsoft Windows 2000, XP, and Server 2003 allows local users to cause a denial of service (system crash) via a 0x4c value in the second argument (aka the Msg argument) of a PostMessage function call for the DDEMLEvent window.
14350| [CVE-2010-1734] The SfnINSTRING function in win32k.sys in the kernel in Microsoft Windows 2000, XP, and Server 2003 allows local users to cause a denial of service (system crash) via a 0x18d value in the second argument (aka the Msg argument) of a PostMessage function call for the DDEMLEvent window.
14351| [CVE-2010-1690] The DNS implementation in smtpsvc.dll before 6.0.2600.5949 in Microsoft Windows 2000 SP4 and earlier, Windows XP SP3 and earlier, Windows Server 2003 SP2 and earlier, Windows Server 2008 SP2 and earlier, Windows Server 2008 R2, Exchange Server 2003 SP3 and earlier, Exchange Server 2007 SP2 and earlier, and Exchange Server 2010 does not verify that transaction IDs of responses match transaction IDs of queries, which makes it easier for man-in-the-middle attackers to spoof DNS responses, a different vulnerability than CVE-2010-0024 and CVE-2010-0025.
14352| [CVE-2010-1689] The DNS implementation in smtpsvc.dll before 6.0.2600.5949 in Microsoft Windows 2000 SP4 and earlier, Windows XP SP3 and earlier, Windows Server 2003 SP2 and earlier, Windows Server 2008 SP2 and earlier, Windows Server 2008 R2, Exchange Server 2003 SP3 and earlier, Exchange Server 2007 SP2 and earlier, and Exchange Server 2010 uses predictable transaction IDs that are formed by incrementing a previous ID by 1, which makes it easier for man-in-the-middle attackers to spoof DNS responses, a different vulnerability than CVE-2010-0024 and CVE-2010-0025.
14353| [CVE-2010-1263] Windows Shell and WordPad in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7
14354| [CVE-2010-1257] Cross-site scripting (XSS) vulnerability in the toStaticHTML API, as used in Microsoft Office InfoPath 2003 SP3, 2007 SP1, and 2007 SP2
14355| [CVE-2010-1255] The Windows kernel-mode drivers in win32k.sys in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 Gold and SP2, Windows 7, and Server 2008 R2 allows local users to execute arbitrary code via vectors related to "glyph outline information" and TrueType fonts, aka "Win32k TrueType Font Parsing Vulnerability."
14356| [CVE-2010-1253] Microsoft Office Excel 2002 SP3, 2007 SP1, and SP2
14357| [CVE-2010-1252] Unspecified vulnerability in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Excel file, aka "Excel String Variable Vulnerability."
14358| [CVE-2010-1251] Unspecified vulnerability in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Excel file, aka "Excel Record Stack Corruption Vulnerability."
14359| [CVE-2010-1250] Heap-based buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via an Excel file with malformed (1) EDG (0x88) and (2) Publisher (0x89) records, aka "Excel EDG Memory Corruption Vulnerability."
14360| [CVE-2010-1249] Buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via an Excel file with a malformed ExternName (0x23) record, aka "Excel Memory Corruption Vulnerability," a different vulnerability than CVE-2010-0823 and CVE-2010-1247.
14361| [CVE-2010-1248] Buffer overflow in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via an Excel file with a malformed HFPicture (0x866) record, aka "Excel HFPicture Memory Corruption Vulnerability."
14362| [CVE-2010-1247] Unspecified vulnerability in Microsoft Office Excel 2002 SP3 allows remote attackers to execute arbitrary code via an Excel file with a malformed RTD (0x813) record that triggers heap corruption, aka "Excel Memory Corruption Vulnerability," a different vulnerability than CVE-2010-0823 and CVE-2010-1249.
14363| [CVE-2010-1246] Stack-based buffer overflow in Microsoft Office Excel 2002 SP3 allows remote attackers to execute arbitrary code via an Excel file with a malformed RTD (0x813) record, aka "Excel RTD Memory Corruption Vulnerability."
14364| [CVE-2010-1245] Unspecified vulnerability in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via an Excel file with a malformed SxView (0xB0) record, aka "Excel Record Memory Corruption Vulnerability," a different vulnerability than CVE-2010-0824 and CVE-2010-0821.
14365| [CVE-2010-1225] The memory-management implementation in the Virtual Machine Monitor (aka VMM or hypervisor) in Microsoft Virtual PC 2007 Gold and SP1, Virtual Server 2005 Gold and R2 SP1, and Windows Virtual PC does not properly restrict access from the guest OS to memory locations in the VMM work area, which allows context-dependent attackers to bypass certain anti-exploitation protection mechanisms on the guest OS via crafted input to a vulnerable application. NOTE: the vendor reportedly found that only systems with an otherwise vulnerable application are affected, because "the memory areas accessible from the guest cannot be leveraged to achieve either remote code execution or elevation of privilege and ... no data from the host is exposed to the guest OS."
14366| [CVE-2010-1175] Microsoft Internet Explorer 7.0 on Windows XP and Windows Server 2003 allows remote attackers to have an unspecified impact via a certain XML document that references a crafted web site in the SRC attribute of an image element, related to a "0day Vulnerability."
14367| [CVE-2010-0917] Stack-based buffer overflow in VBScript in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, when Internet Explorer is used, might allow user-assisted remote attackers to execute arbitrary code via a long string in the fourth argument (aka helpfile argument) to the MsgBox function, leading to code execution when the F1 key is pressed, a different vulnerability than CVE-2010-0483.
14368| [CVE-2010-0824] Unspecified vulnerability in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via an Excel file with a malformed WOPT (0x80B) record, aka "Excel Record Memory Corruption Vulnerability," a different vulnerability than CVE-2010-0821 and CVE-2010-1245.
14369| [CVE-2010-0823] Unspecified vulnerability in Microsoft Office Excel 2002 SP3, 2003 SP3, 2007 SP1 and SP2
14370| [CVE-2010-0822] Stack-based buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via an Excel file with a crafted OBJ (0x5D) record, aka "Excel Object Stack Overflow Vulnerability."
14371| [CVE-2010-0821] Unspecified vulnerability in Microsoft Office Excel 2002 SP3, 2003 SP3, 2007 SP1 and SP2
14372| [CVE-2010-0820] Heap-based buffer overflow in the Local Security Authority Subsystem Service (LSASS), as used in Active Directory in Microsoft Windows Server 2003 SP2 and Windows Server 2008 Gold, SP2, and R2
14373| [CVE-2010-0819] Unspecified vulnerability in the Windows OpenType Compact Font Format (CFF) driver in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 allows local users to execute arbitrary code via unknown vectors related to improper validation when copying data from user mode to kernel mode, aka "OpenType CFF Font Driver Memory Corruption Vulnerability."
14374| [CVE-2010-0818] The MPEG-4 codec in the Windows Media codecs in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2 does not properly handle crafted media content with MPEG-4 video encoding, which allows remote attackers to execute arbitrary code via a file in an unspecified "supported format," aka "MPEG-4 Codec Vulnerability."
14375| [CVE-2010-0817] Cross-site scripting (XSS) vulnerability in _layouts/help.aspx in Microsoft SharePoint Server 2007 12.0.0.6421 and possibly earlier, and SharePoint Services 3.0 SP1 and SP2, versions, allows remote attackers to inject arbitrary web script or HTML via the cid0 parameter.
14376| [CVE-2010-0815] VBE6.DLL in Microsoft Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Visual Basic for Applications (VBA), and VBA SDK 6.3 through 6.5 does not properly search for ActiveX controls that are embedded in documents, which allows remote attackers to execute arbitrary code via a crafted document, aka "VBE6.DLL Stack Memory Corruption Vulnerability."
14377| [CVE-2010-0814] The Microsoft Access Wizard Controls in ACCWIZ.dll in Microsoft Office Access 2003 SP3 and 2007 SP1 and SP2 do not properly interact with the memory-allocation approach used by Internet Explorer during instantiation, which allows remote attackers to execute arbitrary code via a web site that references multiple ActiveX controls, as demonstrated by the ImexGrid and FieldList controls, aka "Access ActiveX Control Vulnerability."
14378| [CVE-2010-0812] Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allow remote attackers to bypass intended IPv4 source-address restrictions via a mismatched IPv6 source address in a tunneled ISATAP packet, aka "ISATAP IPv6 Source Address Spoofing Vulnerability."
14379| [CVE-2010-0811] Multiple unspecified vulnerabilities in the Microsoft Internet Explorer 8 Developer Tools ActiveX control in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allow remote attackers to execute arbitrary code via unknown vectors that "corrupt the system state," aka "Microsoft Internet Explorer 8 Developer Tools Vulnerability."
14380| [CVE-2010-0810] The kernel in Microsoft Windows Vista Gold, SP1, and SP2, and Windows Server 2008 Gold and SP2, does not properly handle unspecified exceptions, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Exception Handler Vulnerability."
14381| [CVE-2010-0719] An unspecified API in Microsoft Windows 2000, Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, and Windows 7 does not validate arguments, which allows local users to cause a denial of service (system crash) via a crafted application.
14382| [CVE-2010-0487] The Authenticode Signature verification functionality in cabview.dll in Cabinet File Viewer Shell Extension 5.1, 6.0, and 6.1 in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly use unspecified fields in a file digest, which allows remote attackers to execute arbitrary code via a modified cabinet (aka .CAB) file that incorrectly appears to have a valid signature, aka "Cabview Corruption Validation Vulnerability."
14383| [CVE-2010-0486] The WinVerifyTrust function in Authenticode Signature Verification 5.1, 6.0, and 6.1 in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly use unspecified fields in a file digest, which allows user-assisted remote attackers to execute arbitrary code via a modified (1) Portable Executable (PE) or (2) cabinet (aka .CAB) file that incorrectly appears to have a valid signature, aka "WinVerifyTrust Signature Validation Vulnerability."
14384| [CVE-2010-0485] The Windows kernel-mode drivers in win32k.sys in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 Gold and SP2, Windows 7, and Server 2008 R2 "do not properly validate all callback parameters when creating a new window," which allows local users to execute arbitrary code, aka "Win32k Window Creation Vulnerability."
14385| [CVE-2010-0484] The Windows kernel-mode drivers in win32k.sys in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2 "do not properly validate changes in certain kernel objects," which allows local users to execute arbitrary code via vectors related to Device Contexts (DC) and the GetDCEx function, aka "Win32k Improper Data Validation Vulnerability."
14386| [CVE-2010-0483] vbscript.dll in VBScript 5.1, 5.6, 5.7, and 5.8 in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, when Internet Explorer is used, allows user-assisted remote attackers to execute arbitrary code by referencing a (1) local pathname, (2) UNC share pathname, or (3) WebDAV server with a crafted .hlp file in the fourth argument (aka helpfile argument) to the MsgBox function, leading to code execution involving winhlp32.exe when the F1 key is pressed, aka "VBScript Help Keypress Vulnerability."
14387| [CVE-2010-0482] The kernel in Microsoft Windows Server 2008 R2 and Windows 7 does not properly validate relocation sections of image files, which allows local users to cause a denial of service (reboot) via a crafted file, aka "Windows Kernel Malformed Image Vulnerability."
14388| [CVE-2010-0481] The kernel in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly translate a registry key's virtual path to its real path, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Virtual Path Parsing Vulnerability."
14389| [CVE-2010-0480] Multiple stack-based buffer overflows in the MPEG Layer-3 audio codecs in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allow remote attackers to execute arbitrary code via a crafted AVI file, aka "MPEG Layer-3 Audio Decoder Stack Overflow Vulnerability."
14390| [CVE-2010-0479] Buffer overflow in Microsoft Office Publisher 2002 SP3, 2003 SP3, and 2007 SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Microsoft Office Publisher File Conversion TextBox Processing Buffer Overflow Vulnerability."
14391| [CVE-2010-0478] Stack-based buffer overflow in nsum.exe in the Windows Media Unicast Service in Media Services for Microsoft Windows 2000 Server SP4 allows remote attackers to execute arbitrary code via crafted packets associated with transport information, aka "Media Services Stack-based Buffer Overflow Vulnerability."
14392| [CVE-2010-0477] The SMB client in Microsoft Windows Server 2008 R2 and Windows 7 does not properly handle (1) SMBv1 and (2) SMBv2 response packets, which allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code via a crafted packet that causes the client to read the entirety of the response, and then improperly interact with the Winsock Kernel (WSK), aka "SMB Client Message Size Vulnerability."
14393| [CVE-2010-0476] The SMB client in Microsoft Windows Server 2003 SP2, Vista Gold, SP1, and SP2, and Windows Server 2008 Gold and SP2 allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and reboot) via a crafted SMB transaction response that uses (1) SMBv1 or (2) SMBv2, aka "SMB Client Response Parsing Vulnerability."
14394| [CVE-2010-0278] A certain ActiveX control in msgsc.14.0.8089.726.dll in Microsoft Windows Live Messenger 2009 build 14.0.8089.726 on Windows Vista and Windows 7 allows remote attackers to cause a denial of service (msnmsgr.exe crash) by calling the ViewProfile method with a crafted argument during an MSN Messenger session.
14395| [CVE-2010-0270] The SMB client in Microsoft Windows Server 2008 R2 and Windows 7 does not properly validate fields in SMB transaction responses, which allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and reboot) via a crafted (1) SMBv1 or (2) SMBv2 response, aka "SMB Client Transaction Vulnerability."
14396| [CVE-2010-0269] The SMB client in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly allocate memory for SMB responses, which allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code via a crafted (1) SMBv1 or (2) SMBv2 response, aka "SMB Client Memory Allocation Vulnerability."
14397| [CVE-2010-0268] Unspecified vulnerability in the Windows Media Player ActiveX control in Windows Media Player (WMP) 9 on Microsoft Windows 2000 SP4 and XP SP2 and SP3 allows remote attackers to execute arbitrary code via crafted media content, aka "Media Player Remote Code Execution Vulnerability."
14398| [CVE-2010-0266] Microsoft Office Outlook 2002 SP3, 2003 SP3, and 2007 SP1 and SP2 does not properly verify e-mail attachments with a PR_ATTACH_METHOD property value of ATTACH_BY_REFERENCE, which allows user-assisted remote attackers to execute arbitrary code via a crafted message, aka "Microsoft Outlook SMB Attachment Vulnerability."
14399| [CVE-2010-0265] Buffer overflow in Microsoft Windows Movie Maker 2.1, 2.6, and 6.0, and Microsoft Producer 2003, allows remote attackers to execute arbitrary code via a crafted project (.MSWMM) file, aka "Movie Maker and Producer Buffer Overflow Vulnerability."
14400| [CVE-2010-0264] Microsoft Office Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Microsoft Office Excel DbOrParamQry Record Parsing Vulnerability."
14401| [CVE-2010-0263] Microsoft Office Excel 2007 SP1 and SP2
14402| [CVE-2010-0262] Microsoft Office Excel 2007 SP1 and SP2 and Office 2004 for Mac do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet that triggers access of an uninitialized stack variable, aka "Microsoft Office Excel FNGROUPNAME Record Uninitialized Memory Vulnerability."
14403| [CVE-2010-0261] Heap-based buffer overflow in Microsoft Office Excel 2007 SP1 and SP2 and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted spreadsheet in which "a MDXSET record is broken up into several records," aka "Microsoft Office Excel MDXSET Record Heap Overflow Vulnerability."
14404| [CVE-2010-0260] Heap-based buffer overflow in Microsoft Office Excel 2007 SP1 and SP2
14405| [CVE-2010-0258] Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2
14406| [CVE-2010-0257] Microsoft Office Excel 2002 SP3 does not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Microsoft Office Excel Record Memory Corruption Vulnerability."
14407| [CVE-2010-0256] Microsoft Office Visio 2002 SP2, 2003 SP3, and 2007 SP1 and SP2 does not properly calculate unspecified indexes associated with Visio files, which allows remote attackers to execute arbitrary code via a crafted file, aka "Visio Index Calculation Memory Corruption Vulnerability."
14408| [CVE-2010-0254] Microsoft Office Visio 2002 SP2, 2003 SP3, and 2007 SP1 and SP2 does not properly validate attributes in Visio files, which allows remote attackers to execute arbitrary code via a crafted file, aka "Visio Attribute Validation Memory Corruption Vulnerability."
14409| [CVE-2010-0252] The Microsoft Data Analyzer ActiveX control (aka the Office Excel ActiveX control for Data Analysis) in max3activex.dll in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows remote attackers to execute arbitrary code via a crafted web page that corrupts the "system state," aka "Microsoft Data Analyzer ActiveX Control Vulnerability."
14410| [CVE-2010-0250] Heap-based buffer overflow in DirectShow in Microsoft DirectX, as used in the AVI Filter on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2, and in Quartz on Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, allows remote attackers to execute arbitrary code via an AVI file with a crafted length field in an unspecified video stream, which is not properly handled by the RLE video decompressor, aka "DirectShow Heap Overflow Vulnerability."
14411| [CVE-2010-0249] Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4
14412| [CVE-2010-0243] Buffer overflow in MSO.DLL in Microsoft Office XP SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Office document, aka "MSO.DLL Buffer Overflow."
14413| [CVE-2010-0242] The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 allows remote attackers to cause a denial of service (system hang) via crafted packets with malformed TCP selective acknowledgement (SACK) values, aka "TCP/IP Selective Acknowledgement Vulnerability."
14414| [CVE-2010-0241] The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2, when IPv6 is enabled, does not properly perform bounds checking on ICMPv6 Route Information packets, which allows remote attackers to execute arbitrary code via crafted packets, aka "ICMPv6 Route Information Vulnerability."
14415| [CVE-2010-0240] The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2, when a custom network driver is used, does not properly handle local fragmentation of Encapsulating Security Payload (ESP) over UDP packets, which allows remote attackers to execute arbitrary code via crafted packets, aka "Header MDL Fragmentation Vulnerability."
14416| [CVE-2010-0239] The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2, when IPv6 is enabled, does not properly perform bounds checking on ICMPv6 Router Advertisement packets, which allows remote attackers to execute arbitrary code via crafted packets, aka "ICMPv6 Router Advertisement Vulnerability."
14417| [CVE-2010-0238] Unspecified vulnerability in registry-key validation in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Vista Gold allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Registry Key Vulnerability."
14418| [CVE-2010-0237] The kernel in Microsoft Windows 2000 SP4 and XP SP2 and SP3 allows local users to gain privileges by creating a symbolic link from an untrusted registry hive to a trusted registry hive, aka "Windows Kernel Symbolic Link Creation Vulnerability."
14419| [CVE-2010-0236] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Vista Gold does not properly allocate memory for the destination key associated with a symbolic-link registry key, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Memory Allocation Vulnerability."
14420| [CVE-2010-0235] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Vista Gold does not perform the expected validation before creating a symbolic link, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Symbolic Link Value Vulnerability."
14421| [CVE-2010-0234] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 does not properly validate a registry-key argument to an unspecified system call, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Null Pointer Vulnerability."
14422| [CVE-2010-0233] Double free vulnerability in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows local users to gain privileges via a crafted application, aka "Windows Kernel Double Free Vulnerability."
14423| [CVE-2010-0232] The kernel in Microsoft Windows NT 3.1 through Windows 7, including Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, and Windows Server 2008 Gold and SP2, when access to 16-bit applications is enabled on a 32-bit x86 platform, does not properly validate certain BIOS calls, which allows local users to gain privileges by crafting a VDM_TIB data structure in the Thread Environment Block (TEB), and then calling the NtVdmControl function to start the Windows Virtual DOS Machine (aka NTVDM) subsystem, leading to improperly handled exceptions involving the #GP trap handler (nt!KiTrap0D), aka "Windows Kernel Exception Handler Vulnerability."
14424| [CVE-2010-0231] The SMB implementation in the Server service in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not use a sufficient source of entropy, which allows remote attackers to obtain access to files and other SMB resources via a large number of authentication requests, related to server-generated challenges, certain "duplicate values," and spoofing of an authentication token, aka "SMB NTLM Authentication Lack of Entropy Vulnerability."
14425| [CVE-2010-0035] The Key Distribution Center (KDC) in Kerberos in Microsoft Windows 2000 SP4, Server 2003 SP2, and Server 2008 Gold and SP2, when a trust relationship with a non-Windows Kerberos realm exists, allows remote authenticated users to cause a denial of service (NULL pointer dereference and domain controller outage) via a crafted Ticket Granting Ticket (TGT) renewal request, aka "Kerberos Null Pointer Dereference Vulnerability."
14426| [CVE-2010-0034] Stack-based buffer overflow in Microsoft Office PowerPoint 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "Office PowerPoint Viewer TextCharsAtom Record Stack Overflow Vulnerability."
14427| [CVE-2010-0033] Stack-based buffer overflow in Microsoft Office PowerPoint 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint Viewer TextBytesAtom Record Stack Overflow Vulnerability."
14428| [CVE-2010-0032] Use-after-free vulnerability in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "OEPlaceholderAtom Use After Free Vulnerability."
14429| [CVE-2010-0031] Array index error in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3, and PowerPoint in Office 2004 for Mac, allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint OEPlaceholderAtom 'placementId' Invalid Array Indexing Vulnerability."
14430| [CVE-2010-0030] Heap-based buffer overflow in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint LinkedSlideAtom Heap Overflow Vulnerability."
14431| [CVE-2010-0029] Buffer overflow in Microsoft Office PowerPoint 2002 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint File Path Handling Buffer Overflow Vulnerability."
14432| [CVE-2010-0028] Integer overflow in Microsoft Paint in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted JPEG (.JPG) file, aka "MS Paint Integer Overflow Vulnerability."
14433| [CVE-2010-0027] The URL validation functionality in Microsoft Internet Explorer 5.01, 6, 6 SP1, 7 and 8, and the ShellExecute API function in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, does not properly process input parameters, which allows remote attackers to execute arbitrary local programs via a crafted URL, aka "URL Validation Vulnerability."
14434| [CVE-2010-0026] The Hyper-V server implementation in Microsoft Windows Server 2008 Gold, SP2, and R2 on the x64 platform allows guest OS users to cause a denial of service (host OS hang) via a crafted application that executes a malformed series of machine instructions, aka "Hyper-V Instruction Set Validation Vulnerability."
14435| [CVE-2010-0025] The SMTP component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Server 2008 Gold, SP2, and R2, and Exchange Server 2000 SP3, does not properly allocate memory for SMTP command replies, which allows remote attackers to read fragments of e-mail messages by sending a series of invalid commands and then sending a STARTTLS command, aka "SMTP Memory Allocation Vulnerability."
14436| [CVE-2010-0024] The SMTP component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Server 2008 Gold, SP2, and R2, and Exchange Server 2003 SP2, does not properly parse MX records, which allows remote DNS servers to cause a denial of service (service outage) via a crafted response to a DNS MX record query, aka "SMTP Server MX Record Vulnerability."
14437| [CVE-2010-0023] The Client/Server Run-time Subsystem (CSRSS) in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly kill processes after a logout, which allows local users to obtain sensitive information or gain privileges via a crafted application that continues to execute throughout the logout of one user and the login session of the next user, aka "CSRSS Local Privilege Elevation Vulnerability."
14438| [CVE-2010-0022] The SMB implementation in the Server service in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate the share and servername fields in SMB packets, which allows remote attackers to cause a denial of service (system hang) via a crafted packet, aka "SMB Null Pointer Vulnerability."
14439| [CVE-2010-0021] Multiple race conditions in the SMB implementation in the Server service in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allow remote attackers to cause a denial of service (system hang) via a crafted (1) SMBv1 or (2) SMBv2 Negotiate packet, aka "SMB Memory Corruption Vulnerability."
14440| [CVE-2010-0020] The SMB implementation in the Server service in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate request fields, which allows remote authenticated users to execute arbitrary code via a malformed request, aka "SMB Pathname Overflow Vulnerability."
14441| [CVE-2010-0018] Integer overflow in the Embedded OpenType (EOT) Font Engine (t2embed.dll) in Microsoft Windows 2000 SP4
14442| [CVE-2010-0017] Race condition in the SMB client implementation in Microsoft Windows Server 2008 R2 and Windows 7 allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code, and in the SMB client implementation in Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 allows local users to gain privileges, via a crafted SMB Negotiate response, aka "SMB Client Race Condition Vulnerability."
14443| [CVE-2010-0016] The SMB client implementation in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly validate response fields, which allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code via a crafted response, aka "SMB Client Pool Corruption Vulnerability."
14444| [CVE-2009-4313] ir32_32.dll 3.24.15.3 in the Indeo32 codec in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to cause a denial of service (heap corruption) or execute arbitrary code via malformed data in a stream in a media file, as demonstrated by an AVI file.
14445| [CVE-2009-4312] Unspecified vulnerability in the Indeo codec in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via crafted media content, as reported to Microsoft by Dave Lenoe of Adobe.
14446| [CVE-2009-4311] Unspecified vulnerability in the Indeo codec in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via crafted media content, as reported to Microsoft by Paul Byrne of NGS Software. NOTE: this might overlap CVE-2008-3615.
14447| [CVE-2009-4310] Stack-based buffer overflow in the Intel Indeo41 codec for Windows Media Player in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via crafted compressed video data in an IV41 stream in a media file, leading to many loop iterations, as demonstrated by data in an AVI file.
14448| [CVE-2009-4309] Heap-based buffer overflow in the Intel Indeo41 codec for Windows Media Player in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via a large size value in a movi record in an IV41 stream in a media file, as demonstrated by an AVI file.
14449| [CVE-2009-4210] The Indeo codec in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via crafted media content.
14450| [CVE-2009-3830] The download functionality in Team Services in Microsoft Office SharePoint Server 2007 12.0.0.4518 and 12.0.0.6219 allows remote attackers to read ASP.NET source code via pathnames in the SourceUrl and Source parameters to _layouts/download.aspx.
14451| [CVE-2009-3678] Integer overflow in cdd.dll in the Canonical Display Driver (CDD) in Microsoft Windows Server 2008 R2 and Windows 7 on 64-bit platforms, when the Windows Aero theme is installed, allows context-dependent attackers to cause a denial of service (reboot) or possibly execute arbitrary code via a crafted image file that triggers incorrect data parsing after user-mode data is copied to kernel mode, as demonstrated using "Browse with Irfanview" and certain actions on a folder containing a large number of thumbnail images in Resample mode, possibly related to the ATI graphics driver or win32k.sys, aka "Canonical Display Driver Integer Overflow Vulnerability."
14452| [CVE-2009-3677] The Internet Authentication Service (IAS) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold and SP1, and Server 2008 Gold does not properly verify the credentials in an MS-CHAP v2 Protected Extensible Authentication Protocol (PEAP) authentication request, which allows remote attackers to access network resources via a malformed request, aka "MS-CHAP Authentication Bypass Vulnerability."
14453| [CVE-2009-3676] The SMB client in the kernel in Microsoft Windows Server 2008 R2 and Windows 7 allows remote SMB servers and man-in-the-middle attackers to cause a denial of service (infinite loop and system hang) via a (1) SMBv1 or (2) SMBv2 response packet that contains (a) an incorrect length value in a NetBIOS header or (b) an additional length field at the end of this response packet, aka "SMB Client Incomplete Response Vulnerability."
14454| [CVE-2009-3675] LSASS.exe in the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote authenticated users to cause a denial of service (CPU consumption) via a malformed ISAKMP request over IPsec, aka "Local Security Authority Subsystem Service Resource Exhaustion Vulnerability."
14455| [CVE-2009-3450] Multiple cross-site scripting (XSS) vulnerabilities in WebCoreModule.ashx in RADactive I-Load before 2008.2.5.0 allow remote attackers to inject arbitrary web script or HTML via parameters with names beginning with __ (underscore underscore) sequences, which are incompatible with an XSS protection mechanism provided by Microsoft ASP.NET.
14456| [CVE-2009-3135] Stack-based buffer overflow in Microsoft Office Word 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, Open XML File Format Converter for Mac, Office Word Viewer 2003 SP3, and Office Word Viewer allow remote attackers to execute arbitrary code via a Word document with a malformed File Information Block (FIB) structure, aka "Microsoft Office Word File Information Memory Corruption Vulnerability."
14457| [CVE-2009-3134] Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2
14458| [CVE-2009-3133] Microsoft Office Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code via a spreadsheet containing a malformed object that triggers memory corruption, related to "loading Excel records," aka "Excel Document Parsing Memory Corruption Vulnerability."
14459| [CVE-2009-3132] Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2
14460| [CVE-2009-3131] Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2
14461| [CVE-2009-3130] Heap-based buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via a spreadsheet containing a malformed Binary File Format (aka BIFF) record that triggers memory corruption, aka "Excel Document Parsing Heap Overflow Vulnerability."
14462| [CVE-2009-3129] Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2
14463| [CVE-2009-3128] Microsoft Office Excel 2002 SP3 and 2003 SP3, and Office Excel Viewer 2003 SP3, does not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a spreadsheet with a malformed record object, aka "Excel SxView Memory Corruption Vulnerability."
14464| [CVE-2009-3127] Microsoft Office Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, Open XML File Format Converter for Mac, and Office Excel Viewer 2003 SP3 do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel Cache Memory Corruption Vulnerability."
14465| [CVE-2009-3126] Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a crafted PNG image file, aka "GDI+ PNG Integer Overflow Vulnerability."
14466| [CVE-2009-3103] Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, and Windows 7 RC allows remote attackers to execute arbitrary code or cause a denial of service (system crash) via an & (ampersand) character in a Process ID High header field in a NEGOTIATE PROTOCOL REQUEST packet, which triggers an attempted dereference of an out-of-bounds memory location, aka "SMBv2 Negotiation Vulnerability." NOTE: some of these details are obtained from third party information.
14467| [CVE-2009-3020] win32k.sys in Microsoft Windows Server 2003 SP2 allows remote attackers to cause a denial of service (system crash) by referencing a crafted .eot file in the src descriptor of an @font-face Cascading Style Sheets (CSS) rule in an HTML document, possibly related to the Embedded OpenType (EOT) Font Engine, a different vulnerability than CVE-2006-0010, CVE-2009-0231, and CVE-2009-0232. NOTE: some of these details are obtained from third party information.
14468| [CVE-2009-2653] ** DISPUTED ** The NtUserConsoleControl function in win32k.sys in Microsoft Windows XP SP2 and SP3, and Server 2003 before SP1, allows local administrators to bypass unspecified "security software" and gain privileges via a crafted call that triggers an overwrite of an arbitrary memory location. NOTE: the vendor disputes the significance of this report, stating that 'the Administrator to SYSTEM "escalation" is not a security boundary we defend.'
14469| [CVE-2009-2532] Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, and Windows 7 RC do not properly process the command value in an SMB Multi-Protocol Negotiate Request packet, which allows remote attackers to execute arbitrary code via a crafted SMBv2 packet to the Server service, aka "SMBv2 Command Value Vulnerability."
14470| [CVE-2009-2526] Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 do not properly validate fields in SMBv2 packets, which allows remote attackers to cause a denial of service (infinite loop and system hang) via a crafted packet to the Server service, aka "SMBv2 Infinite Loop Vulnerability."
14471| [CVE-2009-2524] Integer underflow in the NTLM authentication feature in the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows remote attackers to cause a denial of service (reboot) via a malformed packet, aka "Local Security Authority Subsystem Service Integer Overflow Vulnerability."
14472| [CVE-2009-2523] The License Logging Server (llssrv.exe) in Microsoft Windows 2000 SP4 allows remote attackers to execute arbitrary code via an RPC message containing a string without a null terminator, which triggers a heap-based buffer overflow in the LlsrLicenseRequestW method, aka "License Logging Server Heap Overflow Vulnerability."
14473| [CVE-2009-2519] The DHTML Editing Component ActiveX control in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly format HTML markup, which allows remote attackers to execute arbitrary code via a crafted web site that triggers "system state" corruption, aka "DHTML Editing Component ActiveX Control Vulnerability."
14474| [CVE-2009-2517] The kernel in Microsoft Windows Server 2003 SP2 does not properly handle unspecified exceptions when an error condition occurs, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Exception Handler Vulnerability."
14475| [CVE-2009-2516] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold and SP1, and Server 2008 Gold does not properly validate data sent from user mode, which allows local users to gain privileges via a crafted PE .exe file that triggers a NULL pointer dereference during chain traversal, aka "Windows Kernel NULL Pointer Dereference Vulnerability."
14476| [CVE-2009-2515] Integer underflow in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows local users to gain privileges via a crafted application that triggers an incorrect truncation of a 64-bit integer to a 32-bit integer, aka "Windows Kernel Integer Underflow Vulnerability."
14477| [CVE-2009-2514] win32k.sys in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not correctly parse font code during construction of a directory-entry table, which allows remote attackers to execute arbitrary code via a crafted Embedded OpenType (EOT) font, aka "Win32k EOT Parsing Vulnerability."
14478| [CVE-2009-2513] The Graphics Device Interface (GDI) in win32k.sys in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Win32k Insufficient Data Validation Vulnerability."
14479| [CVE-2009-2511] Integer overflow in the CryptoAPI component in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows man-in-the-middle attackers to spoof arbitrary SSL servers and other entities via an X.509 certificate that has a malformed ASN.1 Object Identifier (OID) and was issued by a legitimate Certification Authority, aka "Integer Overflow in X.509 Object Identifiers Vulnerability."
14480| [CVE-2009-2510] The CryptoAPI component in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, as used by Internet Explorer and other applications, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, aka "Null Truncation in X.509 Common Name Vulnerability," a related issue to CVE-2009-2408.
14481| [CVE-2009-2509] Active Directory Federation Services (ADFS) in Microsoft Windows Server 2003 SP2 and Server 2008 Gold and SP2 does not properly validate headers in HTTP requests, which allows remote authenticated users to execute arbitrary code via a crafted request to an IIS web server, aka "Remote Code Execution in ADFS Vulnerability."
14482| [CVE-2009-2508] The single sign-on implementation in Active Directory Federation Services (ADFS) in Microsoft Windows Server 2003 SP2 and Server 2008 Gold and SP2 does not properly remove credentials at the end of a network session, which allows physically proximate attackers to obtain the credentials of a previous user of the same web browser by using data from the browser's cache, aka "Single Sign On Spoofing in ADFS Vulnerability."
14483| [CVE-2009-2507] A certain ActiveX control in the Indexing Service in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly process URLs, which allows remote attackers to execute arbitrary programs via unspecified vectors that cause a "vulnerable binary" to load and run, aka "Memory Corruption in Indexing Service Vulnerability."
14484| [CVE-2009-2506] Integer overflow in the text converters in Microsoft Office Word 2002 SP3 and 2003 SP3
14485| [CVE-2009-2505] The Internet Authentication Service (IAS) in Microsoft Windows Vista SP2 and Server 2008 SP2 does not properly validate MS-CHAP v2 Protected Extensible Authentication Protocol (PEAP) authentication requests, which allows remote attackers to execute arbitrary code via crafted structures in a malformed request, aka "Internet Authentication Service Memory Corruption Vulnerability."
14486| [CVE-2009-2504] Multiple integer overflows in unspecified APIs in GDI+ in Microsoft .NET Framework 1.1 SP1, .NET Framework 2.0 SP1 and SP2, Windows XP SP2 and SP3, Windows Server 2003 SP2, Vista Gold and SP1, Server 2008 Gold, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allow remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "GDI+ .NET API Vulnerability."
14487| [CVE-2009-2503] GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Windows Server 2003 SP2, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 does not properly allocate an unspecified buffer, which allows remote attackers to execute arbitrary code via a crafted TIFF image file that triggers memory corruption, aka "GDI+ TIFF Memory Corruption Vulnerability."
14488| [CVE-2009-2502] Buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a crafted TIFF image file, aka "GDI+ TIFF Buffer Overflow Vulnerability."
14489| [CVE-2009-2501] Heap-based buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a crafted PNG image file, aka "GDI+ PNG Heap Overflow Vulnerability."
14490| [CVE-2009-2500] Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a crafted WMF image file, aka "GDI+ WMF Integer Overflow Vulnerability."
14491| [CVE-2009-2498] Microsoft Windows Media Format Runtime 9.0, 9.5, and 11 and Windows Media Services 9.1 and 2008 do not properly parse malformed headers in Advanced Systems Format (ASF) files, which allows remote attackers to execute arbitrary code via a crafted (1) .asf, (2) .wmv, or (3) .wma file, aka "Windows Media Header Parsing Invalid Free Vulnerability."
14492| [CVE-2009-2497] The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0, 2.0 SP1, 2.0 SP2, 3.5, and 3.5 SP1, and Silverlight 2, does not properly handle interfaces, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP), (2) a crafted Silverlight application, (3) a crafted ASP.NET application, or (4) a crafted .NET Framework application, aka "Microsoft Silverlight and Microsoft .NET Framework CLR Vulnerability."
14493| [CVE-2009-2496] Heap-based buffer overflow in the Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2003 SP3, Office XP Web Components SP3, Office 2003 Web Components SP3, Office 2003 Web Components SP1 for the 2007 Microsoft Office System, Internet Security and Acceleration (ISA) Server 2004 SP3 and 2006 SP1, and Office Small Business Accounting 2006 allows remote attackers to execute arbitrary code via unspecified parameters to unknown methods, aka "Office Web Components Heap Corruption Vulnerability."
14494| [CVE-2009-2495] The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and 2008 Gold and SP1 does not properly enforce string termination, which allows remote attackers to obtain sensitive information via a crafted HTML document with an ATL (1) component or (2) control that triggers a buffer over-read, related to ATL headers and buffer allocation, aka "ATL Null String Vulnerability."
14495| [CVE-2009-2494] The Active Template Library (ATL) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via vectors related to erroneous free operations after reading a variant from a stream and deleting this variant, aka "ATL Object Type Mismatch Vulnerability."
14496| [CVE-2009-2493] The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and 2008 Gold and SP1
14497| [CVE-2009-1930] The Telnet service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote Telnet servers to execute arbitrary code on a client machine by replaying the NTLM credentials of a client user, aka "Telnet Credential Reflection Vulnerability," a related issue to CVE-2000-0834.
14498| [CVE-2009-1929] Heap-based buffer overflow in the Microsoft Terminal Services Client ActiveX control running RDP 6.1 on Windows XP SP2, Vista SP1 or SP2, or Server 2008 Gold or SP2
14499| [CVE-2009-1928] Stack consumption vulnerability in the LDAP service in Active Directory on Microsoft Windows 2000 SP4, Server 2003 SP2, and Server 2008 Gold and SP2
14500| [CVE-2009-1926] Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allow remote attackers to cause a denial of service (TCP outage) via a series of TCP sessions that have pending data and a (1) small or (2) zero receive window size, and remain in the FIN-WAIT-1 or FIN-WAIT-2 state indefinitely, aka "TCP/IP Orphaned Connections Vulnerability."
14501| [CVE-2009-1925] The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 does not properly manage state information, which allows remote attackers to execute arbitrary code by sending packets to a listening service, and thereby triggering misinterpretation of an unspecified field as a function pointer, aka "TCP/IP Timestamps Code Execution Vulnerability."
14502| [CVE-2009-1924] Integer overflow in the Windows Internet Name Service (WINS) component for Microsoft Windows 2000 SP4 allows remote WINS replication partners to execute arbitrary code via crafted data structures in a packet, aka "WINS Integer Overflow Vulnerability."
14503| [CVE-2009-1923] Heap-based buffer overflow in the Windows Internet Name Service (WINS) component for Microsoft Windows 2000 SP4 and Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted WINS replication packet that triggers an incorrect buffer-length calculation, aka "WINS Heap Overflow Vulnerability."
14504| [CVE-2009-1922] The Message Queuing (aka MSMQ) service for Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP2, and Vista Gold does not properly validate unspecified IOCTL request data from user mode before passing this data to kernel mode, which allows local users to gain privileges via a crafted request, aka "MSMQ Null Pointer Vulnerability."
14505| [CVE-2009-1546] Integer overflow in Avifil32.dll in the Windows Media file handling functionality in Microsoft Windows allows remote attackers to execute arbitrary code on a Windows 2000 SP4 system via a crafted AVI file, or cause a denial of service on a Windows XP SP2 or SP3, Server 2003 SP2, Vista Gold, SP1, or SP2, or Server 2008 Gold or SP2 system via a crafted AVI file, aka "AVI Integer Overflow Vulnerability."
14506| [CVE-2009-1545] Unspecified vulnerability in Avifil32.dll in the Windows Media file handling functionality in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a malformed header in a crafted AVI file, aka "Malformed AVI Header Vulnerability."
14507| [CVE-2009-1544] Double free vulnerability in the Workstation service in Microsoft Windows allows remote authenticated users to gain privileges via a crafted RPC message to a Windows XP SP2 or SP3 or Server 2003 SP2 system, or cause a denial of service via a crafted RPC message to a Vista Gold, SP1, or SP2 or Server 2008 Gold or SP2 system, aka "Workstation Service Memory Corruption Vulnerability."
14508| [CVE-2009-1542] The Virtual Machine Monitor (VMM) in Microsoft Virtual PC 2004 SP1, 2007, and 2007 SP1, and Microsoft Virtual Server 2005 R2 SP1, does not enforce CPU privilege-level requirements for all machine instructions, which allows guest OS users to execute arbitrary kernel-mode code and gain privileges within the guest OS via a crafted application, aka "Virtual PC and Virtual Server Privileged Instruction Decoding Vulnerability."
14509| [CVE-2009-1539] The QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2 does not properly validate unspecified size fields in QuickTime media files, which allows remote attackers to execute arbitrary code via a crafted file, aka "DirectX Size Validation Vulnerability."
14510| [CVE-2009-1538] The QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2 performs updates to pointers without properly validating unspecified data values, which allows remote attackers to execute arbitrary code via a crafted QuickTime media file, aka "DirectX Pointer Validation Vulnerability."
14511| [CVE-2009-1537] Unspecified vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted QuickTime media file, as exploited in the wild in May 2009, aka "DirectX NULL Byte Overwrite Vulnerability."
14512| [CVE-2009-1536] ASP.NET in Microsoft .NET Framework 2.0 SP1 and SP2 and 3.5 Gold and SP1, when ASP 2.0 is used in integrated mode on IIS 7.0, does not properly manage request scheduling, which allows remote attackers to cause a denial of service (daemon outage) via a series of crafted HTTP requests, aka "Remote Unauthenticated Denial of Service in ASP.NET Vulnerability."
14513| [CVE-2009-1534] Buffer overflow in the Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2000 Web Components SP3, Office XP Web Components SP3, BizTalk Server 2002, and Visual Studio .NET 2003 SP1 allows remote attackers to execute arbitrary code via crafted property values, aka "Office Web Components Buffer Overflow Vulnerability."
14514| [CVE-2009-1533] Buffer overflow in the Works for Windows document converters in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, Office 2007 SP1, and Works 8.5 and 9 allows remote attackers to execute arbitrary code via a crafted Works .wps file that triggers memory corruption, aka "File Converter Buffer Overflow Vulnerability."
14515| [CVE-2009-1491] McAfee GroupShield for Microsoft Exchange on Exchange Server 2000, and possibly other anti-virus or anti-spam products from McAfee or other vendors, does not scan X- headers for malicious content, which allows remote attackers to bypass virus detection via a crafted message, as demonstrated by a message with an X-Testing header and no message body.
14516| [CVE-2009-1216] Multiple unspecified vulnerabilities in (1) unlzh.c and (2) unpack.c in the gzip libraries in Microsoft Windows Server 2008, Windows Services for UNIX 3.0 and 3.5, and the Subsystem for UNIX-based Applications (SUA)
14517| [CVE-2009-1141] Microsoft Internet Explorer 6 for Windows XP SP2 and SP3 and Server 2003 SP2 allows remote attackers to execute arbitrary code via unspecified DHTML function calls related to a tr element and the "insertion, deletion and attributes of a table cell," which trigger memory corruption when the window is destroyed, aka "DHTML Object Memory Corruption Vulnerability."
14518| [CVE-2009-1139] Memory leak in the LDAP service in Active Directory on Microsoft Windows 2000 SP4 and Server 2003 SP2, and Active Directory Application Mode (ADAM) on Windows XP SP2 and SP3 and Server 2003 SP2, allows remote attackers to cause a denial of service (memory consumption and service outage) via (1) LDAP or (2) LDAPS requests with unspecified OID filters, aka "Active Directory Memory Leak Vulnerability."
14519| [CVE-2009-1138] The LDAP service in Active Directory on Microsoft Windows 2000 SP4 does not properly free memory for LDAP and LDAPS requests, which allows remote attackers to execute arbitrary code via a request that uses hexadecimal encoding, whose associated memory is not released, related to a "DN AttributeValue," aka "Active Directory Invalid Free Vulnerability." NOTE: this issue is probably a memory leak.
14520| [CVE-2009-1137] Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that uses a PowerPoint 4.0 native file format, leading to memory corruption, aka "Legacy File Format Vulnerability," a different vulnerability than CVE-2009-0222, CVE-2009-0223, CVE-2009-0226, and CVE-2009-0227.
14521| [CVE-2009-1136] The Microsoft Office Web Components Spreadsheet ActiveX control (aka OWC10 or OWC11), as distributed in Office XP SP3 and Office 2003 SP3, Office XP Web Components SP3, Office 2003 Web Components SP3, Office 2003 Web Components SP1 for the 2007 Microsoft Office System, Internet Security and Acceleration (ISA) Server 2004 SP3 and 2006 Gold and SP1, and Office Small Business Accounting 2006, when used in Internet Explorer, allows remote attackers to execute arbitrary code via a crafted call to the msDataSourceObject method, as exploited in the wild in July and August 2009, aka "Office Web Components HTML Script Vulnerability."
14522| [CVE-2009-1135] Microsoft Internet Security and Acceleration (ISA) Server 2006 Gold and SP1, when Radius OTP is enabled, uses the HTTP-Basic authentication method, which allows remote attackers to gain the privileges of an arbitrary account, and access published web pages, via vectors involving attempted access to a network resource behind the ISA Server, aka "Radius OTP Bypass Vulnerability."
14523| [CVE-2009-1134] Excel in 2007 Microsoft Office System SP1 and SP2
14524| [CVE-2009-1133] Heap-based buffer overflow in Microsoft Remote Desktop Connection (formerly Terminal Services Client) running RDP 5.0 through 6.1 on Windows, and Remote Desktop Connection Client for Mac 2.0, allows remote attackers to execute arbitrary code via unspecified parameters, aka "Remote Desktop Connection Heap Overflow Vulnerability."
14525| [CVE-2009-1132] Heap-based buffer overflow in the Wireless LAN AutoConfig Service (aka Wlansvc) in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a malformed wireless frame, aka "Wireless Frame Parsing Remote Code Execution Vulnerability."
14526| [CVE-2009-1131] Multiple stack-based buffer overflows in Microsoft Office PowerPoint 2000 SP3 allow remote attackers to execute arbitrary code via a large amount of data associated with unspecified atoms in a PowerPoint file that triggers memory corruption, aka "Data Out of Bounds Vulnerability."
14527| [CVE-2009-1130] Heap-based buffer overflow in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac, allows remote attackers to execute arbitrary code via a crafted structure in a Notes container in a PowerPoint file that causes PowerPoint to read more data than was allocated when creating a C++ object, leading to an overwrite of a function pointer, aka "Heap Corruption Vulnerability."
14528| [CVE-2009-1129] Multiple stack-based buffer overflows in the PowerPoint 95 importer (PP7X32.DLL) in Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allow remote attackers to execute arbitrary code via an inconsistent record length in sound data in a file that uses a PowerPoint 95 (PPT95) native file format, aka "PP7 Memory Corruption Vulnerability," a different vulnerability than CVE-2009-1128.
14529| [CVE-2009-1128] Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that uses a PowerPoint 95 native file format, leading to memory corruption, aka "PP7 Memory Corruption Vulnerability," a different vulnerability than CVE-2009-1129.
14530| [CVE-2009-1127] win32k.sys in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 does not correctly validate an argument to an unspecified system call, which allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, aka "Win32k NULL Pointer Dereferencing Vulnerability."
14531| [CVE-2009-1126] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly validate the user-mode input associated with the editing of an unspecified desktop parameter, which allows local users to gain privileges via a crafted application, aka "Windows Desktop Parameter Edit Vulnerability."
14532| [CVE-2009-1125] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate an argument to an unspecified system call, which allows local users to gain privileges via a crafted application, aka "Windows Driver Class Registration Vulnerability."
14533| [CVE-2009-1124] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate user-mode pointers in unspecified error conditions, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Pointer Validation Vulnerability."
14534| [CVE-2009-1123] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate changes to unspecified kernel objects, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Desktop Vulnerability."
14535| [CVE-2009-1122] The WebDAV extension in Microsoft Internet Information Services (IIS) 5.0 on Windows 2000 SP4 does not properly decode URLs, which allows remote attackers to bypass authentication, and possibly read or create files, via a crafted HTTP request, aka "IIS 5.0 WebDAV Authentication Bypass Vulnerability," a different vulnerability than CVE-2009-1535.
14536| [CVE-2009-1043] Unspecified vulnerability in Microsoft Internet Explorer 8 on Windows 7 allows remote attackers to execute arbitrary code via unknown vectors triggered by clicking on a link, as demonstrated by Nils during a PWN2OWN competition at CanSecWest 2009.
14537| [CVE-2009-1011] Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.2.2 and 8.3.0 allows local users to affect confidentiality, integrity, and availability, related to HTML. NOTE: the previous information was obtained from the April 2009 CPU. Oracle has not commented on reliable researcher claims that this issue is for multiple integer overflows in a function that parses an optional data stream within a Microsoft Office file, leading to a heap-based buffer overflow.
14538| [CVE-2009-0901] The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold, and Visual C++ 2005 SP1 and 2008 Gold and SP1
14539| [CVE-2009-0568] The RPC Marshalling Engine (aka NDR) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly maintain its internal state, which allows remote attackers to overwrite arbitrary memory locations via a crafted RPC message that triggers incorrect pointer reading, related to "IDL interfaces containing a non-conformant varying array" and FC_SMVARRAY, FC_LGVARRAY, FC_VARIABLE_REPEAT, and FC_VARIABLE_OFFSET, aka "RPC Marshalling Engine Vulnerability."
14540| [CVE-2009-0566] Microsoft Office Publisher 2007 SP1 does not properly calculate object handler data for Publisher files, which allows remote attackers to execute arbitrary code via a crafted file in a legacy format that triggers memory corruption, aka "Pointer Dereference Vulnerability."
14541| [CVE-2009-0565] Buffer overflow in Microsoft Office Word 2000 SP3, 2002 SP3, and 2007 SP1 and SP2
14542| [CVE-2009-0563] Stack-based buffer overflow in Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP1 and SP2
14543| [CVE-2009-0562] The Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2003 SP3, Office XP Web Components SP3, Office 2003 Web Components SP3, Office 2003 Web Components SP1 for the 2007 Microsoft Office System, Internet Security and Acceleration (ISA) Server 2004 SP3 and 2006 SP1, and Office Small Business Accounting 2006 does not properly allocate memory, which allows remote attackers to execute arbitrary code via unspecified vectors that trigger "system state" corruption, aka "Office Web Components Memory Allocation Vulnerability."
14544| [CVE-2009-0561] Integer overflow in Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac
14545| [CVE-2009-0560] Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac
14546| [CVE-2009-0559] Stack-based buffer overflow in Excel in Microsoft Office 2000 SP3 and Office XP SP3 allows remote attackers to execute arbitrary code via a crafted Excel file with a malformed record object, aka "String Copy Stack-Based Overrun Vulnerability."
14547| [CVE-2009-0558] Array index error in Excel in Microsoft Office 2000 SP3 and Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac, allows remote attackers to execute arbitrary code via a crafted Excel file with a malformed record object, aka "Array Indexing Memory Corruption Vulnerability."
14548| [CVE-2009-0557] Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac
14549| [CVE-2009-0556] Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac, allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineTextRefAtom containing an an invalid index value that triggers memory corruption, as exploited in the wild in April 2009 by Exploit:Win32/Apptom.gen, aka "Memory Corruption Vulnerability."
14550| [CVE-2009-0554] Microsoft Internet Explorer 5.01 SP4, 6 SP1, 6 and 7 on Windows XP SP2 and SP3, 6 and 7 on Windows Server 2003 SP1 and SP2, 7 on Windows Vista Gold and SP1, and 7 on Windows Server 2008 allows remote attackers to execute arbitrary code via a web page that triggers presence of an object in memory that was (1) not properly initialized or (2) deleted, aka "Uninitialized Memory Corruption Vulnerability."
14551| [CVE-2009-0553] Microsoft Internet Explorer 6 SP1, 6 and 7 on Windows XP SP2 and SP3, 6 and 7 on Windows Server 2003 SP1 and SP2, 7 on Windows Vista Gold and SP1, and 7 on Windows Server 2008 allows remote attackers to execute arbitrary code via a web page that triggers presence of an object in memory that was (1) not properly initialized or (2) deleted, aka "Uninitialized Memory Corruption Vulnerability."
14552| [CVE-2009-0552] Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4, 6 SP1, 6 on Windows XP SP2 and SP3, and 6 on Windows Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via a web page that triggers presence of an object in memory that was (1) not properly initialized or (2) deleted, aka "Uninitialized Memory Corruption Vulnerability."
14553| [CVE-2009-0551] Microsoft Internet Explorer 6 SP1, 6 and 7 on Windows XP SP2 and SP3, 6 and 7 on Windows Server 2003 SP1 and SP2, 7 on Windows Vista Gold and SP1, and 7 on Windows Server 2008 does not properly handle transition errors in a request for one HTTP document followed by a request for a second HTTP document, which allows remote attackers to execute arbitrary code via vectors involving (1) multiple crafted pages on a web site or (2) a web page with crafted inline content such as banner advertisements, aka "Page Transition Memory Corruption Vulnerability."
14554| [CVE-2009-0550] Windows HTTP Services (aka WinHTTP) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008
14555| [CVE-2009-0549] Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac
14556| [CVE-2009-0320] Microsoft Windows XP, Server 2003 and 2008, and Vista exposes I/O activity measurements of all processes, which allows local users to obtain sensitive information, as demonstrated by reading the I/O Other Bytes column in Task Manager (aka taskmgr.exe) to estimate the number of characters that a different user entered at a runas.exe password prompt, related to a "benchmarking attack."
14557| [CVE-2009-0239] Cross-site scripting (XSS) vulnerability in Windows Search 4.0 for Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows user-assisted remote attackers to inject arbitrary web script or HTML via a crafted file that appears in a preview in a search result, aka "Script Execution in Windows Search Vulnerability."
14558| [CVE-2009-0238] Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1
14559| [CVE-2009-0235] Stack-based buffer overflow in the Word 97 text converter in WordPad in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted Word 97 file that triggers memory corruption, related to use of inconsistent integer data sizes for an unspecified length field, aka "WordPad Word 97 Text Converter Stack Overflow Vulnerability."
14560| [CVE-2009-0234] The DNS Resolver Cache Service (aka DNSCache) in Windows DNS Server in Microsoft Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008 does not properly cache crafted DNS responses, which makes it easier for remote attackers to predict transaction IDs and poison caches by sending many crafted DNS queries that trigger "unnecessary lookups," aka "DNS Server Response Validation Vulnerability."
14561| [CVE-2009-0233] The DNS Resolver Cache Service (aka DNSCache) in Windows DNS Server in Microsoft Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008, when dynamic updates are enabled, does not reuse cached DNS responses in all applicable situations, which makes it easier for remote attackers to predict transaction IDs and poison caches by simultaneously sending crafted DNS queries and responses, aka "DNS Server Query Validation Vulnerability."
14562| [CVE-2009-0232] Integer overflow in the Embedded OpenType (EOT) Font Engine in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a crafted name table, aka "Embedded OpenType Font Integer Overflow Vulnerability."
14563| [CVE-2009-0231] The Embedded OpenType (EOT) Font Engine (T2EMBED.DLL) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a crafted name table in a data record that triggers an integer truncation and a heap-based buffer overflow, aka "Embedded OpenType Font Heap Overflow Vulnerability."
14564| [CVE-2009-0230] The Windows Print Spooler in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 allows remote authenticated users to gain privileges via a crafted RPC message that triggers loading of a DLL file from an arbitrary directory, aka "Print Spooler Load Library Vulnerability."
14565| [CVE-2009-0229] The Windows Printing Service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 allows local users to read arbitrary files via a crafted separator page, aka "Print Spooler Read File Vulnerability."
14566| [CVE-2009-0228] Stack-based buffer overflow in the EnumeratePrintShares function in Windows Print Spooler Service (win32spl.dll) in Microsoft Windows 2000 SP4 allows remote printer servers to execute arbitrary code via a a crafted ShareName in a response to an RPC request, related to "printing data structures," aka "Buffer Overflow in Print Spooler Vulnerability."
14567| [CVE-2009-0227] Stack-based buffer overflow in the PowerPoint 4.2 conversion filter (PP4X32.DLL) in Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via a large number of structures in sound data in a file that uses a PowerPoint 4.0 native file format, leading to memory corruption, aka "Legacy File Format Vulnerability," a different vulnerability than CVE-2009-0222, CVE-2009-0223, CVE-2009-0226, and CVE-2009-1137.
14568| [CVE-2009-0226] Stack-based buffer overflow in the PowerPoint 4.2 conversion filter in Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via a long string in sound data in a file that uses a PowerPoint 4.0 native file format, leading to memory corruption, aka "Legacy File Format Vulnerability," a different vulnerability than CVE-2009-0222, CVE-2009-0223, CVE-2009-0227, and CVE-2009-1137.
14569| [CVE-2009-0225] Microsoft Office PowerPoint 2002 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that uses a PowerPoint 95 native file format, leading to improper "array indexing" and memory corruption, aka "PP7 Memory Corruption Vulnerability."
14570| [CVE-2009-0224] Microsoft Office PowerPoint 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1 and SP2
14571| [CVE-2009-0223] Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that uses a PowerPoint 4.0 native file format, leading to memory corruption, aka "Legacy File Format Vulnerability," a different vulnerability than CVE-2009-0222, CVE-2009-0226, CVE-2009-0227, and CVE-2009-1137.
14572| [CVE-2009-0222] Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that uses a PowerPoint 4.0 native file format, leading to a "pointer overwrite" and memory corruption, aka "Legacy File Format Vulnerability," a different vulnerability than CVE-2009-0223, CVE-2009-0226, CVE-2009-0227, and CVE-2009-1137.
14573| [CVE-2009-0221] Integer overflow in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a PowerPoint file containing a crafted record type for "collaboration information for different slides" that contains a field that specifies a large number of records, which triggers an under-allocated buffer and a heap-based buffer overflow, aka "Integer Overflow Vulnerability."
14574| [CVE-2009-0220] Multiple stack-based buffer overflows in the PowerPoint 4.0 importer (PP4X32.DLL) in Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allow remote attackers to execute arbitrary code via crafted formatting data for paragraphs in a file that uses a PowerPoint 4.0 native file format, related to (1) an incorrect calculation from a record header, or (2) an interget that is used to specify the number of bytes to copy, aka "Legacy File Format Vulnerability."
14575| [CVE-2009-0202] Array index error in FL21WIN.DLL in the PowerPoint Freelance Windows 2.1 Translator in Microsoft PowerPoint 2000 and 2002 allows remote attackers to execute arbitrary code via a Freelance file with unspecified "layout information" that triggers a heap-based buffer overflow.
14576| [CVE-2009-0102] Microsoft Project 2000 SR1 and 2002 SP1, and Office Project 2003 SP3, does not properly handle memory allocation for Project files, which allows remote attackers to execute arbitrary code via a malformed file, aka "Project Memory Validation Vulnerability."
14577| [CVE-2009-0100] Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1
14578| [CVE-2009-0099] The Electronic Messaging System Microsoft Data Base (EMSMDB32) provider in Microsoft Exchange 2000 Server SP3 and Exchange Server 2003 SP2, as used in Exchange System Attendant, allows remote attackers to cause a denial of service (application outage) via a malformed MAPI command, aka "Literal Processing Vulnerability."
14579| [CVE-2009-0098] Microsoft Exchange 2000 Server SP3, Exchange Server 2003 SP2, and Exchange Server 2007 SP1 do not properly interpret Transport Neutral Encapsulation (TNEF) properties, which allows remote attackers to execute arbitrary code via a crafted TNEF message, aka "Memory Corruption Vulnerability."
14580| [CVE-2009-0097] Microsoft Office Visio 2002 SP2 and 2003 SP3 does not properly validate memory allocation for Visio files, which allows remote attackers to execute arbitrary code via a crafted file, aka "Memory Corruption Vulnerability."
14581| [CVE-2009-0096] Microsoft Office Visio 2002 SP2, 2003 SP3, and 2007 SP1 does not properly perform memory copy operations for object data, which allows remote attackers to execute arbitrary code via a crafted Visio document, aka "Memory Corruption Vulnerability."
14582| [CVE-2009-0095] Microsoft Office Visio 2002 SP2, 2003 SP3, and 2007 SP1 does not properly validate object data in Visio files, which allows remote attackers to execute arbitrary code via a crafted file, aka "Memory Validation Vulnerability."
14583| [CVE-2009-0094] The WINS server in Microsoft Windows 2000 SP4 and Server 2003 SP1 and SP2 does not restrict registration of the (1) "wpad" and (2) "isatap" NetBIOS names, which allows remote authenticated users to hijack the Web Proxy Auto-Discovery (WPAD) and Intra-Site Automatic Tunnel Addressing Protocol (ISATAP) features, and conduct man-in-the-middle attacks by spoofing a proxy server or ISATAP route, by registering one of these names in the WINS database, aka "WPAD WINS Server Registration Vulnerability," a related issue to CVE-2007-1692.
14584| [CVE-2009-0093] Windows DNS Server in Microsoft Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008, when dynamic updates are enabled, does not restrict registration of the "wpad" hostname, which allows remote authenticated users to hijack the Web Proxy Auto-Discovery (WPAD) feature, and conduct man-in-the-middle attacks by spoofing a proxy server, via a Dynamic Update request for this hostname, aka "DNS Server Vulnerability in WPAD Registration Vulnerability," a related issue to CVE-2007-1692.
14585| [CVE-2009-0091] Microsoft .NET Framework 2.0, 2.0 SP1, and 3.5 does not properly enforce a certain type-equality constraint in .NET verifiable code, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "Microsoft .NET Framework Type Verification Vulnerability."
14586| [CVE-2009-0090] Microsoft .NET Framework 1.0 SP3, 1.1 SP1, and 2.0 SP1 does not properly validate .NET verifiable code, which allows remote attackers to obtain unintended access to stack memory, and execute arbitrary code, via (1) a crafted XAML browser application (XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "Microsoft .NET Framework Pointer Verification Vulnerability."
14587| [CVE-2009-0089] Windows HTTP Services (aka WinHTTP) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, and Vista Gold allows remote web servers to impersonate arbitrary https web sites by using DNS spoofing to "forward a connection" to a different https web site that has a valid certificate matching its own domain name, but not a certificate matching the domain name of the host requested by the user, aka "Windows HTTP Services Certificate Name Mismatch Vulnerability."
14588| [CVE-2009-0088] The WordPerfect 6.x Converter (WPFT632.CNV, 1998.1.27.0) in Microsoft Office Word 2000 SP3 and Microsoft Office Converter Pack does not properly validate the length of an unspecified string, which allows remote attackers to execute arbitrary code via a crafted WordPerfect 6.x file, related to an unspecified counter and control structures on the stack, aka "Word 2000 WordPerfect 6.x Converter Stack Corruption Vulnerability."
14589| [CVE-2009-0087] Unspecified vulnerability in the Word 6 text converter in WordPad in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2
14590| [CVE-2009-0086] Integer underflow in Windows HTTP Services (aka WinHTTP) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote HTTP servers to execute arbitrary code via crafted parameter values in a response, related to error handling, aka "Windows HTTP Services Integer Underflow Vulnerability."
14591| [CVE-2009-0085] The Secure Channel (aka SChannel) authentication component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008, when certificate authentication is used, does not properly validate the client's key exchange data in Transport Layer Security (TLS) handshake messages, which allows remote attackers to spoof authentication by crafting a TLS packet based on knowledge of the certificate but not the private key, aka "SChannel Spoofing Vulnerability."
14592| [CVE-2009-0083] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 does not properly handle invalid pointers, which allows local users to gain privileges via an application that triggers use of a crafted pointer, aka "Windows Kernel Invalid Pointer Vulnerability."
14593| [CVE-2009-0082] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate handles, which allows local users to gain privileges via a crafted application that triggers unspecified "actions," aka "Windows Kernel Handle Validation Vulnerability."
14594| [CVE-2009-0081] The graphics device interface (GDI) implementation in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate input received from user mode, which allows remote attackers to execute arbitrary code via a crafted (1) Windows Metafile (aka WMF) or (2) Enhanced Metafile (aka EMF) image file, aka "Windows Kernel Input Validation Vulnerability."
14595| [CVE-2009-0079] The RPCSS service in Microsoft Windows XP SP2 and SP3 and Server 2003 SP1 and SP2 does not properly implement isolation among a set of distinct processes that (1) all run under the NetworkService account or (2) all run under the LocalService account, which allows local users to gain privileges by accessing the resources of one of the processes, aka "Windows RPCSS Service Isolation Vulnerability."
14596| [CVE-2009-0078] The Windows Management Instrumentation (WMI) provider in Microsoft Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly implement isolation among a set of distinct processes that (1) all run under the NetworkService account or (2) all run under the LocalService account, which allows local users to gain privileges by accessing the resources of one of the processes, aka "Windows WMI Service Isolation Vulnerability."
14597| [CVE-2008-7217] Microsoft Office 2008 for Mac, when running on Macintosh systems that restrict Office access to administrators, does not enforce this restriction for user ID 502, which allows local users with that ID to bypass intended security policy and access Office programs, related to permissions and ownership for certain directories.
14598| [CVE-2008-6819] win32k.sys in Microsoft Windows Server 2003 and Vista allows local users to cause a denial of service (system crash) via vectors related to CreateWindow, TranslateMessage, and DispatchMessage, possibly a race condition between threads, a different vulnerability than CVE-2008-1084. NOTE: some of these details are obtained from third party information.
14599| [CVE-2008-6219] nsrexecd.exe in multiple EMC Networker products including EMC NetWorker Server, Storage Node, and Client 7.3.x and 7.4, 7.4.1, 7.4.2, Client and Storage Node for Open VMS 7.3.2 ECO6 and earlier, Module for Microsoft Exchange 5.1 and earlier, Module for Microsoft Applications 2.0 and earlier, Module for Meditech 2.0 and earlier, and PowerSnap 2.4 SP1 and earlier does not properly control the allocation of memory, which allows remote attackers to cause a denial of service (memory exhaustion) via multiple crafted RPC requests.
14600| [CVE-2008-6063] Microsoft Word 2007, when the "Save as PDF" add-on is enabled, places an absolute pathname in the Subject field during an "Email as PDF" operation, which allows remote attackers to obtain sensitive information such as the sender's account name and a Temporary Internet Files subdirectory name.
14601| [CVE-2008-5912] An unspecified function in the JavaScript implementation in Microsoft Internet Explorer creates and exposes a "temporary footprint" when there is a current login to a web site, which makes it easier for remote attackers to trick a user into acting upon a spoofed pop-up message, aka an "in-session phishing attack." NOTE: as of 20090116, the only disclosure is a vague pre-advisory with no actionable information. However, because it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.
14602| [CVE-2008-5823] An ActiveX control in prtstb06.dll in Microsoft Money 2006, when used with WScript in Windows Script Host (WSH) on Windows Vista, allows remote attackers to cause a denial of service (access violation and application crash) via a zero value for the Startup property.
14603| [CVE-2008-5416] Heap-based buffer overflow in Microsoft SQL Server 2000 SP4, 8.00.2050, 8.00.2039, and earlier
14604| [CVE-2008-5232] Buffer overflow in the CallHTMLHelp method in the Microsoft Windows Media Services ActiveX control in nskey.dll 4.1.00.3917 in Windows Media Services on Microsoft Windows NT and 2000, and Avaya Media and Message Application servers, allows remote attackers to execute arbitrary code via a long argument. NOTE: the provenance of this information is unknown
14605| [CVE-2008-5112] The LDAP server in Active Directory in Microsoft Windows 2000 SP4 and Server 2003 SP1 and SP2 responds differently to a failed bind attempt depending on whether the user account exists and is permitted to login, which allows remote attackers to enumerate valid usernames via a series of LDAP bind requests, as demonstrated by ldapuserenum.
14606| [CVE-2008-5100] The strong name (SN) implementation in Microsoft .NET Framework 2.0.50727 relies on the digital signature Public Key Token embedded in the pathname of a DLL file instead of the digital signature of this file itself, which makes it easier for attackers to bypass Global Assembly Cache (GAC) and Code Access Security (CAS) protection mechanisms, aka MSRC ticket MSRC8566gs.
14607| [CVE-2008-5044] Race condition in Microsoft Windows Server 2003 and Vista allows local users to cause a denial of service (crash or hang) via a multi-threaded application that makes many calls to UnhookWindowsHookEx while certain other desktop activity is occurring.
14608| [CVE-2008-4844] Use-after-free vulnerability in the CRecordInstance::TransferToDestination function in mshtml.dll in Microsoft Internet Explorer 5.01, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via DSO bindings involving (1) an XML Island, (2) XML DSOs, or (3) Tabular Data Control (TDC) in a crafted HTML or XML document, as demonstrated by nested SPAN or MARQUEE elements, and exploited in the wild in December 2008.
14609| [CVE-2008-4841] The WordPad Text Converter for Word 97 files in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted (1) .doc, (2) .wri, or (3) .rtf Word 97 file that triggers memory corruption, as exploited in the wild in December 2008. NOTE: As of 20081210, it is unclear whether this vulnerability is related to a WordPad issue disclosed on 20080925 with a 2008-crash.doc.rar example, but there are insufficient details to be sure.
14610| [CVE-2008-4837] Stack-based buffer overflow in Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1
14611| [CVE-2008-4835] SMB in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to execute arbitrary code via malformed values of unspecified "fields inside the SMB packets" in an NT Trans2 request, related to "insufficiently validating the buffer size," aka "SMB Validation Remote Code Execution Vulnerability."
14612| [CVE-2008-4834] Buffer overflow in SMB in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via malformed values of unspecified "fields inside the SMB packets" in an NT Trans request, aka "SMB Buffer Overflow Remote Code Execution Vulnerability."
14613| [CVE-2008-4493] Microsoft PicturePusher ActiveX control (PipPPush.DLL 7.00.0709), as used in Microsoft Digital Image 2006 Starter Edition, allows remote attackers to force the upload of arbitrary files by using the AddString and Post methods and a modified PostURL to construct an HTTP POST request. NOTE: this issue might only be exploitable in limited environments or non-default browser settings.
14614| [CVE-2008-4295] Microsoft Windows Mobile 6.0 on HTC Wiza 200 and HTC MDA 8125 devices does not properly handle the first attempt to establish a Bluetooth connection to a peer with a long name, which allows remote attackers to cause a denial of service (device reboot) by configuring a Bluetooth device with a long hci name and (1) connecting directly to the Windows Mobile system or (2) waiting for the Windows Mobile system to scan for nearby devices.
14615| [CVE-2008-4269] The search-ms protocol handler in Windows Explorer in Microsoft Windows Vista Gold and SP1 and Server 2008 uses untrusted parameter data obtained from incorrect parsing, which allows remote attackers to execute arbitrary code via a crafted HTML document, aka "Windows Search Parsing Vulnerability."
14616| [CVE-2008-4268] The Windows Search component in Microsoft Windows Vista Gold and SP1 and Server 2008 does not properly free memory during a save operation for a Windows Search file, which allows remote attackers to execute arbitrary code via a crafted saved-search file, aka "Windows Saved Search Vulnerability."
14617| [CVE-2008-4266] Array index vulnerability in Microsoft Office Excel 2000 SP3, 2002 SP3, and 2003 SP3
14618| [CVE-2008-4265] Microsoft Office Excel 2000 SP3 allows remote attackers to execute arbitrary code via a crafted Excel spreadsheet that contains a malformed object, which triggers memory corruption during the loading of records from this spreadsheet, aka "File Format Parsing Vulnerability."
14619| [CVE-2008-4264] Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1
14620| [CVE-2008-4261] Stack-based buffer overflow in Microsoft Internet Explorer 5.01 SP4, 6 SP1 on Windows 2000, and 6 on Windows XP and Server 2003 does not properly handle extraneous data associated with an object embedded in a web page, which allows remote attackers to execute arbitrary code via crafted HTML tags that trigger memory corruption, aka "HTML Rendering Memory Corruption Vulnerability."
14621| [CVE-2008-4256] The Charts ActiveX control in Microsoft Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2 does not properly handle errors during access to incorrectly initialized objects, which allows remote attackers to execute arbitrary code via a crafted HTML document, related to corruption of the "system state," aka "Charts Control Memory Corruption Vulnerability."
14622| [CVE-2008-4255] Heap-based buffer overflow in mscomct2.ocx (aka Windows Common ActiveX control or Microsoft Animation ActiveX control) in Microsoft Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2, and Office Project 2003 SP3 and 2007 Gold and SP1 allows remote attackers to execute arbitrary code via an AVI file with a crafted stream length, which triggers an "allocation error" and memory corruption, aka "Windows Common AVI Parsing Overflow Vulnerability."
14623| [CVE-2008-4253] The FlexGrid ActiveX control in Microsoft Visual Basic 6.0, Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2, Office FrontPage 2002 SP3, and Office Project 2003 SP3 does not properly handle errors during access to incorrectly initialized objects, which allows remote attackers to execute arbitrary code via a crafted HTML document, related to corruption of the "system state," aka "FlexGrid Control Memory Corruption Vulnerability."
14624| [CVE-2008-4250] The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitrary code via a crafted RPC request that triggers the overflow during path canonicalization, as exploited in the wild by Gimmiv.A in October 2008, aka "Server Service Vulnerability."
14625| [CVE-2008-4114] srv.sys in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to cause a denial of service (system crash) or possibly have unspecified other impact via an SMB WRITE_ANDX packet with an offset that is inconsistent with the packet size, related to "insufficiently validating the buffer size," as demonstrated by a request to the \PIPE\lsarpc named pipe, aka "SMB Validation Denial of Service Vulnerability."
14626| [CVE-2008-4110] Buffer overflow in the SQLVDIRLib.SQLVDirControl ActiveX control in Tools\Binn\sqlvdir.dll in Microsoft SQL Server 2000 (aka SQL Server 8.0) allows remote attackers to cause a denial of service (browser crash) or possibly execute arbitrary code via a long URL in the second argument to the Connect method. NOTE: this issue is not a vulnerability in many environments, since the control is not marked as safe for scripting and would not execute with default Internet Explorer settings.
14627| [CVE-2008-4038] Buffer underflow in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to execute arbitrary code via a Server Message Block (SMB) request that contains a filename with a crafted length, aka "SMB Buffer Underflow Vulnerability."
14628| [CVE-2008-4037] Microsoft Windows 2000 Gold through SP4, XP Gold through SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote SMB servers to execute arbitrary code on a client machine by replaying the NTLM credentials of a client user, as demonstrated by backrush, aka "SMB Credential Reflection Vulnerability." NOTE: some reliable sources report that this vulnerability exists because of an insufficient fix for CVE-2000-0834.
14629| [CVE-2008-4036] Integer overflow in Memory Manager in Microsoft Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows local users to gain privileges via a crafted application that triggers an erroneous decrement of a variable, related to validation of parameters for Virtual Address Descriptors (VADs) and a "memory allocation mapping error," aka "Virtual Address Descriptor Elevation of Privilege Vulnerability."
14630| [CVE-2008-4032] Microsoft Office SharePoint Server 2007 Gold and SP1 and Microsoft Search Server 2008 do not properly perform authentication and authorization for administrative functions, which allows remote attackers to cause a denial of service (server load), obtain sensitive information, and "create scripts that would run in the context of the site" via requests to administrative URIs, aka "Access Control Vulnerability."
14631| [CVE-2008-4031] Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1
14632| [CVE-2008-4030] Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1
14633| [CVE-2008-4028] Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1
14634| [CVE-2008-4027] Double free vulnerability in Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1
14635| [CVE-2008-4026] Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1
14636| [CVE-2008-4025] Integer overflow in Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1
14637| [CVE-2008-4024] Microsoft Office Word 2000 SP3 and 2002 SP3 and Office 2004 for Mac allow remote attackers to execute arbitrary code via a Word document with a crafted lcbPlcfBkfSdt field in the File Information Block (FIB), which bypasses an initialization step and triggers an "arbitrary free," aka "Word Memory Corruption Vulnerability."
14638| [CVE-2008-4023] Active Directory in Microsoft Windows 2000 SP4 does not properly allocate memory for (1) LDAP and (2) LDAPS requests, which allows remote attackers to execute arbitrary code via a crafted request, aka "Active Directory Overflow Vulnerability."
14639| [CVE-2008-4019] Integer overflow in the REPT function in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2 and SP3, and 2007 Gold and SP1
14640| [CVE-2008-3956] orgchart.exe in Microsoft Organization Chart 2.00 allows user-assisted attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted .opx file.
14641| [CVE-2008-3704] Heap-based buffer overflow in the MaskedEdit ActiveX control in Msmask32.ocx 6.0.81.69, and possibly other versions before 6.0.84.18, in Microsoft Visual Studio 6.0, Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2 allows remote attackers to execute arbitrary code via a long Mask parameter, related to not "validating property values with boundary checks," as exploited in the wild in August 2008, aka "Masked Edit Control Memory Corruption Vulnerability."
14642| [CVE-2008-3648] nslookup.exe in Microsoft Windows XP SP2 allows user-assisted remote attackers to execute arbitrary code, as demonstrated by an attempted DNS zone transfer, and as exploited in the wild in August 2008.
14643| [CVE-2008-3636] Integer overflow in the IopfCompleteRequest API in the kernel in Microsoft Windows 2000, XP, Server 2003, and Vista allows context-dependent attackers to gain privileges. NOTE: this issue was originally reported for GEARAspiWDM.sys 2.0.7.5 in Gear Software CD DVD Filter driver before 4.001.7, as used in other products including Apple iTunes and multiple Symantec and Norton products, which allows local users to gain privileges via repeated IoAttachDevice IOCTL calls to \\.\GEARAspiWDMDevice in this GEARAspiWDM.sys. However, the root cause is the integer overflow in the API call itself.
14644| [CVE-2008-3479] Heap-based buffer overflow in the Microsoft Message Queuing (MSMQ) service (mqsvc.exe) in Microsoft Windows 2000 SP4 allows remote attackers to read memory contents and execute arbitrary code via a crafted RPC call, related to improper processing of parameters to string APIs, aka "Message Queuing Service Remote Code Execution Vulnerability."
14645| [CVE-2008-3477] Microsoft Excel 2000 SP3, 2002 SP3, and 2003 SP2 and SP3 does not properly validate data in the VBA Performance Cache when processing an Office document with an embedded object, which allows remote attackers to execute arbitrary code via an Excel file containing a crafted value, leading to heap-based buffer overflows, integer overflows, array index errors, and memory corruption, aka "Calendar Object Validation Vulnerability."
14646| [CVE-2008-3471] Stack-based buffer overflow in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2 and SP3, and 2007 Gold and SP1
14647| [CVE-2008-3466] Microsoft Host Integration Server (HIS) 2000, 2004, and 2006 does not limit RPC access to administrative functions, which allows remote attackers to bypass authentication and execute arbitrary programs via a crafted SNA RPC message using opcode 1 or 6 to call the CreateProcess function, aka "HIS Command Execution Vulnerability."
14648| [CVE-2008-3465] Heap-based buffer overflow in an API in GDI in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows context-dependent attackers to cause a denial of service or execute arbitrary code via a WMF file with a malformed file-size parameter, which would not be properly handled by a third-party application that uses this API for a copy operation, aka "GDI Heap Overflow Vulnerability."
14649| [CVE-2008-3464] afd.sys in the Ancillary Function Driver (AFD) component in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP1 and SP2 does not properly validate input sent from user mode to the kernel, which allows local users to gain privileges via a crafted application, as demonstrated using crafted pointers and lengths that bypass intended ProbeForRead and ProbeForWrite restrictions, aka "AFD Kernel Overwrite Vulnerability."
14650| [CVE-2008-3460] WPGIMP32.FLT in Microsoft Office 2000 SP3, XP SP3, and 2003 SP2
14651| [CVE-2008-3068] Microsoft Crypto API 5.131.2600.2180 through 6.0, as used in Outlook, Windows Live Mail, and Office 2007, performs Certificate Revocation List (CRL) checks by using an arbitrary URL from a certificate embedded in a (1) S/MIME e-mail message or (2) signed document, which allows remote attackers to obtain reading times and IP addresses of recipients, and port-scan results, via a crafted certificate with an Authority Information Access (AIA) extension.
14652| [CVE-2008-3021] Microsoft Office 2000 SP3, XP SP3, and 2003 SP2
14653| [CVE-2008-3020] Microsoft Office 2000 SP3 and XP SP3
14654| [CVE-2008-3019] Microsoft Office 2000 SP3, XP SP3, and 2003 SP2
14655| [CVE-2008-3018] Microsoft Office 2000 SP3, XP SP3, and 2003 SP2
14656| [CVE-2008-3015] Integer overflow in gdiplus.dll in GDI+ in Microsoft Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a BMP image file with a malformed BitMapInfoHeader that triggers a buffer overflow, aka "GDI+ BMP Integer Overflow Vulnerability."
14657| [CVE-2008-3014] Buffer overflow in gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a malformed WMF image file that triggers improper memory allocation, aka "GDI+ WMF Buffer Overrun Vulnerability."
14658| [CVE-2008-3013] gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a malformed GIF image file containing many extension markers for graphic control extensions and subsequent unknown labels, aka "GDI+ GIF Parsing Vulnerability."
14659| [CVE-2008-3012] gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 does not properly perform memory allocation, which allows remote attackers to execute arbitrary code via a malformed EMF image file, aka "GDI+ EMF Memory Corruption Vulnerability."
14660| [CVE-2008-3009] Microsoft Windows Media Player 6.4, Windows Media Format Runtime 7.1 through 11, and Windows Media Services 4.1, 9, and 2008 do not properly use the Service Principal Name (SPN) identifier when validating replies to authentication requests, which allows remote servers to execute arbitrary code via vectors that employ NTLM credential reflection, aka "SPN Vulnerability."
14661| [CVE-2008-3007] Argument injection vulnerability in a URI handler in Microsoft Office XP SP3, 2003 SP2 and SP3, 2007 Office System Gold and SP1, and Office OneNote 2007 Gold and SP1 allow remote attackers to execute arbitrary code via a crafted onenote:// URL, aka "Uniform Resource Locator Validation Error Vulnerability."
14662| [CVE-2008-3006] Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP2 and SP3, and 2007 Gold and SP1
14663| [CVE-2008-3005] Array index vulnerability in Microsoft Office Excel 2000 SP3 and 2002 SP3, and Office 2004 and 2008 for Mac allows remote attackers to execute arbitrary code via an Excel file with a crafted array index for a FORMAT record, aka the "Excel Index Array Vulnerability."
14664| [CVE-2008-3004] Microsoft Office Excel 2000 SP3, 2002 SP3, and 2003 SP2 and SP3
14665| [CVE-2008-3003] Microsoft Office Excel 2007 Gold and SP1 does not properly delete the PWD (password) string from connections.xml when a .xlsx file is configured not to save the remote data session password, which allows local users to obtain sensitive information and obtain access to a remote data source, aka the "Excel Credential Caching Vulnerability."
14666| [CVE-2008-2752] Microsoft Word 2000 9.0.2812 and 2003 11.8106.8172 does not properly handle unordered lists, which allows user-assisted remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted .doc file. NOTE: some of these details are obtained from third party information.
14667| [CVE-2008-2540] Apple Safari on Mac OS X, and before 3.1.2 on Windows, does not prompt the user before downloading an object that has an unrecognized content type, which allows remote attackers to place malware into the (1) Desktop directory on Windows or (2) Downloads directory on Mac OS X, and subsequently allows remote attackers to execute arbitrary code on Windows by leveraging an untrusted search path vulnerability in (a) Internet Explorer 7 on Windows XP or (b) the SearchPath function in Windows XP, Vista, and Server 2003 and 2008, aka a "Carpet Bomb" and a "Blended Threat Elevation of Privilege Vulnerability," a different issue than CVE-2008-1032. NOTE: Apple considers this a vulnerability only because the Microsoft products can load application libraries from the desktop and, as of 20080619, has not covered the issue in an advisory for Mac OS X.
14668| [CVE-2008-2463] The Microsoft Office Snapshot Viewer ActiveX control in snapview.ocx 10.0.5529.0, as distributed in the standalone Snapshot Viewer and Microsoft Office Access 2000 through 2003, allows remote attackers to download arbitrary files to a client machine via a crafted HTML document or e-mail message, probably involving use of the SnapshotPath and CompressedPath properties and the PrintSnapshot method. NOTE: this can be leveraged for code execution by writing to a Startup folder.
14669| [CVE-2008-2252] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate parameters sent from user mode to the kernel, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Memory Corruption Vulnerability."
14670| [CVE-2008-2251] Double free vulnerability in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows local users to gain privileges via a crafted application that makes system calls within multiple threads, aka "Windows Kernel Unhandled Exception Vulnerability." NOTE: according to Microsoft, this is not a duplicate of CVE-2008-4510.
14671| [CVE-2008-2250] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate window properties sent from a parent window to a child window during creation of a new window, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Window Creation Vulnerability."
14672| [CVE-2008-2249] Integer overflow in GDI in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to execute arbitrary code via a malformed header in a crafted WMF file, which triggers a buffer overflow, aka "GDI Integer Overflow Vulnerability."
14673| [CVE-2008-2246] Microsoft Windows Vista through SP1 and Server 2008 do not properly import the default IPsec policy from a Windows Server 2003 domain to a Windows Server 2008 domain, which prevents IPsec rules from being enforced and allows remote attackers to bypass intended access restrictions.
14674| [CVE-2008-2245] Heap-based buffer overflow in the InternalOpenColorProfile function in mscms.dll in Microsoft Windows Image Color Management System (MSCMS) in the Image Color Management (ICM) component on Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted image file.
14675| [CVE-2008-2244] Microsoft Office Word 2002 SP3 allows remote attackers to execute arbitrary code via a .doc file that contains malformed data, as exploited in the wild in July 2008, and as demonstrated by attachement.doc.
14676| [CVE-2008-1898] A certain ActiveX control in WkImgSrv.dll 7.03.0616.0, as distributed in Microsoft Works 7 and Microsoft Office 2003 and 2007, allows remote attackers to execute arbitrary code or cause a denial of service (browser crash) via an invalid WksPictureInterface property value, which triggers an improper function call.
14677| [CVE-2008-1888] Cross-site scripting (XSS) vulnerability in Microsoft Windows SharePoint Services 2.0 allows remote attackers to inject arbitrary web script or HTML via the Picture Source (aka picture object source) field in the Rich Text Editor.
14678| [CVE-2008-1547] Open redirect vulnerability in exchweb/bin/redir.asp in Microsoft Outlook Web Access (OWA) for Exchange Server 2003 SP2 (aka build 6.5.7638) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the URL parameter.
14679| [CVE-2008-1457] The Event System in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate per-user subscriptions, which allows remote authenticated users to execute arbitrary code via a crafted event subscription request.
14680| [CVE-2008-1456] Array index vulnerability in the Event System in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote authenticated users to execute arbitrary code via a crafted event subscription request that is used to access an array of function pointers.
14681| [CVE-2008-1455] A "memory calculation error" in Microsoft Office PowerPoint 2000 SP3, 2002 SP3, 2003 SP2, and 2007 through SP1
14682| [CVE-2008-1454] Unspecified vulnerability in Microsoft DNS in Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008 allows remote attackers to conduct cache poisoning attacks via unknown vectors related to accepting "records from a response that is outside the remote server's authority," aka "DNS Cache Poisoning Vulnerability," a different vulnerability than CVE-2008-1447.
14683| [CVE-2008-1451] The WINS service on Microsoft Windows 2000 SP4, and Server 2003 SP1 and SP2, does not properly validate data structures in WINS network packets, which allows local users to gain privileges via a crafted packet, aka "Memory Overwrite Vulnerability."
14684| [CVE-2008-1446] Integer overflow in the Internet Printing Protocol (IPP) ISAPI extension in Microsoft Internet Information Services (IIS) 5.0 through 7.0 on Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, and Server 2008 allows remote authenticated users to execute arbitrary code via an HTTP POST request that triggers an outbound IPP connection from a web server to a machine operated by the attacker, aka "Integer Overflow in IPP Service Vulnerability."
14685| [CVE-2008-1445] Active Directory on Microsoft Windows 2000 Server SP4, XP Professional SP2 and SP3, Server 2003 SP1 and SP2, and Server 2008 allows remote authenticated users to cause a denial of service (system hang or reboot) via a crafted LDAP request.
14686| [CVE-2008-1444] Stack-based buffer overflow in Microsoft DirectX 7.0 and 8.1 on Windows 2000 SP4 allows remote attackers to execute arbitrary code via a Synchronized Accessible Media Interchange (SAMI) file with crafted parameters for a Class Name variable, aka the "SAMI Format Parsing Vulnerability."
14687| [CVE-2008-1441] Microsoft Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to cause a denial of service (system hang) via a series of Pragmatic General Multicast (PGM) packets with invalid fragment options, aka the "PGM Malformed Fragment Vulnerability."
14688| [CVE-2008-1440] Microsoft Windows XP SP2 and SP3, and Server 2003 SP1 and SP2, does not properly validate the option length field in Pragmatic General Multicast (PGM) packets, which allows remote attackers to cause a denial of service (infinite loop and system hang) via a crafted PGM packet, aka the "PGM Invalid Length Vulnerability."
14689| [CVE-2008-1436] Microsoft Windows XP Professional SP2, Vista, and Server 2003 and 2008 does not properly assign activities to the (1) NetworkService and (2) LocalService accounts, which might allow context-dependent attackers to gain privileges by using one service process to capture a resource from a second service process that has a LocalSystem privilege-escalation ability, related to improper management of the SeImpersonatePrivilege user right, as originally reported for Internet Information Services (IIS), aka Token Kidnapping.
14690| [CVE-2008-1435] Windows Explorer in Microsoft Windows Vista up to SP1, and Server 2008, allows user-assisted remote attackers to execute arbitrary code via crafted saved-search (.search-ms) files that are not properly handled when saving, aka "Windows Saved Search Vulnerability."
14691| [CVE-2008-1434] Use-after-free vulnerability in Microsoft Word in Office 2000 and XP SP3, 2003 SP2 and SP3, and 2007 Office System SP1 and earlier allows remote attackers to execute arbitrary code via an HTML document with a large number of Cascading Style Sheets (CSS) selectors, related to a "memory handling error" that triggers memory corruption.
14692| [CVE-2008-1092] Buffer overflow in msjet40.dll before 4.0.9505.0 in Microsoft Jet Database Engine allows remote attackers to execute arbitrary code via a crafted Word file, as exploited in the wild in March 2008. NOTE: as of 20080513, Microsoft has stated that this is the same issue as CVE-2007-6026.
14693| [CVE-2008-1091] Unspecified vulnerability in Microsoft Word in Office 2000 and XP SP3, 2003 SP2 and SP3, and 2007 Office System SP1 and earlier allows remote attackers to execute arbitrary code via a Rich Text Format (.rtf) file with a malformed string that triggers a "memory calculation error" and a heap-based buffer overflow, aka "Object Parsing Vulnerability."
14694| [CVE-2008-1090] Unspecified vulnerability in Microsoft Visio 2002 SP2, 2003 SP2 and SP3, and 2007 up to SP1 allows user-assisted remote attackers to execute arbitrary code via a crafted .DXF file, aka "Visio Memory Validation Vulnerability."
14695| [CVE-2008-1089] Unspecified vulnerability in Microsoft Visio 2002 SP2, 2003 SP2 and SP3, and 2007 up to SP1 allows user-assisted remote attackers to execute arbitrary code via a Visio file containing crafted object header data, aka "Visio Object Header Vulnerability."
14696| [CVE-2008-1088] Microsoft Project 2000 Service Release 1, 2002 SP1, and 2003 SP2 allows user-assisted remote attackers to execute arbitrary code via a crafted Project file, related to improper validation of "memory resource allocations."
14697| [CVE-2008-1087] Stack-based buffer overflow in GDI in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, and Server 2008 allows remote attackers to execute arbitrary code via an EMF image file with crafted filename parameters, aka "GDI Stack Overflow Vulnerability."
14698| [CVE-2008-1086] The HxTocCtrl ActiveX control (hxvz.dll), as used in Microsoft Internet Explorer 5.01 SP4 and 6 SP1, in Windows XP SP2, Server 2003 SP1 and SP2, Vista SP1, and Server 2008, allows remote attackers to execute arbitrary code via malformed arguments, which triggers memory corruption.
14699| [CVE-2008-1084] Unspecified vulnerability in the kernel in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, through Vista SP1, and Server 2008 allows local users to execute arbitrary code via unknown vectors related to improper input validation. NOTE: it was later reported that one affected function is NtUserFnOUTSTRING in win32k.sys.
14700| [CVE-2008-1083] Heap-based buffer overflow in the CreateDIBPatternBrushPt function in GDI in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, and Server 2008 allows remote attackers to execute arbitrary code via an EMF or WMF image file with a malformed header that triggers an integer overflow, aka "GDI Heap Overflow Vulnerability."
14701| [CVE-2008-0121] A "memory calculation error" in Microsoft PowerPoint Viewer 2003 allows remote attackers to execute arbitrary code via a PowerPoint file with an invalid picture index that triggers memory corruption, aka "Memory Calculation Vulnerability."
14702| [CVE-2008-0120] Integer overflow in Microsoft PowerPoint Viewer 2003 allows remote attackers to execute arbitrary code via a PowerPoint file with a malformed picture index that triggers memory corruption, related to handling of CString objects, aka "Memory Allocation Vulnerability."
14703| [CVE-2008-0119] Unspecified vulnerability in Microsoft Publisher in Office 2000 and XP SP3, 2003 SP2 and SP3, and 2007 SP1 and earlier allows remote attackers to execute arbitrary code via a Publisher file with crafted object header data that triggers memory corruption, aka "Publisher Object Handler Validation Vulnerability."
14704| [CVE-2008-0118] Unspecified vulnerability in Microsoft Office 2000 SP3, XP SP3, 2003 SP2, Excel Viewer 2003 up to SP3, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via a crafted Office document that triggers memory corruption from an "allocation error," aka "Microsoft Office Memory Corruption Vulnerability."
14705| [CVE-2008-0117] Unspecified vulnerability in Microsoft Excel 2000 SP3 and 2002 SP2, and Office 2004 and 2008 for Mac, allows user-assisted remote attackers to execute arbitrary code via crafted conditional formatting values, aka "Excel Conditional Formatting Vulnerability."
14706| [CVE-2008-0116] Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, Compatibility Pack, and Office 2004 and 2008 for Mac allows user-assisted remote attackers to execute arbitrary code via malformed tags in rich text, aka "Excel Rich Text Validation Vulnerability."
14707| [CVE-2008-0115] Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2007, Viewer 2003, Compatibility Pack, and Office for Mac 2004 allows user-assisted remote attackers to execute arbitrary code via malformed formulas, aka "Excel Formula Parsing Vulnerability."
14708| [CVE-2008-0114] Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, and Office for Mac 2004 allows user-assisted remote attackers to execute arbitrary code via crafted Style records that trigger memory corruption.
14709| [CVE-2008-0113] Unspecified vulnerability in Microsoft Office Excel Viewer 2003 up to SP3 allows user-assisted remote attackers to execute arbitrary code via an Excel document with malformed cell comments that trigger memory corruption from an "allocation error," aka "Microsoft Office Cell Parsing Memory Corruption Vulnerability."
14710| [CVE-2008-0112] Unspecified vulnerability in Microsoft Excel 2000 SP3, and Office for Mac 2004 and 2008 allows user-assisted remote attackers to execute arbitrary code via a crafted .SLK file that is not properly handled when importing the file, aka "Excel File Import Vulnerability."
14711| [CVE-2008-0111] Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2007, Viewer 2003, Compatibility Pack, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via crafted data validation records, aka "Excel Data Validation Record Vulnerability."
14712| [CVE-2008-0110] Unspecified vulnerability in Microsoft Outlook in Office 2000 SP3, XP SP3, 2003 SP2 and Sp3, and Office System allows user-assisted remote attackers to execute arbitrary code via a crafted mailto URI.
14713| [CVE-2008-0109] Word in Microsoft Office 2000 SP3, XP SP3, Office 2003 SP2, and Office Word Viewer 2003 allows remote attackers to execute arbitrary code via crafted fields within the File Information Block (FIB) of a Word file, which triggers length calculation errors and memory corruption.
14714| [CVE-2008-0108] Stack-based buffer overflow in wkcvqd01.dll in Microsoft Works 6 File Converter, as used in Office 2003 SP2 and SP3, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted field lengths, aka "Microsoft Works File Converter Field Length Vulnerability."
14715| [CVE-2008-0106] Buffer overflow in Microsoft SQL Server 2005 SP1 and SP2, and 2005 Express Edition SP1 and SP2, allows remote authenticated users to execute arbitrary code via a crafted insert statement.
14716| [CVE-2008-0105] Microsoft Works 6 File Converter, as used in Office 2003 SP2 and SP3, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted section header index table information, aka "Microsoft Works File Converter Index Table Vulnerability."
14717| [CVE-2008-0104] Unspecified vulnerability in Microsoft Office Publisher 2000, 2002, and 2003 SP2 allows remote attackers to execute arbitrary code via a crafted .pub file, aka "Publisher Memory Corruption Vulnerability."
14718| [CVE-2008-0103] Unspecified vulnerability in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP2, and Office 2004 for Mac allows remote attackers to execute arbitrary code via an Office document that contains a malformed object, related to a "memory handling error," aka "Microsoft Office Execution Jump Vulnerability."
14719| [CVE-2008-0102] Unspecified vulnerability in Microsoft Office Publisher 2000, 2002, and 2003 SP2 allows remote attackers to execute arbitrary code via a crafted .pub file, related to invalid "memory values," aka "Publisher Invalid Memory Reference Vulnerability."
14720| [CVE-2008-0088] Unspecified vulnerability in Active Directory on Microsoft Windows 2000 and Windows Server 2003, and Active Directory Application Mode (ADAM) on XP and Server 2003, allows remote attackers to cause a denial of service (hang and restart) via a crafted LDAP request.
14721| [CVE-2008-0087] The DNS client in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, and Vista uses predictable DNS transaction IDs, which allows remote attackers to spoof DNS responses.
14722| [CVE-2008-0086] Buffer overflow in the convert function in Microsoft SQL Server 2000 SP4, 2000 Desktop Engine (MSDE 2000) SP4, and 2000 Desktop Engine (WMSDE) allows remote authenticated users to execute arbitrary code via a crafted SQL expression.
14723| [CVE-2008-0083] The (1) VBScript (VBScript.dll) and (2) JScript (JScript.dll) scripting engines 5.1 and 5.6, as used in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2, do not properly decode script, which allows remote attackers to execute arbitrary code via unknown vectors.
14724| [CVE-2008-0081] Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via crafted macros, aka "Macro Validation Vulnerability," a different vulnerability than CVE-2007-3490.
14725| [CVE-2008-0080] Heap-based buffer overflow in the WebDAV Mini-Redirector in Microsoft Windows XP SP2, Server 2003 SP1 and SP2, and Vista allows remote attackers to execute arbitrary code via a crafted WebDAV response.
14726| [CVE-2008-0020] Unspecified vulnerability in the Load method in the IPersistStreamInit interface in the Active Template Library (ATL), as used in the Microsoft Video ActiveX control in msvidctl.dll in DirectShow, in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via unknown vectors that trigger memory corruption, aka "ATL Header Memcopy Vulnerability," a different vulnerability than CVE-2008-0015.
14727| [CVE-2008-0015] Stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL), as used in the MPEG2TuneRequest ActiveX control in msvidctl.dll in DirectShow, in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a crafted web page, as exploited in the wild in July 2009, aka "Microsoft Video ActiveX Control Vulnerability."
14728| [CVE-2008-0011] Microsoft DirectX 8.1 through 9.0c, and DirectX on Microsoft XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008, does not properly perform MJPEG error checking, which allows remote attackers to execute arbitrary code via a crafted MJPEG stream in a (1) AVI or (2) ASF file, aka the "MJPEG Decoder Vulnerability."
14729| [CVE-2007-6753] Untrusted search path vulnerability in Shell32.dll in Microsoft Windows 2000, Windows XP, Windows Vista, Windows Server 2008, and Windows 7, when using an environment configured with a string such as %APPDATA% or %PROGRAMFILES% in a certain way, allows local users to gain privileges via a Trojan horse DLL under the current working directory, as demonstrated by iTunes and Safari.
14730| [CVE-2007-6357] Stack-based buffer overflow in Microsoft Office Access allows remote, user-assisted attackers to execute arbitrary code via a crafted Microsoft Access Database (.mdb) file. NOTE: due to the lack of details as of 20071210, it is not clear whether this issue is the same as CVE-2007-6026 or CVE-2005-0944.
14731| [CVE-2007-6329] Microsoft Office 2007 12.0.6015.5000 and MSO 12.0.6017.5000 do not sign the metadata of Office Open XML (OOXML) documents, which makes it easier for remote attackers to modify Dublin Core metadata fields, as demonstrated by the (1) LastModifiedBy and (2) creator fields in docProps/core.xml in the OOXML ZIP container.
14732| [CVE-2007-6043] The CryptGenRandom function in Microsoft Windows 2000 generates predictable values, which makes it easier for context-dependent attackers to reduce the effectiveness of cryptographic mechanisms, as demonstrated by attacks on (1) forward security and (2) backward security, related to use of eight instances of the RC4 cipher, and possibly a related issue to CVE-2007-3898.
14733| [CVE-2007-6026] Stack-based buffer overflow in Microsoft msjet40.dll 4.0.8618.0 (aka Microsoft Jet Engine), as used by Access 2003 in Microsoft Office 2003 SP3, allows user-assisted attackers to execute arbitrary code via a crafted MDB file database file containing a column structure with a modified column count. NOTE: this might be the same issue as CVE-2005-0944.
14734| [CVE-2007-5587] Buffer overflow in Macrovision SafeDisc secdrv.sys before 4.3.86.0, as shipped in Microsoft Windows XP SP2, XP Professional x64 and x64 SP2, Server 2003 SP1 and SP2, and Server 2003 x64 and x64 SP2 allows local users to overwrite arbitrary memory locations and gain privileges via a crafted argument to a METHOD_NEITHER IOCTL, as originally discovered in the wild.
14735| [CVE-2007-5352] Unspecified vulnerability in Local Security Authority Subsystem Service (LSASS) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2 allows local users to gain privileges via a crafted local procedure call (LPC) request.
14736| [CVE-2007-5348] Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via an image file with crafted gradient sizes in gradient fill input, which triggers a heap-based buffer overflow related to GdiPlus.dll and VGX.DLL, aka "GDI+ VML Buffer Overrun Vulnerability."
14737| [CVE-2007-4991] The SOCKS4 Proxy in Microsoft Internet Security and Acceleration (ISA) Server 2004 SP1 and SP2 allows remote attackers to obtain potentially sensitive information (the destination IP address of another user's session) via an empty packet.
14738| [CVE-2007-4916] Heap-based buffer overflow in the FileFind::FindFile method in (1) MFC42.dll, (2) MFC42u.dll, (3) MFC71.dll, and (4) MFC71u.dll in Microsoft Foundation Class (MFC) Library 8.0, as used by the ListFiles method in hpqutil.dll 2.0.0.138 in Hewlett-Packard (HP) All-in-One and Photo & Imaging Gallery 1.1 and probably other products, allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long first argument.
14739| [CVE-2007-4814] Buffer overflow in the SQLServer ActiveX control in the Distributed Management Objects OLE DLL (sqldmo.dll) 2000.085.2004.00 in Microsoft SQL Server Enterprise Manager 8.05.2004 allows remote attackers to execute arbitrary code via a long second argument to the Start method.
14740| [CVE-2007-3930] Interpretation conflict between Microsoft Internet Explorer and DocuWiki before 2007-06-26b allows remote attackers to inject arbitrary JavaScript and conduct cross-site scripting (XSS) attacks when spellchecking UTF-8 encoded messages via the spell_utf8test function in lib/exe/spellcheck.php, which triggers HTML document identification and script execution by Internet Explorer even though the Content-Type header is text/plain.
14741| [CVE-2007-3924] Argument injection vulnerability in Microsoft Internet Explorer, when running on systems with Netscape installed and certain URIs registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in a -chrome argument to the navigatorurl URI, which are inserted into the command line that is created when invoking netscape.exe, a related issue to CVE-2007-3670. NOTE: there has been debate about whether the issue is in Internet Explorer or Netscape. As of 20070713, it is CVE's opinion that IE appears to not properly delimit the URL argument when invoking Netscape
14742| [CVE-2007-3899] Unspecified vulnerability in Microsoft Word 2000 SP3, Word 2002 SP3, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via a malformed string in a Word file, aka "Word Memory Corruption Vulnerability."
14743| [CVE-2007-3898] The DNS server in Microsoft Windows 2000 Server SP4, and Server 2003 SP1 and SP2, uses predictable transaction IDs when querying other DNS servers, which allows remote attackers to spoof DNS replies, poison the DNS cache, and facilitate further attack vectors.
14744| [CVE-2007-3896] The URL handling in Shell32.dll in the Windows shell in Microsoft Windows XP and Server 2003, with Internet Explorer 7 installed, allows remote attackers to execute arbitrary programs via invalid "%" sequences in a mailto: or other URI handler, as demonstrated using mIRC, Outlook, Firefox, Adobe Reader, Skype, and other applications. NOTE: this issue might be related to other issues involving URL handlers in Windows systems, such as CVE-2007-3845. There also might be separate but closely related issues in the applications that are invoked by the handlers.
14745| [CVE-2007-3890] Microsoft Excel in Office 2000 SP3, Office XP SP3, Office 2003 SP2, and Office 2004 for Mac allows remote attackers to execute arbitrary code via a Workspace with a certain index value that triggers memory corruption.
14746| [CVE-2007-3670] Argument injection vulnerability in Microsoft Internet Explorer, when running on systems with Firefox installed and certain URIs registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in a (1) FirefoxURL or (2) FirefoxHTML URI, which are inserted into the command line that is created when invoking firefox.exe. NOTE: it has been debated as to whether the issue is in Internet Explorer or Firefox. As of 20070711, it is CVE's opinion that IE appears to be failing to properly delimit the URL argument when invoking Firefox, and this issue could arise with other protocol handlers in IE as well. However, Mozilla has stated that it will address the issue with a "defense in depth" fix that will "prevent IE from sending Firefox malicious data."
14747| [CVE-2007-3490] Unspecified vulnerability in Microsoft Excel 2003 SP2 allows remote attackers to have an unknown impact via unspecified vectors, possibly related to the sheet name, as demonstrated by 2670.xls.
14748| [CVE-2007-3300] Multiple F-Secure anti-virus products for Microsoft Windows and Linux before 20070619 allow remote attackers to bypass scanning via a crafted header in a (1) LHA or (2) RAR archive.
14749| [CVE-2007-3040] Stack-based buffer overflow in agentdpv.dll 2.0.0.3425 in Microsoft Agent on Windows 2000 SP4 allows remote attackers to execute arbitrary code via a crafted URL to the Agent (Agent.Control) ActiveX control, which triggers an overflow within the Agent Service (agentsrv.exe) process, a different issue than CVE-2007-1205.
14750| [CVE-2007-3039] Stack-based buffer overflow in the Microsoft Message Queuing (MSMQ) service in Microsoft Windows 2000 Server SP4, Windows 2000 Professional SP4, and Windows XP SP2 allows attackers to execute arbitrary code via a long string in an opnum 0x06 RPC call to port 2103. NOTE: this is remotely exploitable on Windows 2000 Server.
14751| [CVE-2007-3036] Unspecified vulnerability in the (1) Windows Services for UNIX 3.0 and 3.5, and (2) Subsystem for UNIX-based Applications in Microsoft Windows 2000, XP, Server 2003, and Vista allows local users to gain privileges via unspecified vectors related to "certain setuid binary files."
14752| [CVE-2007-3034] Integer overflow in the AttemptWrite function in Graphics Rendering Engine (GDI) on Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted metafile (image) with a large record length value, which triggers a heap-based buffer overflow.
14753| [CVE-2007-3030] Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, and 2003 Viewer allows user-assisted remote attackers to execute arbitrary code via a malformed Excel file involving the "denoting [of] the start of a Workspace designation", which results in memory corruption, aka the "Workbook Memory Corruption Vulnerability".
14754| [CVE-2007-3029] Unspecified vulnerability in Microsoft Excel 2002 SP3 and 2003 SP2 allows user-assisted remote attackers to execute arbitrary code via a malformed Excel file containing multiple active worksheets, which results in memory corruption.
14755| [CVE-2007-3028] The LDAP service in Windows Active Directory in Microsoft Windows 2000 Server SP4 does not properly check "the number of convertible attributes", which allows remote attackers to cause a denial of service (service unavailability) via a crafted LDAP request, related to "client sent LDAP request logic," aka "Windows Active Directory Denial of Service Vulnerability". NOTE: this is probably a different issue than CVE-2007-0040.
14756| [CVE-2007-2999] Microsoft Windows Server 2003, when time restrictions are in effect for user accounts, generates different error messages for failed login attempts with a valid user name than for those with an invalid user name, which allows context-dependent attackers to determine valid Active Directory account names.
14757| [CVE-2007-2967] Multiple F-Secure anti-virus products for Microsoft Windows and Linux before 20070522 allow remote attackers to cause a denial of service (file scanning infinite loop) via certain crafted (1) ARJ archives or (2) FSG packed files.
14758| [CVE-2007-2966] Buffer overflow in the LHA decompresion component in F-Secure anti-virus products for Microsoft Windows and Linux before 20070529 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted LHA archive, related to an integer wrap, a similar issue to CVE-2006-4335.
14759| [CVE-2007-2903] Buffer overflow in the HelpPopup method in the Microsoft Office 2000 Controllo UA di Microsoft Office ActiveX control (OUACTRL.OCX) 1.0.1.9 allows remote attackers to cause a denial of service (probably winhlp32.exe crash) via a long first argument. NOTE: it is not clear whether this issue crosses privilege boundaries.
14760| [CVE-2007-2593] The Terminal Server in Microsoft Windows 2003 Server, when using TLS, allows remote attackers to bypass SSL and self-signed certificate requirements, downgrade the server security, and possibly conduct man-in-the-middle attacks via unspecified vectors, as demonstrated using the Remote Desktop Protocol (RDP) 6.0 client. NOTE: a third party claims that the vendor may have fixed this in approximately 2006.
14761| [CVE-2007-2581] Multiple cross-site scripting (XSS) vulnerabilities in Microsoft Windows SharePoint Services 3.0 for Windows Server 2003 and Office SharePoint Server 2007 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO (query string) in "every main page," as demonstrated by default.aspx.
14762| [CVE-2007-2374] Unspecified vulnerability in Microsoft Windows 2000, XP, and Server 2003 allows user-assisted remote attackers to execute arbitrary code via unspecified vectors. NOTE: this information is based upon a vague pre-advisory with no actionable information. However, the advisory is from a reliable source.
14763| [CVE-2007-2228] rpcrt4.dll (aka the RPC runtime library) in Microsoft Windows XP SP2, XP Professional x64 Edition, Server 2003 SP1 and SP2, Server 2003 x64 Edition and x64 Edition SP2, and Vista and Vista x64 Edition allows remote attackers to cause a denial of service (RPCSS service stop and system restart) via an RPC request that uses NTLMSSP PACKET authentication with a zero-valued verification trailer signature, which triggers an invalid dereference. NOTE: this also affects Windows 2000 SP4, although the impact is an information leak.
14764| [CVE-2007-2224] Object linking and embedding (OLE) Automation, as used in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Office 2004 for Mac, and Visual Basic 6.0 allows remote attackers to execute arbitrary code via the substringData method on a TextNode object, which causes an integer overflow that leads to a buffer overflow.
14765| [CVE-2007-2221] Unspecified vulnerability in the mdsauth.dll COM object in Microsoft Windows Media Server in the Microsoft Internet Explorer 5.01 SP4 on Windows 2000 SP4
14766| [CVE-2007-2219] Unspecified vulnerability in the Win32 API on Microsoft Windows 2000, XP SP2, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via certain parameters to an unspecified function.
14767| [CVE-2007-2218] Unspecified vulnerability in the Windows Schannel Security Package for Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2, allows remote servers to execute arbitrary code or cause a denial of service via crafted digital signatures that are processed during an SSL handshake.
14768| [CVE-2007-2217] Kodak Image Viewer in Microsoft Windows 2000 SP4, and in some cases XP SP2 and Server 2003 SP1 and SP2, allows remote attackers to execute arbitrary code via crafted image files that trigger memory corruption, as demonstrated by a certain .tif (TIFF) file.
14769| [CVE-2007-1911] Multiple unspecified vulnerabilities in Microsoft Word 2007 allow remote attackers to cause a denial of service (CPU consumption) via crafted documents, as demonstrated by (1) file798-1.doc and (2) file613-1.doc, possibly related to a buffer overflow.
14770| [CVE-2007-1910] Buffer overflow in wwlib.dll in Microsoft Word 2007 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted document, as demonstrated by file789-1.doc.
14771| [CVE-2007-1765] Unspecified vulnerability in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a malformed ANI file, which results in memory corruption when processing cursors, animated cursors, and icons, a similar issue to CVE-2005-0416, as originally demonstrated using Internet Explorer 6 and 7. NOTE: this issue might be a duplicate of CVE-2007-0038
14772| [CVE-2007-1756] Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2003 Viewer, and Office Excel 2007 does not properly validate version information, which allows user-assisted remote attackers to execute arbitrary code via a crafted Excel file, aka "Calculation Error Vulnerability".
14773| [CVE-2007-1754] PUBCONV.DLL in Microsoft Office Publisher 2007 does not properly clear memory when transferring data from disk to memory, which allows user-assisted remote attackers to execute arbitrary code via a malformed .pub page via a certain negative value, which bypasses a sanitization procedure that initializes critical pointers to NULL, aka the "Publisher Invalid Memory Reference Vulnerability".
14774| [CVE-2007-1748] Stack-based buffer overflow in the RPC interface in the Domain Name System (DNS) Server Service in Microsoft Windows 2000 Server SP 4, Server 2003 SP 1, and Server 2003 SP 2 allows remote attackers to execute arbitrary code via a long zone name containing character constants represented by escape sequences.
14775| [CVE-2007-1747] Unspecified vulnerability in MSO.dll in Microsoft Office 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and 2007 allows user-assisted remote attackers to execute arbitrary code via a malformed drawing object, which triggers memory corruption.
14776| [CVE-2007-1645] Buffer overflow in FutureSoft TFTP Server 2000 on Microsoft Windows 2000 SP4 allows remote attackers to execute arbitrary code via a long request on UDP port 69. NOTE: this issue might overlap CVE-2006-4781 or CVE-2005-1812.
14777| [CVE-2007-1537] \Device\NdisTapi (NDISTAPI.sys) in Microsoft Windows XP SP2 and 2003 SP1 uses weak permissions, which allows local users to write to the device and cause a denial of service, as demonstrated by using an IRQL to acquire a spinlock on paged memory via the NdisTapiDispatch function.
14778| [CVE-2007-1512] Stack-based buffer overflow in the AfxOleSetEditMenu function in the MFC component in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 Gold and SP1, and Visual Studio .NET 2002 Gold and SP1, and 2003 Gold and SP1 allows user-assisted remote attackers to have an unknown impact (probably crash) via an RTF file with a malformed OLE object, which results in writing two 0x00 characters past the end of szBuffer, aka the "MFC42u.dll Off-by-Two Overflow." NOTE: this issue is due to an incomplete patch (MS07-012) for CVE-2007-0025.
14779| [CVE-2007-1347] Microsoft Windows Explorer on Windows 2000 SP4 FR and XP SP2 FR, and possibly other versions and platforms, allows remote attackers to cause a denial of service (memory corruption and crash) via an Office file with crafted document summary information, which causes an error in Ole32.dll.
14780| [CVE-2007-1239] Microsoft Excel 2003 does not properly parse .XLS files, which allows remote attackers to cause a denial of service (application crash) via a file with a (1) corrupted XML format or a (2) corrupted XLS format, which triggers a NULL pointer dereference.
14781| [CVE-2007-1238] Microsoft Office 2003 allows user-assisted remote attackers to cause a denial of service (application crash) by attempting to insert a corrupted WMF file.
14782| [CVE-2007-1215] Buffer overflow in the Graphics Device Interface (GDI) in Microsoft Windows 2000 SP4
14783| [CVE-2007-1214] Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2003 Viewer, and 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via a crafted AutoFilter filter record in an Excel BIFF8 format XLS file, which triggers memory corruption.
14784| [CVE-2007-1213] The TrueType Fonts rasterizer in Microsoft Windows 2000 SP4 allows local users to gain privileges via crafted TrueType fonts, which result in an uninitialized function pointer.
14785| [CVE-2007-1212] Buffer overflow in the Graphics Device Interface (GDI) in Microsoft Windows 2000 SP4
14786| [CVE-2007-1211] Unspecified kernel GDI functions in Microsoft Windows 2000 SP4
14787| [CVE-2007-1205] Unspecified vulnerability in Microsoft Agent (msagent\agentsvr.exe) in Windows 2000 SP4, XP SP2, and Server 2003, 2003 SP1, and 2003 SP2 allows remote attackers to execute arbitrary code via crafted URLs, which result in memory corruption.
14788| [CVE-2007-1203] Unspecified vulnerability in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2003 Viewer, 2004 for Mac, and 2007 allows user-assisted remote attackers to execute arbitrary code via a crafted set font value in an Excel file, which results in memory corruption.
14789| [CVE-2007-1202] Word (or Word Viewer) in Microsoft Office 2000 SP3, XP SP3, 2003 SP2, 2004 for Mac, and Works Suite 2004, 2005, and 2006 does not properly parse certain rich text "property strings of certain control words," which allows user-assisted remote attackers to trigger heap corruption and execute arbitrary code, aka the "Word RTF Parsing Vulnerability."
14790| [CVE-2007-1201] Unspecified vulnerability in certain COM objects in Microsoft Office Web Components 2000 allows user-assisted remote attackers to execute arbitrary code via vectors related to DataSource that trigger memory corruption, aka "Office Web Components DataSource Vulnerability."
14791| [CVE-2007-1117] Unspecified vulnerability in Publisher 2007 in Microsoft Office 2007 allows remote attackers to execute arbitrary code via unspecified vectors, related to a "file format vulnerability." NOTE: this information is based upon a vague pre-advisory with no actionable information. However, the advisory is from a reliable source.
14792| [CVE-2007-1090] Microsoft Windows Explorer on Windows XP and 2003 allows remote user-assisted attackers to cause a denial of service (crash) via a malformed WMF file, which triggers the crash when the user browses the folder.
14793| [CVE-2007-1083] Buffer overflow in the Configuration Checker (ConfigChk) ActiveX control in VSCnfChk.dll 2.0.0.2 for Verisign Managed PKI Service, Secure Messaging for Microsoft Exchange, and Go Secure! allows remote attackers to execute arbitrary code via long arguments to the VerCompare method.
14794| [CVE-2007-0948] Heap-based buffer overflow in Microsoft Virtual PC 2004 and PC for Mac 7.1 and 7, and Virtual Server 2005 and 2005 R2, allows local guest OS administrators to execute arbitrary code on the host OS via unspecified vectors related to "interaction and initialization of components."
14795| [CVE-2007-0947] Use-after-free vulnerability in Microsoft Internet Explorer 7 on Windows XP SP2, Windows Server 2003 SP1 or SP2, or Windows Vista allows remote attackers to execute arbitrary code via crafted HTML objects, resulting in accessing deallocated memory of CMarkup objects, aka the second of two "HTML Objects Memory Corruption Vulnerabilities" and a different issue than CVE-2007-0946.
14796| [CVE-2007-0946] Unspecified vulnerability in Microsoft Internet Explorer 7 on Windows XP SP2, Windows Server 2003 SP1 or SP2, or Windows Vista allows remote attackers to execute arbitrary code via crafted HTML objects, which results in memory corruption, aka the first of two "HTML Objects Memory Corruption Vulnerabilities" and a different issue than CVE-2007-0947.
14797| [CVE-2007-0945] Microsoft Internet Explorer 6 SP1 on Windows 2000 SP4
14798| [CVE-2007-0944] Unspecified vulnerability in the CTableCol::OnPropertyChange method in Microsoft Internet Explorer 5.01 SP4 on Windows 2000 SP4
14799| [CVE-2007-0942] Microsoft Internet Explorer 5.01 SP4 on Windows 2000 SP4
14800| [CVE-2007-0940] Unspecified vulnerability in the Cryptographic API Component Object Model Certificates ActiveX control (CAPICOM.dll) in Microsoft CAPICOM and BizTalk Server 2004 SP1 and SP2 allows remote attackers to execute arbitrary code via unspecified vectors, aka the "CAPICOM.Certificates Vulnerability."
14801| [CVE-2007-0939] Cross-site scripting (XSS) vulnerability in Microsoft Content Management Server (MCMS) 2001 SP1 and 2002 SP2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving HTML redirection queries, aka "Cross-site Scripting and Spoofing Vulnerability."
14802| [CVE-2007-0938] Microsoft Content Management Server (MCMS) 2001 SP1 and 2002 SP2 does not properly handle certain characters in a crafted HTTP GET request, which allows remote attackers to execute arbitrary code, aka the "CMS Memory Corruption Vulnerability."
14803| [CVE-2007-0936] Multiple unspecified vulnerabilities in Microsoft Visio 2002 allow remote user-assisted attackers to execute arbitrary code via a Visio (.VSD, VSS, .VST) file with a crafted packed object that triggers memory corruption, aka "Visio Document Packaging Vulnerability."
14804| [CVE-2007-0934] Unspecified vulnerability in Microsoft Visio 2002 allows remote user-assisted attackers to execute arbitrary code via a Visio (.VSD, VSS, .VST) file with a crafted version number that triggers memory corruption.
14805| [CVE-2007-0913] Unspecified vulnerability in Microsoft Powerpoint allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as exploited by Trojan.PPDropper.G. NOTE: as of 20070213, it is not clear whether this is the same issue as CVE-2006-5296, CVE-2006-4694, CVE-2006-3876, CVE-2006-3877, or older issues.
14806| [CVE-2007-0870] Unspecified vulnerability in Microsoft Word 2000 allows remote attackers to cause a denial of service (crash) via unknown vectors, a different vulnerability than CVE-2006-5994, CVE-2006-6456, CVE-2006-6561, and CVE-2007-0515, a variant of Exploit-MS06-027.
14807| [CVE-2007-0843] The ReadDirectoryChangesW API function on Microsoft Windows 2000, XP, Server 2003, and Vista does not check permissions for child objects, which allows local users to bypass permissions by opening a directory with LIST (READ) access and using ReadDirectoryChangesW to monitor changes of files that do not have LIST permissions, which can be leveraged to determine filenames, access times, and other sensitive information.
14808| [CVE-2007-0811] Microsoft Internet Explorer 6.0 SP1 on Windows 2000, and 6.0 SP2 on Windows XP, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an HTML document containing a certain JavaScript for loop with an empty loop body, possibly involving getElementById.
14809| [CVE-2007-0671] Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as demonstrated by Exploit-MSExcel.h in targeted zero-day attacks.
14810| [CVE-2007-0612] Multiple ActiveX controls in Microsoft Windows 2000, XP, 2003, and Vista allows remote attackers to cause a denial of service (Internet Explorer crash) by accessing the bgColor, fgColor, linkColor, alinkColor, vlinkColor, or defaultCharset properties in the (1) giffile, (2) htmlfile, (3) jpegfile, (4) mhtmlfile, (5) ODCfile, (6) pjpegfile, (7) pngfile, (8) xbmfile, (9) xmlfile, (10) xslfile, or (11) wdfile objects in (a) mshtml.dll
14811| [CVE-2007-0515] Unspecified vulnerability in Microsoft Word allows user-assisted remote attackers to execute arbitrary code on Word 2000, and cause a denial of service on Word 2003, via unknown attack vectors that trigger memory corruption, as exploited by Trojan.Mdropper.W and later by Trojan.Mdropper.X, a different issue than CVE-2006-6456, CVE-2006-5994, and CVE-2006-6561.
14812| [CVE-2007-0351] Microsoft Windows XP and Windows Server 2003 do not properly handle user logoff, which might allow local users to gain the privileges of a previous system user, possibly related to user profile unload failure. NOTE: it is not clear whether this is an issue in Windows itself, or an interaction with another product. The issue might involve ZoneAlarm not being able to terminate processes when it cannot prompt the user.
14813| [CVE-2007-0221] Integer overflow in the IMAP (IMAP4) support in Microsoft Exchange Server 2000 SP3 allows remote attackers to cause a denial of service (service hang) via crafted literals in an IMAP command, aka the "IMAP Literal Processing Vulnerability."
14814| [CVE-2007-0220] Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2000 SP3, and 2003 SP1 and SP2 allows remote attackers to execute arbitrary scripts, spoof content, or obtain sensitive information via certain UTF-encoded, script-based e-mail attachments, involving an "incorrectly handled UTF character set label".
14815| [CVE-2007-0216] wkcvqd01.dll in Microsoft Works 6 File Converter, as used in Office 2003 SP2, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted section length headers, aka "Microsoft Works File Converter Input Validation Vulnerability."
14816| [CVE-2007-0215] Stack-based buffer overflow in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, and 2003 Viewer allows user-assisted remote attackers to execute arbitrary code via a .XLS BIFF file with a malformed Named Graph record, which results in memory corruption.
14817| [CVE-2007-0214] The HTML Help ActiveX control (Hhctrl.ocx) in Microsoft Windows 2000 SP3, XP SP2 and Professional, 2003 SP1 allows remote attackers to execute arbitrary code via unspecified functions, related to uninitialized parameters.
14818| [CVE-2007-0213] Microsoft Exchange Server 2000 SP3, 2003 SP1 and SP2, and 2007 does not properly decode certain MIME encoded e-mails, which allows remote attackers to execute arbitrary code via a crafted base64-encoded MIME e-mail message.
14819| [CVE-2007-0211] The hardware detection functionality in the Windows Shell in Microsoft Windows XP SP2 and Professional, and Server 2003 SP1 allows local users to gain privileges via an unvalidated parameter to a function related to the "detection and registration of new hardware."
14820| [CVE-2007-0209] Microsoft Word in Office 2000 SP3, XP SP3, Office 2003 SP2, Works Suite 2004 to 2006, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via a Word file with a malformed drawing object, which leads to memory corruption.
14821| [CVE-2007-0208] Microsoft Word in Office 2000 SP3, XP SP3, Office 2003 SP2, Works Suite 2004 to 2006, and Office 2004 for Mac does not correctly check the properties of certain documents and warn the user of macro content, which allows user-assisted remote attackers to execute arbitrary code.
14822| [CVE-2007-0069] Unspecified vulnerability in the kernel in Microsoft Windows XP SP2, Server 2003, and Vista allows remote attackers to cause a denial of service (CPU consumption) and possibly execute arbitrary code via crafted (1) IGMPv3 and (2) MLDv2 packets that trigger memory corruption, aka "Windows Kernel TCP/IP/IGMPv3 and MLDv2 Vulnerability."
14823| [CVE-2007-0066] The kernel in Microsoft Windows 2000 SP4, XP SP2, and Server 2003, when ICMP Router Discovery Protocol (RDP) is enabled, allows remote attackers to cause a denial of service via fragmented router advertisement ICMP packets that trigger an out-of-bounds read, aka "Windows Kernel TCP/IP/ICMP Vulnerability."
14824| [CVE-2007-0065] Heap-based buffer overflow in Object Linking and Embedding (OLE) Automation in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, Office 2004 for Mac, and Visual basic 6.0 SP6 allows remote attackers to execute arbitrary code via a crafted script request.
14825| [CVE-2007-0064] Heap-based buffer overflow in Windows Media Format Runtime 7.1, 9, 9.5, 9.5 x64 Edition, 11, and Windows Media Services 9.1 for Microsoft Windows 2000, XP, Server 2003, and Vista allows user-assisted remote attackers to execute arbitrary code via a crafted Advanced Systems Format (ASF) file.
14826| [CVE-2007-0043] The Just In Time (JIT) Compiler service in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows user-assisted remote attackers to execute arbitrary code via unspecified vectors involving an "unchecked buffer," probably a buffer overflow, aka ".NET JIT Compiler Vulnerability".
14827| [CVE-2007-0042] Interpretation conflict in ASP.NET in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows remote attackers to access configuration files and obtain sensitive information, and possibly bypass security mechanisms that try to constrain the final substring of a string, via %00 characters, related to use of %00 as a string terminator within POSIX functions but a data character within .NET strings, aka "Null Byte Termination Vulnerability."
14828| [CVE-2007-0041] The PE Loader service in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows remote attackers to execute arbitrary code via unspecified vectors involving an "unchecked buffer" and unvalidated message lengths, probably a buffer overflow.
14829| [CVE-2007-0040] The LDAP service in Windows Active Directory in Microsoft Windows 2000 Server SP4, Server 2003 SP1 and SP2, Server 2003 x64 Edition and SP2, and Server 2003 for Itanium-based Systems SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted LDAP request with an unspecified number of "convertible attributes."
14830| [CVE-2007-0039] The Exchange Collaboration Data Objects (EXCDO) functionality in Microsoft Exchange Server 2000 SP3, 2003 SP1 and SP2, and 2007 allows remote attackers to cause a denial of service (crash) via an Internet Calendar (iCal) file containing multiple X-MICROSOFT-CDO-MODPROPS (MODPROPS) properties in which the second MODPROPS is longer than the first, which triggers a NULL pointer dereference and an unhandled exception.
14831| [CVE-2007-0038] Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a large length value in the second (or later) anih block of a RIFF .ANI, cur, or .ico file, which results in memory corruption when processing cursors, animated cursors, and icons, a variant of CVE-2005-0416, as originally demonstrated using Internet Explorer 6 and 7. NOTE: this might be a duplicate of CVE-2007-1765
14832| [CVE-2007-0035] Word (or Word Viewer) in Microsoft Office 2000 SP3, XP SP3, 2003 SP2, 2004 for Mac, and Works Suite 2004, 2005, and 2006 does not properly handle data in a certain array, which allows user-assisted remote attackers to execute arbitrary code, aka the "Word Array Overflow Vulnerability."
14833| [CVE-2007-0034] Buffer overflow in the Advanced Search (Finder.exe) feature of Microsoft Outlook 2000, 2002, and 2003 allows user-assisted remote attackers to execute arbitrary code via a crafted Outlook Saved Searches (OSS) file that triggers memory corruption, aka "Microsoft Outlook Advanced Find Vulnerability."
14834| [CVE-2007-0033] Microsoft Outlook 2002 and 2003 allows user-assisted remote attackers to execute arbitrary code via a malformed VEVENT record in an .iCal meeting request or ICS file.
14835| [CVE-2007-0031] Heap-based buffer overflow in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows user-assisted remote attackers to execute arbitrary code via a BIFF8 spreadsheet with a PALETTE record that contains a large number of entries.
14836| [CVE-2007-0030] Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows user-assisted remote attackers to execute arbitrary code via an Excel file with an out-of-range Column field in certain BIFF8 record types, which references arbitrary memory.
14837| [CVE-2007-0029] Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows user-assisted remote attackers to execute arbitrary code via a malformed string, aka "Excel Malformed String Vulnerability."
14838| [CVE-2007-0028] Microsoft Excel 2000, 2002, 2003, Viewer 2003, Office 2004 for Mac, and Office v.X for Mac does not properly handle certain opcodes, which allows user-assisted remote attackers to execute arbitrary code via a crafted XLS file, which results in an "Improper Memory Access Vulnerability." NOTE: an early disclosure of this issue used CVE-2006-3432, but only CVE-2007-0028 should be used.
14839| [CVE-2007-0027] Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows remote attackers to execute arbitrary code via malformed IMDATA records that trigger memory corruption.
14840| [CVE-2007-0026] The OLE Dialog component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1 allows user-assisted remote attackers to execute arbitrary code via an RTF file with a malformed OLE object that triggers memory corruption.
14841| [CVE-2007-0025] The MFC component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1 and Visual Studio .NET 2000, 2002 SP1, 2003, and 2003 SP1 allows user-assisted remote attackers to execute arbitrary code via an RTF file with a malformed OLE object that triggers memory corruption. NOTE: this might be due to a stack-based buffer overflow in the AfxOleSetEditMenu function in MFC42u.dll.
14842| [CVE-2007-0024] Integer overflow in the Vector Markup Language (VML) implementation (vgx.dll) in Microsoft Internet Explorer 5.01, 6, and 7 on Windows 2000 SP4, XP SP2, Server 2003, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted web page that contains unspecified integer properties that cause insufficient memory allocation and trigger a buffer overflow, aka the "VML Buffer Overrun Vulnerability."
14843| [CVE-2006-7210] Microsoft Windows 2000, XP, and Server 2003 allows remote attackers to cause a denial of service (cpu consumption) via a PNG image with crafted (1) Width and (2) Height values in the IHDR block.
14844| [CVE-2006-7192] Microsoft ASP .NET Framework 2.0.50727.42 does not properly handle comment (/* */) enclosures, which allows remote attackers to bypass request filtering and conduct cross-site scripting (XSS) attacks, or cause a denial of service, as demonstrated via an xss:expression STYLE attribute in a closing XSS HTML tag.
14845| [CVE-2006-7027] Microsoft Internet Security and Acceleration (ISA) Server 2004 logs unusual ASCII characters in the Host header, including the tab, which allows remote attackers to manipulate portions of the log file and possibly leverage this for other attacks.
14846| [CVE-2006-6723] The Workstation service in Microsoft Windows 2000 SP4 and XP SP2 allows remote attackers to cause a denial of service (memory consumption) via a large maxlen value in an NetrWkstaUserEnum RPC request.
14847| [CVE-2006-6696] Double free vulnerability in Microsoft Windows 2000, XP, 2003, and Vista allows local users to gain privileges by calling the MessageBox function with a MB_SERVICE_NOTIFICATION message with crafted data, which sends a HardError message to Client/Server Runtime Server Subsystem (CSRSS) process, which is not properly handled when invoking the UserHardError and GetHardErrorText functions in WINSRV.DLL.
14848| [CVE-2006-6617] projectserver/logon/pdsrequest.asp in Microsoft Project Server 2003 allows remote authenticated users to obtain the MSProjectUser password for a SQL database via a GetInitializationData request, which includes the information in the UserName and Password tags of the response.
14849| [CVE-2006-6561] Unspecified vulnerability in Microsoft Word 2000, 2002, and Word Viewer 2003 allows user-assisted remote attackers to execute arbitrary code via a crafted DOC file that triggers memory corruption, as demonstrated via the 12122006-djtest.doc file, a different issue than CVE-2006-5994 and CVE-2006-6456.
14850| [CVE-2006-6456] Unspecified vulnerability in Microsoft Word 2000, 2002, and 2003 and Word Viewer 2003 allows remote attackers to execute code via unspecified vectors related to malformed data structures that trigger memory corruption, a different vulnerability than CVE-2006-5994.
14851| [CVE-2006-6296] The RpcGetPrinterData function in the Print Spooler (spoolsv.exe) service in Microsoft Windows 2000 SP4 and earlier, and possibly Windows XP SP1 and earlier, allows remote attackers to cause a denial of service (memory consumption) via an RPC request that specifies a large 'offered' value (output buffer size), a variant of CVE-2005-3644.
14852| [CVE-2006-6134] Heap-based buffer overflow in the WMCheckURLScheme function in WMVCORE.DLL in Microsoft Windows Media Player (WMP) 10.00.00.4036 on Windows XP SP2, Server 2003, and Server 2003 SP1 allows remote attackers to cause a denial of service (application crash) and execute arbitrary code via a long HREF attribute, using an unrecognized protocol, in a REF element in an ASX PlayList file.
14853| [CVE-2006-6133] Stack-based buffer overflow in Visual Studio Crystal Reports for Microsoft Visual Studio .NET 2002 and 2002 SP1, .NET 2003 and 2003 SP1, and 2005 and 2005 SP1 (formerly Business Objects Crystal Reports XI Professional) allows user-assisted remote attackers to execute arbitrary code via a crafted RPT file.
14854| [CVE-2006-5994] Unspecified vulnerability in Microsoft Word 2000 and 2002, Office Word and Word Viewer 2003, Word 2004 and 2004 v. X for Mac, and Works 2004, 2005, and 2006 allows remote attackers to execute arbitrary code via a Word document with a malformed string that triggers memory corruption, a different vulnerability than CVE-2006-6456.
14855| [CVE-2006-5758] The Graphics Rendering Engine in Microsoft Windows 2000 through 2000 SP4 and Windows XP through SP2 maps GDI Kernel structures on a global shared memory section that is mapped with read-only permissions, but can be remapped by other processes as read-write, which allows local users to cause a denial of service (memory corruption and crash) and gain privileges by modifying the kernel structures.
14856| [CVE-2006-5586] The Graphics Rendering Engine in Microsoft Windows 2000 SP4 and XP SP2 allows local users to gain privileges via "invalid application window sizes" in layered application windows, aka the "GDI Invalid Window Size Elevation of Privilege Vulnerability."
14857| [CVE-2006-5585] The Client-Server Run-time Subsystem in Microsoft Windows XP SP2 and Server 2003 allows local users to gain privileges via a crafted file manifest within an application, aka "File Manifest Corruption Vulnerability."
14858| [CVE-2006-5584] The Remote Installation Service (RIS) in Microsoft Windows 2000 SP4 uses a TFTP server that allows anonymous access, which allows remote attackers to upload and overwrite arbitrary files to gain privileges on systems that use RIS.
14859| [CVE-2006-5583] Buffer overflow in the SNMP Service in Microsoft Windows 2000 SP4, XP SP2, Server 2003, Server 2003 SP1, and possibly other versions allows remote attackers to execute arbitrary code via a crafted SNMP packet, aka "SNMP Memory Corruption Vulnerability."
14860| [CVE-2006-5574] Unspecified vulnerability in the Brazilian Portuguese Grammar Checker in Microsoft Office 2003 and the Multilingual Interface for Office 2003, Project 2003, and Visio 2003 allows user-assisted remote attackers to execute arbitrary code via crafted text that is not properly parsed.
14861| [CVE-2006-5296] PowerPoint in Microsoft Office 2003 does not properly handle a container object whose position value exceeds the record length, which allows user-assisted attackers to cause a denial of service (NULL dereference and application crash) via a crafted PowerPoint (.PPT) file, as demonstrated by Nanika.ppt, and a different vulnerability than CVE-2006-3435, CVE-2006-3876, CVE-2006-3877, and CVE-2006-4694. NOTE: the impact of this issue was originally claimed to be arbitrary code execution, but later analysis demonstrated that this was erroneous.
14862| [CVE-2006-4854] ** REJECT ** Unspecified vulnerability in Microsoft Office 2000 (Chinese Edition) and Microsoft PowerPoint 2000 (Chinese Edition) allows user-assisted attackers to execute arbitrary code via a crafted PPT document, as exploited by malware such as Trojan.PPDropper.E. NOTE: on 20060919, Microsoft notified CVE that this is a duplicate of CVE-2006-0009.
14863| [CVE-2006-4704] Cross-zone scripting vulnerability in the WMI Object Broker (WMIScriptUtils.WMIObjectBroker2) ActiveX control (WmiScriptUtils.dll) in Microsoft Visual Studio 2005 allows remote attackers to bypass Internet zone restrictions and execute arbitrary code by instantiating dangerous objects, aka "WMI Object Broker Vulnerability."
14864| [CVE-2006-4702] Buffer overflow in the Windows Media Format Runtime in Microsoft Windows Media Player (WMP) 6.4 and Windows XP SP2, Server 2003, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted Advanced Systems Format (ASF) file.
14865| [CVE-2006-4696] Unspecified vulnerability in the Server service in Microsoft Windows 2000 SP4, Server 2003 SP1 and earlier, and XP SP2 and earlier allows remote attackers to execute arbitrary code via a crafted packet, aka "SMB Rename Vulnerability."
14866| [CVE-2006-4695] Unspecified vulnerability in certain COM objects in Microsoft Office Web Components 2000 allows user-assisted remote attackers to execute arbitrary code via a crafted URL, aka "Office Web Components URL Parsing Vulnerability."
14867| [CVE-2006-4694] Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office XP and Office 2003 allows user-assisted attackers to execute arbitrary code via a crafted record in a PPT file, as exploited by malware such as Exploit:Win32/Controlppt.W, Exploit:Win32/Controlppt.X, and Exploit-PPT.d/Trojan.PPDropper.F. NOTE: it has been reported that the attack vector involves SlideShowWindows.View.GotoNamedShow.
14868| [CVE-2006-4693] Unspecified vulnerability in Microsoft Word 2004 for Mac and v.X for Mac allows remote user-assisted attackers to execute arbitrary code via a crafted string in a Word file, a different issue than CVE-2006-3647 and CVE-2006-3651.
14869| [CVE-2006-4692] Argument injection vulnerability in the Windows Object Packager (packager.exe) in Microsoft Windows XP SP1 and SP2 and Server 2003 SP1 and earlier allows remote user-assisted attackers to execute arbitrary commands via a crafted file with a "/" (slash) character in the filename of the Command Line property, followed by a valid file extension, which causes the command before the slash to be executed, aka "Object Packager Dialogue Spoofing Vulnerability."
14870| [CVE-2006-4691] Stack-based buffer overflow in the NetpManageIPCConnect function in the Workstation service (wkssvc.dll) in Microsoft Windows 2000 SP4 and XP SP2 allows remote attackers to execute arbitrary code via NetrJoinDomain2 RPC messages with a long hostname.
14871| [CVE-2006-4689] Unspecified vulnerability in the driver for the Client Service for NetWare (CSNW) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 allows remote attackers to cause a denial of service (hang and reboot) via has unknown attack vectors, aka "NetWare Driver Denial of Service Vulnerability."
14872| [CVE-2006-4688] Buffer overflow in Client Service for NetWare (CSNW) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 allows remote attackers to execute arbitrary code via crafted messages, aka "Client Service for NetWare Memory Corruption Vulnerability."
14873| [CVE-2006-4534] Unspecified vulnerability in Microsoft Word 2000, 2002, and Office 2003 allows remote user-assisted attackers to execute arbitrary code via unspecified vectors involving a crafted file resulting in a malformed stack, as exploited by malware with names including Trojan.Mdropper.Q, Mofei, and Femo.
14874| [CVE-2006-4495] Microsoft Internet Explorer allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code by instantiating certain Windows 2000 ActiveX COM Objects including (1) ciodm.dll, (2) myinfo.dll, (3) msdxm.ocx, and (4) creator.dll.
14875| [CVE-2006-4274] ** REJECT ** Unknown vulnerability in Microsoft PowerPoint allows user-assisted attackers to execute arbitrary code via a crafted PPT document, as exploited by malware such as TROJ_MDROPPER.BH. NOTE: on 20060822, it was determined that TROJ_MDROPPER.BH was exploiting CVE-2006-0009, so this is not a new vulnerability.
14876| [CVE-2006-4219] The Terminal Services COM object (tsuserex.dll) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by instantiating it as an ActiveX object in Internet Explorer 6.0 SP1 on Microsoft Windows 2003 EE SP1 CN.
14877| [CVE-2006-4183] Heap-based buffer overflow in Microsoft DirectX SDK (February 2006) and probably earlier, including 9.0c End User Runtimes, allows context-dependent attackers to execute arbitrary code via a crafted Targa file with a run-length-encoding (RLE) compression that produces more data than expected when decoding.
14878| [CVE-2006-4071] Sign extension vulnerability in the createBrushIndirect function in the GDI library (gdi32.dll) in Microsoft Windows XP, Server 2003, and possibly other versions, allows user-assisted attackers to cause a denial of service (application crash) via a crafted WMF file.
14879| [CVE-2006-3992] Unspecified vulnerability in the Centrino (1) w22n50.sys, (2) w22n51.sys, (3) w29n50.sys, and (4) w29n51.sys Microsoft Windows drivers for Intel 2200BG and 2915ABG PRO/Wireless Network Connection before 10.5 with driver 9.0.4.16 allows remote attackers to execute arbitrary code via certain frames that trigger memory corruption.
14880| [CVE-2006-3942] The server driver (srv.sys) in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause a denial of service (system crash) via an SMB_COM_TRANSACTION SMB message that contains a string without null character termination, which leads to a NULL dereference in the ExecuteTransaction function, possibly related to an "SMB PIPE," aka the "Mailslot DOS" vulnerability. NOTE: the name "Mailslot DOS" was derived from incomplete initial research
14881| [CVE-2006-3897] Stack overflow in Microsoft Internet Explorer 6 on Windows 2000 allows remote attackers to cause a denial of service (application crash) by creating an NMSA.ASFSourceMediaDescription.1 ActiveX object with a long dispValue property.
14882| [CVE-2006-3880] ** DISPUTED ** Microsoft Windows NT 4.0, Windows 2000, Windows XP, and Windows Small Business Server 2003 allow remote attackers to cause a denial of service (IP stack hang) via a continuous stream of packets on TCP port 135 that have incorrect TCP header checksums and random numbers in certain TCP header fields, as demonstrated by the Achilles Windows Attack Tool. NOTE: the researcher reports that the Microsoft Security Response Center has stated "Our investigation which has included code review, review of the TCPDump, and attempts on reproing the issue on multiple fresh installs of various Windows Operating Systems have all resulted in non confirmation."
14883| [CVE-2006-3877] Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office 2002, Office 2003, Office 2004 for Mac, and Office v.X for Mac allows user-assisted attackers to execute arbitrary code via an unspecified "crafted file," a different vulnerability than CVE-2006-3435, CVE-2006-4694, and CVE-2006-3876.
14884| [CVE-2006-3876] Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office 2002, Office 2003, Office 2004 for Mac, and Office v.X for Mac allows user-assisted attackers to execute arbitrary code via a crafted Data record in a PPT file, a different vulnerability than CVE-2006-3435 and CVE-2006-4694.
14885| [CVE-2006-3875] Unspecified vulnerability in Microsoft Excel 2000, 2002, 2003, 2004 for Mac, v.X for Mac, and Excel Viewer 2003 allows user-assisted attackers to execute arbitrary code via a crafted COLINFO record in an XLS file, a different vulnerability than CVE-2006-2387 and CVE-2006-3867.
14886| [CVE-2006-3873] Heap-based buffer overflow in URLMON.DLL in Microsoft Internet Explorer 6 SP1 on Windows 2000 and XP SP1, with versions the MS06-042 patch before 20060912, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long URL in a GZIP-encoded website that was the target of an HTTP redirect, due to an incomplete fix for CVE-2006-3869.
14887| [CVE-2006-3869] Heap-based buffer overflow in URLMON.DLL in Microsoft Internet Explorer 6 SP1 on Windows 2000 and XP SP1, with versions the MS06-042 patch before 20060824, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long URL on a website that uses HTTP 1.1 compression.
14888| [CVE-2006-3868] Unspecified vulnerability in Microsoft Office XP and 2003 allows remote user-assisted attackers to execute arbitrary code via a malformed Smart Tag.
14889| [CVE-2006-3867] Unspecified vulnerability in Microsoft Excel 2000, 2002, 2003, 2004 for Mac, v.X for Mac, and Excel Viewer 2003 allows user-assisted attackers to execute arbitrary code via a crafted Lotus 1-2-3 file, a different vulnerability than CVE-2006-2387 and CVE-2006-3875.
14890| [CVE-2006-3864] Unspecified vulnerability in mso.dll in Microsoft Office 2000, XP, and 2003, and Microsoft PowerPoint 2000, XP, and 2003, allows remote user-assisted attackers to execute arbitrary code via a malformed record in a (1) .DOC, (2) .PPT, or (3) .XLS file that triggers memory corruption, related to an "array boundary condition" (possibly an array index overflow), a different vulnerability than CVE-2006-3434, CVE-2006-3650, and CVE-2006-3868.
14891| [CVE-2006-3841] Cross-site scripting (XSS) vulnerability in WebScarab before 20060718-1904, when used with Microsoft Internet Explorer 6 SP2 or Konqueror 3.5.3, allows remote attackers to inject arbitrary web script or HTML via the URL, which is not sanitized before being returned in an error message when WebScarab is not able to access the URL.
14892| [CVE-2006-3660] Unspecified vulnerability in Microsoft PowerPoint 2003 has unknown impact and user-assisted attack vectors related to powerpnt.exe. NOTE: due to the lack of available details as of 20060717, it is unclear how this is related to CVE-2006-3655, CVE-2006-3656, and CVE-2006-3590, although it is possible that they are all different.
14893| [CVE-2006-3656] Unspecified vulnerability in Microsoft PowerPoint 2003 allows user-assisted attackers to cause memory corruption via a crafted PowerPoint file, which triggers the corruption when the file is closed. NOTE: due to the lack of available details as of 20060717, it is unclear how this is related to CVE-2006-3655, CVE-2006-3660, and CVE-2006-3590, although it is possible that they are all different.
14894| [CVE-2006-3655] Unspecified vulnerability in mso.dll in Microsoft PowerPoint 2003 allows user-assisted attackers to execute arbitrary code via a crafted PowerPoint file. NOTE: due to the lack of available details as of 20060717, it is unclear how this is related to CVE-2006-3656, CVE-2006-3660, and CVE-2006-3590, although it is possible that they are all different.
14895| [CVE-2006-3652] Microsoft Internet Security and Acceleration (ISA) Server 2004 allows remote attackers to bypass file extension filters via a request with a trailing "#" character. NOTE: as of 20060715, this could not be reproduced by third parties.
14896| [CVE-2006-3651] Unspecified vulnerability in Microsoft Word 2000, 2002, and Office 2003 allows remote user-assisted attackers to execute arbitrary code via a crafted mail merge file, a different vulnerability than CVE-2006-3647 and CVE-2006-4693.
14897| [CVE-2006-3650] Microsoft Office 2000, XP, 2003, 2004 for Mac, and v.X for Mac do not properly parse the length of a chart record, which allows remote user-assisted attackers to execute arbitrary code via a Word document with an embedded malformed chart record that triggers an overwrite of pointer values with values from the document, a different vulnerability than CVE-2006-3434, CVE-2006-3864, and CVE-2006-3868.
14898| [CVE-2006-3649] Buffer overflow in Microsoft Visual Basic for Applications (VBA) SDK 6.0 through 6.4, as used by Microsoft Office 2000 SP3, Office XP SP3, Project 2000 SR1, Project 2002 SP1, Access 2000 Runtime SP3, Visio 2002 SP2, and Works Suite 2004 through 2006, allows user-assisted attackers to execute arbitrary code via unspecified document properties that are not verified when VBA is invoked to open documents.
14899| [CVE-2006-3648] Unspecified vulnerability in Microsoft Windows 2000 SP4, XP SP1 and SP2, Server 2003 and 2003 SP1, allows remote attackers to execute arbitrary code via unspecified vectors involving unhandled exceptions, memory resident applications, and incorrectly "unloading chained exception."
14900| [CVE-2006-3647] Integer overflow in Microsoft Word 2000, 2002, 2003, 2004 for Mac, and v.X for Mac allows remote user-assisted attackers to execute arbitrary code via a crafted string in a Word document, which overflows a 16-bit integer length value, aka "Memmove Code Execution," a different vulnerability than CVE-2006-3651 and CVE-2006-4693.
14901| [CVE-2006-3643] Cross-site scripting (XSS) vulnerability in Internet Explorer 5.01 and 6 in Microsoft Windows 2000 SP4 permits access to local "HTML-embedded resource files" in the Microsoft Management Console (MMC) library, which allows remote authenticated users to execute arbitrary commands, aka "MMC Redirect Cross-Site Scripting Vulnerability."
14902| [CVE-2006-3590] mso.dll, as used by Microsoft PowerPoint 2000 through 2003, allows user-assisted attackers to execute arbitrary commands via a malformed shape container in a PPT file that leads to memory corruption, as exploited by Trojan.PPDropper.B, a different issue than CVE-2006-1540 and CVE-2006-3493.
14903| [CVE-2006-3510] The Remote Data Service Object (RDS.DataControl) in Microsoft Internet Explorer 6 on Windows 2000 allows remote attackers to cause a denial of service (crash) via a series of operations that result in an invalid length calculation when using SysAllocStringLen, then triggers a buffer over-read.
14904| [CVE-2006-3493] Buffer overflow in LsCreateLine function (mso_203) in mso.dll and mso9.dll, as used by Microsoft Word and possibly other products in Microsoft Office 2003, 2002, and 2000, allows remote user-assisted attackers to cause a denial of service (crash) via a crafted Word DOC or other Office file type. NOTE: this issue was originally reported to allow code execution, but on 20060710 Microsoft stated that code execution is not possible, and the original researcher agrees.
14905| [CVE-2006-3449] Unspecified vulnerability in Microsoft PowerPoint 2000 through 2003, possibly a buffer overflow, allows user-assisted remote attackers to execute arbitrary commands via a malformed record in the BIFF file format used in a PPT file, a different issue than CVE-2006-1540, aka "Microsoft PowerPoint Malformed Record Vulnerability."
14906| [CVE-2006-3448] Buffer overflow in the Step-by-Step Interactive Training in Microsoft Windows 2000 SP4, XP SP2 and Professional, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a long Syllabus string in crafted bookmark link files (cbo, cbl, or .cbm), a different issue than CVE-2005-1212.
14907| [CVE-2006-3445] Integer overflow in the ReadWideString function in agentdpv.dll in Microsoft Agent on Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 allows remote attackers to execute arbitrary code via a large length value in an .ACF file, which results in a heap-based buffer overflow.
14908| [CVE-2006-3444] Unspecified vulnerability in the kernel in Microsoft Windows 2000 SP4, probably a buffer overflow, allows local users to obtain privileges via unspecified vectors involving an "unchecked buffer."
14909| [CVE-2006-3443] Untrusted search path vulnerability in Winlogon in Microsoft Windows 2000 SP4, when SafeDllSearchMode is disabled, allows local users to gain privileges via a malicious DLL in the UserProfile directory, aka "User Profile Elevation of Privilege Vulnerability."
14910| [CVE-2006-3441] Buffer overflow in the DNS Client service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted record response. NOTE: while MS06-041 implies that there is a single issue, there are multiple vectors, and likely multiple vulnerabilities, related to (1) a heap-based buffer overflow in a DNS server response to the client, (2) a DNS server response with malformed ATMA records, and (3) a length miscalculation in TXT, HINFO, X25, and ISDN records.
14911| [CVE-2006-3440] Buffer overflow in the Winsock API in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via unknown vectors, aka "Winsock Hostname Vulnerability."
14912| [CVE-2006-3439] Buffer overflow in the Server Service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers, including anonymous users, to execute arbitrary code via a crafted RPC message, a different vulnerability than CVE-2006-1314.
14913| [CVE-2006-3436] Cross-site scripting (XSS) vulnerability in Microsoft .NET Framework 2.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving "ASP.NET controls that set the AutoPostBack property to true".
14914| [CVE-2006-3435] PowerPoint in Microsoft Office 2000, XP, 2003, 2004 for Mac, and v.X for Mac does not properly parse the slide notes field in a document, which allows remote user-assisted attackers to execute arbitrary code via crafted data in this field, which triggers an erroneous object pointer calculation that uses data from within the document. NOTE: this issue is different than other PowerPoint vulnerabilities including CVE-2006-4694.
14915| [CVE-2006-3434] Unspecified vulnerability in Microsoft Office 2000, XP, 2003, 2004 for Mac, and v.X for Mac allows remote user-assisted attackers to execute arbitrary code via a crafted string that triggers memory corruption.
14916| [CVE-2006-3431] Buffer overflow in certain Asian language versions of Microsoft Excel might allow user-assisted attackers to execute arbitrary code via a crafted STYLE record in a spreadsheet that triggers the overflow when the user attempts to repair the document or selects the "Style" option, as demonstrated by nanika.xls. NOTE: Microsoft has confirmed to CVE via e-mail that this is different than the other Excel vulnerabilities announced before 20060707, including CVE-2006-3059 and CVE-2006-3086.
14917| [CVE-2006-3059] Unspecified vulnerability in Microsoft Excel 2000 through 2004 allows remote user-assisted attackers to execute arbitrary code via unspecified vectors. NOTE: this is a different vulnerability than CVE-2006-3086.
14918| [CVE-2006-2492] Buffer overflow in Microsoft Word in Office 2000 SP3, Office XP SP3, Office 2003 Sp1 and SP2, and Microsoft Works Suites through 2006, allows user-assisted attackers to execute arbitrary code via a malformed object pointer, as originally reported by ISC on 20060519 for a zero-day attack.
14919| [CVE-2006-2389] Unspecified vulnerability in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via an Office file with a malformed property that triggers memory corruption related to record lengths, aka "Microsoft Office Property Vulnerability," a different vulnerability than CVE-2006-1316.
14920| [CVE-2006-2388] Microsoft Office Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via malformed cell comments, which lead to modification of "critical data offsets" during the rebuilding process.
14921| [CVE-2006-2387] Unspecified vulnerability in Microsoft Excel 2000, 2002, 2003, 2004 for Mac, v.X for Mac, Excel Viewer 2003, and Microsoft Works Suite 2004 through 2006 allows user-assisted attackers to execute arbitrary code via a crafted DATETIME record in an XLS file, a different vulnerability than CVE-2006-3867 and CVE-2006-3875.
14922| [CVE-2006-2380] Microsoft Windows 2000 SP4 does not properly validate an RPC server during mutual authentication over SSL, which allows remote attackers to spoof an RPC server, aka the "RPC Mutual Authentication Vulnerability."
14923| [CVE-2006-2379] Buffer overflow in the TCP/IP Protocol driver in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote attackers to execute arbitrary code via unknown vectors related to IP source routing.
14924| [CVE-2006-2378] Buffer overflow in the ART Image Rendering component (jgdw400.dll) in Microsoft Windows XP SP1 and Sp2, Server 2003 SP1 and earlier, and Windows 98 and Me allows remote attackers to execute arbitrary code via a crafted ART image that causes heap corruption.
14925| [CVE-2006-2374] The Server Message Block (SMB) driver (MRXSMB.SYS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows local users to cause a denial of service (hang) by calling the MrxSmbCscIoctlCloseForCopyChunk with the file handle of the shadow device, which results in a deadlock, aka the "SMB Invalid Handle Vulnerability."
14926| [CVE-2006-2373] The Server Message Block (SMB) driver (MRXSMB.SYS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows local users to execute arbitrary code by calling the MrxSmbCscIoctlOpenForCopyChunk function with the METHOD_NEITHER method flag and an arbitrary address, possibly for kernel memory, aka the "SMB Driver Elevation of Privilege Vulnerability."
14927| [CVE-2006-2372] Buffer overflow in the DHCP Client service for Microsoft Windows 2000 SP4, Windows XP SP1 and SP2, and Server 2003 up to SP1 allows remote attackers to execute arbitrary code via a crafted DHCP response.
14928| [CVE-2006-2371] Buffer overflow in the Remote Access Connection Manager service (RASMAN) service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote unauthenticated or authenticated attackers to execute arbitrary code via certain crafted "RPC related requests," that lead to registry corruption and stack corruption, aka the "RASMAN Registry Corruption Vulnerability."
14929| [CVE-2006-2370] Buffer overflow in the Routing and Remote Access service (RRAS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote unauthenticated or authenticated attackers to execute arbitrary code via certain crafted "RPC related requests," aka the "RRAS Memory Corruption Vulnerability."
14930| [CVE-2006-2334] The RtlDosPathNameToNtPathName_U API function in NTDLL.DLL in Microsoft Windows 2000 SP4 and XP SP2 does not properly convert DOS style paths with trailing spaces into NT style paths, which allows context-dependent attackers to create files that cannot be accessed through the expected DOS path or prevent access to other similarly named files in the same directory, which prevents those files from being detected or disinfected by certain anti-virus and anti-spyware software.
14931| [CVE-2006-2094] Microsoft Internet Explorer before Windows XP Service Pack 2 and Windows Server 2003 Service Pack 1, when Prompt is configured in Security Settings, uses modal dialogs to verify that a user wishes to run an ActiveX control or perform other risky actions, which allows user-assisted remote attackers to construct a race condition that tricks a user into clicking an object or pressing keys that are actually applied to a "Yes" approval for executing the control.
14932| [CVE-2006-2055] Argument injection vulnerability in Microsoft Outlook 2003 SP1 allows user-assisted remote attackers to modify command line arguments to an invoked mail client via " (double quote) characters in a mailto: scheme handler, as demonstrated by launching Microsoft Outlook with an arbitrary filename as an attachment. NOTE: it is not clear whether this issue is implementation-specific or a problem in the Microsoft API.
14933| [CVE-2006-1654] Directory traversal vulnerability in the HP Color LaserJet 2500 Toolbox and Color LaserJet 4600 Toolbox on Microsoft Windows before 20060402 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP GET request to TCP port 5225.
14934| [CVE-2006-1651] ** DISPUTED ** Microsoft ISA Server 2004 allows remote attackers to bypass certain filtering rules, including ones for (1) ICMP and (2) TCP, via IPv6 packets. NOTE: An established researcher has disputed this issue, saying that "Neither ISA Server 2004 nor Windows 2003 Basic Firewall support IPv6 filtering ... This is different network protocol."
14935| [CVE-2006-1540] MSO.DLL in Microsoft Office 2000, Office XP (2002), and Office 2003 allows user-assisted attackers to cause a denial of service and execute arbitrary code via multiple attack vectors, as originally demonstrated using a crafted document record with a malformed string, as demonstrated by replacing a certain "01 00 00 00" byte sequence with an "FF FF FF FF" byte sequence, possibly causing an invalid array index, in (1) an Excel .xls document, which triggers an access violation in ole32.dll
14936| [CVE-2006-1316] Unspecified vulnerability in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via an Office file with malformed string that triggers memory corruption related to record lengths, aka "Microsoft Office Parsing Vulnerability," a different vulnerability than CVE-2006-2389.
14937| [CVE-2006-1315] The Server Service (SRV.SYS driver) in Microsoft Windows 2000 SP4, XP SP1 and SP2, Server 2003 up to SP1, and other products, allows remote attackers to obtain sensitive information via crafted requests that leak information in SMB buffers, which are not properly initialized, aka "SMB Information Disclosure Vulnerability."
14938| [CVE-2006-1314] Heap-based buffer overflow in the Server Service (SRV.SYS driver) in Microsoft Windows 2000 SP4, XP SP1 and SP2, Server 2003 up to SP1, and other products, allows remote attackers to execute arbitrary code via crafted first-class Mailslot messages that triggers memory corruption and bypasses size restrictions on second-class Mailslot messages.
14939| [CVE-2006-1313] Microsoft JScript 5.1, 5.5, and 5.6 on Windows 2000 SP4, and 5.6 on Windows XP, Server 2003, Windows 98 and Windows Me, will "release objects early" in certain cases, which results in memory corruption and allows remote attackers to execute arbitrary code.
14940| [CVE-2006-1311] The RichEdit component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1
14941| [CVE-2006-1309] Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted LABEL record that triggers memory corruption.
14942| [CVE-2006-1308] Unspecified vulnerability in Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted FNGROUPCOUNT value.
14943| [CVE-2006-1306] Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted BIFF record with an attacker-controlled array index that is used for a function pointer, aka "Malformed OBJECT record Vulnerability."
14944| [CVE-2006-1305] Microsoft Outlook 2000, 2002, and 2003 allows user-assisted remote attackers to cause a denial of service (memory exhaustion and interrupted mail recovery) via malformed e-mail header information, possibly related to (1) long subject lines or (2) large numbers of recipients in To or CC headers.
14945| [CVE-2006-1304] Buffer overflow in Microsoft Excel 2000 through 2003 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted COLINFO record, which triggers the overflow during a "data filling operation."
14946| [CVE-2006-1302] Buffer overflow in Microsoft Excel 2000 through 2003 allows user-assisted attackers to execute arbitrary code via a .xls file with certain crafted fields in a SELECTION record, which triggers memory corruption, aka "Malformed SELECTION record Vulnerability."
14947| [CVE-2006-1301] Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted SELECTION record that triggers memory corruption, a different vulnerability than CVE-2006-1302.
14948| [CVE-2006-1300] Microsoft .NET framework 2.0 (ASP.NET) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1 allows remote attackers to bypass access restrictions via unspecified "URL paths" that can access Application Folder objects "explicitly by name."
14949| [CVE-2006-1257] The sample files in the authfiles directory in Microsoft Commerce Server 2002 before SP2 allow remote attackers to bypass authentication by logging in to authfiles/login.asp with a valid username and any password, then going to the main site twice.
14950| [CVE-2006-1193] Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2000 SP1 through SP3, when running Outlook Web Access (OWA), allows user-assisted remote attackers to inject arbitrary HTML or web script via unknown vectors related to "HTML parsing."
14951| [CVE-2006-1184] Microsoft Distributed Transaction Coordinator (MSDTC) for Windows NT 4.0, 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote attackers to cause a denial of service (crash) via a BuildContextW request with a large (1) UuidString or (2) GuidIn of a certain length, which causes an out-of-range memory access, aka the MSDTC Denial of Service Vulnerability. NOTE: this is a variant of CVE-2005-2119.
14952| [CVE-2006-0988] The default configuration of the DNS Server service on Windows Server 2003 and Windows 2000, and the Microsoft DNS Server service on Windows NT 4.0, allows recursive queries and provides additional delegation information to arbitrary IP addresses, which allows remote attackers to cause a denial of service (traffic amplification) via DNS queries with spoofed source IP addresses.
14953| [CVE-2006-0935] Microsoft Word 2003 allows remote attackers to cause a denial of service (application crash) via a crafted file, as demonstrated by 101_filefuzz.
14954| [CVE-2006-0187] By design, Microsoft Visual Studio 2005 automatically executes code in the Load event of a user-defined control (UserControl1_Load function), which allows user-assisted attackers to execute arbitrary code by tricking the user into opening a malicious Visual Studio project file.
14955| [CVE-2006-0034] Heap-based buffer overflow in the CRpcIoManagerServer::BuildContext function in msdtcprx.dll for Microsoft Distributed Transaction Coordinator (MSDTC) for Windows NT 4.0 and Windows 2000 SP2 and SP3 allows remote attackers to execute arbitrary code via a long fifth argument to the BuildContextW or BuildContext opcode, which triggers a bug in the NdrAllocate function, aka the MSDTC Invalid Memory Access Vulnerability.
14956| [CVE-2006-0033] Unspecified vulnerability in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via a crafted PNG image that triggers memory corruption when it is parsed.
14957| [CVE-2006-0032] Cross-site scripting (XSS) vulnerability in the Indexing Service in Microsoft Windows 2000, XP, and Server 2003, when the Encoding option is set to Auto Select, allows remote attackers to inject arbitrary web script or HTML via a UTF-7 encoded URL, which is injected into an error message whose charset is set to UTF-7.
14958| [CVE-2006-0031] Stack-based buffer overflow in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed record with a modified length value, which leads to memory corruption.
14959| [CVE-2006-0030] Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed graphic, which leads to memory corruption.
14960| [CVE-2006-0029] Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed description, which leads to memory corruption.
14961| [CVE-2006-0028] Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via a BIFF parsing format file containing malformed BOOLERR records that lead to memory corruption, probably involving invalid pointers.
14962| [CVE-2006-0023] Microsoft Windows XP SP1 and SP2 before August 2004, and possibly other operating systems and versions, uses insecure default ACLs that allow the Authenticated Users group to gain privileges by modifying critical configuration information for the (1) Simple Service Discovery Protocol (SSDP), (2) Universal Plug and Play Device Host (UPnP), (3) NetBT, (4) SCardSvr, (5) DHCP, and (6) DnsCache services, aka "Permissive Windows Services DACLs." NOTE: the NetBT, SCardSvr, DHCP, DnsCache already require privileged access to exploit.
14963| [CVE-2006-0022] Unspecified vulnerability in Microsoft PowerPoint in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP1 and SP2, Office 2004 for Mac, and v. X for Mac allows user-assisted attackers to execute arbitrary code via a PowerPoint document with a malformed record, which triggers memory corruption.
14964| [CVE-2006-0021] Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote attackers to cause a denial of service (hang) via an IGMP packet with an invalid IP option, aka the "IGMP v3 DoS Vulnerability."
14965| [CVE-2006-0020] An unspecified Microsoft WMF parsing application, as used in Internet Explorer 5.01 SP4 on Windows 2000 SP4, and 5.5 SP2 on Windows Millennium, and possibly other versions, allows attackers to cause a denial of service (crash) and possibly execute code via a crafted WMF file with a manipulated WMF header size, possibly involving an integer overflow, a different vulnerability than CVE-2005-4560, and aka "WMF Image Parsing Memory Corruption Vulnerability."
14966| [CVE-2006-0015] Cross-site scripting (XSS) vulnerability in _vti_bin/_vti_adm/fpadmdll.dll in Microsoft FrontPage Server Extensions 2002 and SharePoint Team Services allows remote attackers to inject arbitrary web script or HTML, then leverage the attack to execute arbitrary programs or create new accounts, via the (1) operation, (2) command, and (3) name parameters.
14967| [CVE-2006-0013] Buffer overflow in the Web Client service (WebClnt.dll) for Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote authenticated users or Guests to execute arbitrary code via crafted RPC requests, a different vulnerability than CVE-2005-1207.
14968| [CVE-2006-0012] Unspecified vulnerability in Windows Explorer in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via attack vectors involving COM objects and "crafted files and directories," aka the "Windows Shell Vulnerability."
14969| [CVE-2006-0010] Heap-based buffer overflow in T2EMBED.DLL in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1, Windows 98, and Windows ME allows remote attackers to execute arbitrary code via an e-mail message or web page with a crafted Embedded Open Type (EOT) web font that triggers the overflow during decompression.
14970| [CVE-2006-0009] Buffer overflow in Microsoft Office 2000 SP3, XP SP3, and other versions and packages, allows user-assisted attackers to execute arbitrary code via a routing slip that is longer than specified by the provided length field, as exploited by malware such as TROJ_MDROPPER.BH and Trojan.PPDropper.E in attacks against PowerPoint.
14971| [CVE-2006-0008] The ShellAbout API call in Korean Input Method Editor (IME) in Korean versions of Microsoft Windows XP SP1 and SP2, Windows Server 2003 up to SP1, and Office 2003, allows local users to gain privileges by launching the "shell about dialog box" and clicking the "End-User License Agreement" link, which executes Notepad with the privileges of the program that displays the about box.
14972| [CVE-2006-0007] Buffer overflow in GIFIMP32.FLT, as used in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via a crafted GIF image that triggers memory corruption when it is parsed.
14973| [CVE-2006-0006] Heap-based buffer overflow in the bitmap processing routine in Microsoft Windows Media Player 7.1 on Windows 2000 SP4, Media Player 9 on Windows 2000 SP4 and XP SP1, and Media Player 10 on XP SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted bitmap (.BMP) file that specifies a size of 0 but contains additional data.
14974| [CVE-2006-0004] Microsoft PowerPoint 2000 in Office 2000 SP3 has an interaction with Internet Explorer that allows remote attackers to obtain sensitive information via a PowerPoint presentation that attempts to access objects in the Temporary Internet Files Folder (TIFF).
14975| [CVE-2006-0002] Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment, related to message length validation.
14976| [CVE-2006-0001] Stack-based buffer overflow in Microsoft Publisher 2000 through 2003 allows user-assisted remote attackers to execute arbitrary code via a crafted PUB file, which causes an overflow when parsing fonts.
14977| [CVE-2005-4717] Microsoft Internet Explorer 6.0 on Windows NT 4.0 SP6a, Windows 2000 SP4, Windows XP SP1, Windows XP SP2, and Windows Server 2003 SP1 allows remote attackers to cause a denial of service (client crash) via a certain combination of a malformed HTML file and a CSS file that triggers a null dereference, probably related to rendering of a DIV element that contains a malformed IMG tag, as demonstrated by IEcrash.htm and IEcrash.rar.
14978| [CVE-2005-4269] mshtml.dll in Microsoft Windows XP, Server 2003, and Internet Explorer 6.0 SP1 allows attackers to cause a denial of service (access violation) by causing mshtml.dll to process button-focus events at the same time that a document is reloading, as seen in Microsoft Office InfoPath 2003 by repeatedly clicking the "Delete" button in a repeating section in a form. NOTE: the normal operation of InfoPath appears to involve a local user without any privilege boundaries, so this might not be a vulnerability in InfoPath. If no realistic scenarios exist for this problem in other products, then perhaps it should be excluded from CVE.
14979| [CVE-2005-4131] Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed range, which could lead to memory corruption involving an argument to the msvcrt.memmove function, aka "Brand new Microsoft Excel Vulnerability," as originally placed for sale on eBay as item number 7203336538.
14980| [CVE-2005-3981] ** DISPUTED ** NOTE: this issue has been disputed by third parties. Microsoft Windows XP, 2000, and 2003 allows local users to kill a writable process by using the CreateRemoteThread function with certain arguments on a process that has been opened using the OpenProcess function, possibly involving an invalid address for the start routine. NOTE: followup posts have disputed this issue, saying that if a user already has privileges to write to a process, then other functions could be called or the process could be terminated using PROCESS_TERMINATE.
14981| [CVE-2005-3945] The SynAttackProtect protection in Microsoft Windows 2003 before SP1 and Windows 2000 before SP4 with Update Roll-up uses a hash of predictable data, which allows remote attackers to cause a denial of service (CPU consumption) via a flood of SYN packets that produce identical hash values, which slows down the hash table lookups.
14982| [CVE-2005-3644] PNP_GetDeviceList (upnp_getdevicelist) in UPnP for Microsoft Windows 2000 SP4 and earlier, and possibly Windows XP SP1 and earlier, allows remote attackers to cause a denial of service (memory consumption) via a DCE RPC request that specifies a large output buffer size, a variant of CVE-2006-6296, and a different vulnerability than CVE-2005-2120.
14983| [CVE-2005-3177] CHKDSK in Microsoft Windows 2000 before Update Rollup 1 for SP4, Windows XP, and Windows Server 2003, when running in fix mode, does not properly handle security descriptors if the master file table contains a large number of files or if the descriptors do not satisfy certain NTFS conventions, which could cause ACLs for some files to be reverted to less secure defaults, or cause security descriptors to be removed.
14984| [CVE-2005-3176] Microsoft Windows 2000 before Update Rollup 1 for SP4 does not record the IP address of a Windows Terminal Services client in a security log event if the client connects successfully, which could make it easier for attackers to escape detection.
14985| [CVE-2005-3175] Microsoft Windows 2000 before Update Rollup 1 for SP4 allows a local administrator to unlock a computer even if it has been locked by a domain administrator, which allows the local administrator to access the session as the domain administrator.
14986| [CVE-2005-3174] Microsoft Windows 2000 before Update Rollup 1 for SP4 allows users to log on to the domain, even when their password has expired, if the fully qualified domain name (FQDN) is 8 characters long.
14987| [CVE-2005-3173] Microsoft Windows 2000 before Update Rollup 1 for SP4 does not apply group policies if the user logs on using UPN credentials with a trailing dot, which prevents Windows 2000 from finding the correct domain controller and could allow the user to bypass intended restrictions.
14988| [CVE-2005-3172] The WideCharToMultiByte function in Microsoft Windows 2000 before Update Rollup 1 for SP4 does not properly convert strings with Japanese composite characters in the last character, which could prevent the string from being null terminated and lead to data corruption or enable buffer overflow attacks.
14989| [CVE-2005-3171] Microsoft Windows 2000 before Update Rollup 1 for SP4 records Event ID 1704 to indicate that Group Policy security settings were successfully updated, even when the processing fails such as when Ntuser.pol cannot be accessed, which could cause system administrators to believe that the system is compliant with the specified settings.
14990| [CVE-2005-3170] The LDAP client on Microsoft Windows 2000 before Update Rollup 1 for SP4 accepts certificates using LDAP Secure Sockets Layer (LDAPS) even when the Certificate Authority (CA) is not trusted, which could allow attackers to trick users into believing that they are accessing a trusted site.
14991| [CVE-2005-3169] Microsoft Windows 2000 before Update Rollup 1 for SP4, when the "audit directory service access" policy is enabled, does not record a 565 event message for File Delete Child operations on an Active Directory object in the security event log, which could allow attackers to conduct unauthorized activities without detection.
14992| [CVE-2005-3168] The SECEDIT command on Microsoft Windows 2000 before Update Rollup 1 for SP4, when using a security template to set Access Control Lists (ACLs) on folders, does not apply ACLs on folders that are listed after a long folder entry, which could result in less secure permissions than specified by the template.
14993| [CVE-2005-2122] Windows Shell for Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote attackers to execute arbitrary commands via a shortcut (.lnk) file with long font properties that lead to a buffer overflow in the Client/Server Runtime Server Subsystem (CSRSS), a different vulnerability than CVE-2005-2118.
14994| [CVE-2005-2120] Stack-based buffer overflow in the Plug and Play (PnP) service (UMPNPMGR.DLL) in Microsoft Windows 2000 SP4, and XP SP1 and SP2, allows remote or local authenticated attackers to execute arbitrary code via a large number of "\" (backslash) characters in a registry key name, which triggers the overflow in a wsprintfW function call.
14995| [CVE-2005-2118] Windows Shell for Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote user-assisted attackers to execute arbitrary commands via a crafted shortcut (.lnk) file with long font properties that lead to a buffer overflow when the user views the file's properties using Windows Explorer, a different vulnerability than CVE-2005-2122.
14996| [CVE-2005-2117] Web View in Windows Explorer on Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 does not properly handle certain HTML characters in preview fields, which allows remote user-assisted attackers to execute arbitrary code.
14997| [CVE-2005-1985] The Client Service for NetWare (CSNW) on Microsoft Windows 2000 SP4, XP SP1 and Sp2, and Server 2003 SP1 and earlier, allows remote attackers to execute arbitrary code due to an "unchecked buffer" when processing certain crafted network messages.
14998| [CVE-2005-1984] Buffer overflow in the Print Spooler service (Spoolsv.exe) for Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via a malicious message.
14999| [CVE-2005-1983] Stack-based buffer overflow in the Plug and Play (PnP) service for Microsoft Windows 2000 and Windows XP Service Pack 1 allows remote attackers to execute arbitrary code via a crafted packet, and local users to gain privileges via a malicious application, as exploited by the Zotob (aka Mytob) worm.
15000| [CVE-2005-1982] Unknown vulnerability in the PKINIT Protocol for Microsoft Windows 2000, Windows XP, and Windows Server 2003 could allow a local user to obtain information and spoof a server via a man-in-the-middle (MITM) attack between a client and a domain controller when PKINIT smart card authentication is being used.
15001| [CVE-2005-1981] Unknown vulnerability in Microsoft Windows 2000 Server and Windows Server 2003 domain controllers allows remote authenticated users to cause a denial of service (system crash) via a crafted Kerberos message.
15002| [CVE-2005-1907] The ISA Firewall service in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service (Wspsrv.exe crash) via a large amount of SecureNAT network traffic.
15003| [CVE-2005-1683] Buffer overflow in winword.exe 10.2627.6714 and earlier in Microsoft Word for the Macintosh, before SP3 for Word 2002, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted mcw file.
15004| [CVE-2005-1218] The Microsoft Windows kernel in Microsoft Windows 2000 Server, Windows XP, and Windows Server 2003 allows remote attackers to cause a denial of service (crash) via crafted Remote Desktop Protocol (RDP) requests.
15005| [CVE-2005-1216] Microsoft ISA Server 2000 allows remote attackers to connect to services utilizing the NetBIOS protocol via a NetBIOS connection with an ISA Server that uses the NetBIOS (all) predefined packet filter.
15006| [CVE-2005-1215] Microsoft ISA Server 2000 allows remote attackers to poison the ISA cache or bypass content restriction policies via a malformed HTTP request packet containing multiple Content-Length headers.
15007| [CVE-2005-1208] Integer overflow in Microsoft Windows 98, 2000, XP SP2 and earlier, and Server 2003 SP1 and earlier allows remote attackers to execute arbitrary code via a crafted compiled Help (.CHM) file with a large size field that triggers a heap-based buffer overflow, as demonstrated using a "ms-its:" URL in Internet Explorer.
15008| [CVE-2005-1207] Buffer overflow in the Web Client service in Microsoft Windows XP and Windows Server 2003 allows remote authenticated users to execute arbitrary code via a crafted WebDAV request containing special parameters.
15009| [CVE-2005-1206] Buffer overflow in the Server Message Block (SMB) functionality for Microsoft Windows 2000, XP SP1 and SP2, and Server 2003 and SP1 allows remote attackers to execute arbitrary code via unknown vectors, aka the "Server Message Block Vulnerability."
15010| [CVE-2005-1205] The Telnet client for Microsoft Windows XP, Windows Server 2003, and Windows Services for UNIX allows remote attackers to read sensitive environment variables via the NEW-ENVIRON option with a SEND ENV_USERVAR command.
15011| [CVE-2005-1052] Microsoft Outlook 2003 and Outlook Web Access (OWA) 2003 do not properly display comma separated addresses in the From field in an e-mail message, which could allow remote attackers to spoof e-mail addresses.
15012| [CVE-2005-0921] Microsoft Outlook 2002 Connector for IBM Lotus Domino 2.0 allows local users to save passwords and login credentials locally, even when password caching is disabled by a group policy.
15013| [CVE-2005-0820] Microsoft Office InfoPath 2003 SP1 includes sensitive information in the Manifest.xsf file in a custom .xsn form, which allows attackers to obtain printer and network information, obtain the database name, username, and password, or obtain the internal web server name.
15014| [CVE-2005-0738] Stack consumption vulnerability in Microsoft Exchange Server 2003 SP1 allows users to cause a denial of service (hang) by deleting or moving a folder with deeply nested subfolders, which causes Microsoft Exchange Information Store service (Store.exe) to hang as a result of a large number of recursive calls.
15015| [CVE-2005-0564] Stack-based buffer overflow in Microsoft Word 2000 and Word 2002, and Microsoft Works Suites 2000 through 2004, might allow remote attackers to execute arbitrary code via a .doc file with long font information.
15016| [CVE-2005-0558] Buffer overflow in Microsoft Word 2000, Word 2002, and Word 2003 allows remote attackers to execute arbitrary code via a crafted document.
15017| [CVE-2005-0551] Stack-based buffer overflow in WINSRV.DLL in the Client Server Runtime System (CSRSS) process of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application that provides console window information with a long FaceName value.
15018| [CVE-2005-0550] Buffer overflow in Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to cause a denial of service (i.e., system crash) via a malformed request, aka "Object Management Vulnerability".
15019| [CVE-2005-0545] Microsoft Windows XP Pro SP2 and Windows 2000 Server SP4 running Active Directory allow local users to bypass group policies that restrict access to hidden drives by using the browse feature in Office 10 applications such as Word or Excel, or using a flash drive. NOTE: this issue has been disputed in a followup post.
15020| [CVE-2005-0063] The document processing application used by the Windows Shell in Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by modifying the CLSID stored in a file so that it is processed by HTML Application Host (MSHTA), as demonstrated using a Microsoft Word document.
15021| [CVE-2005-0061] The kernel of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via certain access requests.
15022| [CVE-2005-0060] Buffer overflow in the font processing component of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application.
15023| [CVE-2005-0059] Buffer overflow in the Message Queuing component of Microsoft Windows 2000 and Windows XP SP1 allows remote attackers to execute arbitrary code via a crafted message.
15024| [CVE-2005-0058] Buffer overflow in the Telephony Application Programming Interface (TAPI) for Microsoft Windows 98, Windows 98 SE, Windows ME, Windows 2000, Windows XP, and Windows Server 2003 allows attackers elevate privileges or execute arbitrary code via a crafted message.
15025| [CVE-2005-0048] Microsoft Windows XP SP2 and earlier, 2000 SP3 and SP4, Server 2003, and older operating systems allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted IP packets with malformed options, aka the "IP Validation Vulnerability."
15026| [CVE-2004-2527] The local and remote desktop login screens in Microsoft Windows XP before SP2 and 2003 allow remote attackers to cause a denial of service (CPU and memory consumption) by repeatedly using the WinKey+"U" key combination, which causes multiple copies of Windows Utility Manager to be loaded more quickly than they can be closed when the copies detect that another instance is running.
15027| [CVE-2004-2482] Microsoft Outlook 2000 and 2003, when configured to use Microsoft Word 2000 or 2003 as the e-mail editor and when forwarding e-mail, does not properly handle an opening OBJECT tag that does not have a closing OBJECT tag, which causes Outlook to automatically download the URI in the data property of the OBJECT tag and might allow remote attackers to execute arbitrary code.
15028| [CVE-2004-2365] Memory leak in Microsoft Windows XP and Windows Server 2003 allows local users to cause a denial of service (memory exhaustion) by repeatedly creating and deleting directories using a non-standard tool such as smbmount.
15029| [CVE-2004-2339] ** DISPUTED ** Microsoft Windows 2000, XP, and possibly 2003 allows local users with the SeDebugPrivilege privilege to execute arbitrary code as kernel and read or write kernel memory via the NtSystemDebugControl function, which does not verify its pointer arguments. Note: this issue has been disputed, since Administrator privileges are typically required to exploit this issue, thus privilege boundaries are not crossed.
15030| [CVE-2004-1080] The WINS service (wins.exe) on Microsoft Windows NT Server 4.0, Windows 2000 Server, and Windows Server 2003 allows remote attackers to write to arbitrary memory locations and possibly execute arbitrary code via a modified memory pointer in a WINS replication packet to TCP port 42, aka the "Association Context Vulnerability."
15031| [CVE-2004-0963] Buffer overflow in Microsoft Word 2002 (10.6612.6714) SP3, and possibly other versions, allows remote attackers to cause a denial of service (application exception) and possibly execute arbitrary code in winword.exe via certain unexpected values in a .doc file, including (1) an offset that triggers an out-of-bounds memory access, (2) a certain value that causes a large memory copy as triggered by an integer conversion error, and other values.
15032| [CVE-2004-0897] The Indexing Service for Microsoft Windows XP and Server 2003 does not properly validate the length of a message, which allows remote attackers to execute arbitrary code via a buffer overflow attack.
15033| [CVE-2004-0892] Microsoft Proxy Server 2.0 and Microsoft ISA Server 2000 (which is included in Small Business Server 2000 and Small Business Server 2003 Premium Edition) allows remote attackers to spoof trusted Internet content on a specially crafted webpage via spoofed reverse DNS lookup results.
15034| [CVE-2004-0846] Unknown vulnerability in Microsoft Excel 2000, 2002, 2001 for Mac, and v.X for Mac allows remote attackers to execute arbitrary code via a malicious file containing certain parameters that are not properly validated.
15035| [CVE-2004-0840] The SMTP (Simple Mail Transfer Protocol) component of Microsoft Windows XP 64-bit Edition, Windows Server 2003, Windows Server 2003 64-bit Edition, and the Exchange Routing Engine component of Exchange Server 2003, allows remote attackers to execute arbitrary code via a malicious DNS response message containing length values that are not properly validated.
15036| [CVE-2004-0728] The Remote Control Client service in Microsoft's Systems Management Server (SMS) 2.50.2726.0 allows remote attackers to cause a denial of service (crash) via a data packet to TCP port 2702 that causes the server to read or write to an invalid memory address.
15037| [CVE-2004-0726] The Windows Media Player control in Microsoft Windows 2000 allows remote attackers to execute arbitrary script in the local computer zone via an ASX filename that contains javascript, which is executed in the local context in a preview panel.
15038| [CVE-2004-0575] Integer overflow in DUNZIP32.DLL for Microsoft Windows XP, Windows XP 64-bit Edition, Windows Server 2003, and Windows Server 2003 64-bit Edition allows remote attackers to execute arbitrary code via compressed (zipped) folders that involve an "unchecked buffer" and improper length validation.
15039| [CVE-2004-0574] The Network News Transfer Protocol (NNTP) component of Microsoft Windows NT Server 4.0, Windows 2000 Server, Windows Server 2003, Exchange 2000 Server, and Exchange Server 2003 allows remote attackers to execute arbitrary code via XPAT patterns, possibly related to improper length validation and an "unchecked buffer," leading to off-by-one and heap-based buffer overflows.
15040| [CVE-2004-0573] Buffer overflow in the converter for Microsoft WordPerfect 5.x on Office 2000, Office XP, Office 2003, and Works Suites 2001 through 2004 allows remote attackers to execute arbitrary code via a malicious document or website.
15041| [CVE-2004-0540] Microsoft Windows 2000, when running in a domain whose Fully Qualified Domain Name (FQDN) is exactly 8 characters long, does not prevent users with expired passwords from logging on to the domain.
15042| [CVE-2004-0503] Microsoft Outlook 2003 allows remote attackers to bypass the default zone restrictions and execute script within media files via a Rich Text Format (RTF) message containing an OLE object for the Windows Media Player, which bypasses Media Player's setting to disallow scripting and may lead to unprompted installation of an executable when exploited in conjunction with predictable-file-location exposures such as CVE-2004-0502.
15043| [CVE-2004-0379] Multiple cross-site scripting (XSS) vulnerabilities in Microsoft SharePoint Portal Server 2001 allow remote attackers to process arbitrary web content and steal cookies via certain server scripts.
15044| [CVE-2004-0284] Microsoft Internet Explorer 6.0, Outlook 2002, and Outlook 2003 allow remote attackers to cause a denial of service (CPU consumption), if "Do not save encrypted pages to disk" is disabled, via a web site or HTML e-mail that contains two null characters (%00) after the host name.
15045| [CVE-2004-0214] Buffer overflow in Microsoft Internet Explorer and Explorer on Windows XP SP1, WIndows 2000, Windows 98, and Windows Me may allow remote malicious servers to cause a denial of service (application crash) and possibly execute arbitrary code via long share names, as demonstrated using Samba.
15046| [CVE-2004-0211] The kernel for Microsoft Windows Server 2003 does not reset certain values in CPU data structures, which allows local users to cause a denial of service (system crash) via a malicious program.
15047| [CVE-2004-0210] The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters, possibly by modifying message length values and causing a buffer overflow.
15048| [CVE-2004-0209] Unknown vulnerability in the Graphics Rendering Engine processes of Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats that involve "an unchecked buffer."
15049| [CVE-2004-0208] The Virtual DOS Machine (VDM) subsystem of Microsoft Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows local users to access kernel memory and gain privileges via a malicious program that modified some system structures in a way that is not properly validated by privileged operating system functions.
15050| [CVE-2004-0207] "Shatter" style vulnerability in the Window Management application programming interface (API) for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows local users to gain privileges by using certain API functions to change properties of privileged programs using the SetWindowLong and SetWIndowLongPtr API functions.
15051| [CVE-2004-0206] Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to remotely execute arbitrary code or locally gain privileges via a malicious message or application that involves an "unchecked buffer," possibly a buffer overflow.
15052| [CVE-2004-0204] Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as used in Visual Studio .NET 2003 and Outlook 2003 with Business Contact Manager, Microsoft Business Solutions CRM 1.2, and other products, allows remote attackers to read and delete arbitrary files via ".." sequences in the dynamicimag argument to crystalimagehandler.aspx.
15053| [CVE-2004-0202] IDirectPlay4 Application Programming Interface (API) of Microsoft DirectPlay 7.0a thru 9.0b, as used in Windows Server 2003 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed packet.
15054| [CVE-2004-0201] Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, Me, NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary commands via a .CHM file with a large length field, a different vulnerability than CVE-2003-1041.
15055| [CVE-2004-0199] Help and Support Center in Microsoft Windows XP and Windows Server 2003 SP1 does not properly validate HCP URLs, which allows remote attackers to execute arbitrary code, as demonstrated using certain hcp:// URLs that access the DVD Upgrade capability (dvdupgrd.htm).
15056| [CVE-2004-0124] The DCOM RPC interface for Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause network communications via an "alter context" call that contains additional data, aka the "Object Identity Vulnerability."
15057| [CVE-2004-0121] Argument injection vulnerability in Microsoft Outlook 2002 does not sufficiently filter parameters of mailto: URLs when using them as arguments when calling OUTLOOK.EXE, which allows remote attackers to use script code in the Local Machine zone and execute arbitrary programs.
15058| [CVE-2004-0120] The Microsoft Secure Sockets Layer (SSL) library, as used in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service via malformed SSL messages.
15059| [CVE-2004-0116] An Activation function in the RPCSS Service involved with DCOM activation for Microsoft Windows 2000, XP, and 2003 allows remote attackers to cause a denial of service (memory consumption) via an activation request with a large length field.
15060| [CVE-2003-1378] Microsoft Outlook Express 6.0 and Outlook 2000, with the security zone set to Internet Zone, allows remote attackers to execute arbitrary programs via an HTML email with the CODEBASE parameter set to the program, a vulnerability similar to CAN-2002-0077.
15061| [CVE-2003-1106] The SMTP service in Microsoft Windows 2000 before SP4 allows remote attackers to cause a denial of service (crash or hang) via an e-mail message with a malformed time stamp in the FILETIME attribute.
15062| [CVE-2003-0908] The Utility Manager in Microsoft Windows 2000 executes winhlp32.exe with system privileges, which allows local users to execute arbitrary code via a "Shatter" style attack using a Windows message that accesses the context sensitive help button in the GUI, as demonstrated using the File Open dialog in the Help window, a different vulnerability than CVE-2004-0213.
15063| [CVE-2003-0906] Buffer overflow in the rendering for (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1 allows remote attackers to execute arbitrary code via a malformed WMF or EMF image.
15064| [CVE-2003-0904] Microsoft Exchange 2003 and Outlook Web Access (OWA), when configured to use NTLM authentication, does not properly reuse HTTP connections, which can cause OWA users to view mailboxes of other users when Kerberos has been disabled as an authentication method for IIS 6.0, e.g. when SharePoint Services 2.0 is installed.
15065| [CVE-2003-0839] Directory traversal vulnerability in the "Shell Folders" capability in Microsoft Windows Server 2003 allows remote attackers to read arbitrary files via .. (dot dot) sequences in a "shell:" link.
15066| [CVE-2003-0825] The Windows Internet Naming Service (WINS) for Microsoft Windows Server 2003, and possibly Windows NT and Server 2000, does not properly validate the length of certain packets, which allows attackers to cause a denial of service and possibly execute arbitrary code.
15067| [CVE-2003-0824] Unknown vulnerability in the SmartHTML interpreter (shtml.dll) in Microsoft FrontPage Server Extensions 2000 and 2002, and Microsoft SharePoint Team Services 2002, allows remote attackers to cause a denial of service (response failure) via a certain request.
15068| [CVE-2003-0822] Buffer overflow in the debug functionality in fp30reg.dll of Microsoft FrontPage Server Extensions (FPSE) 2000 and 2002 allows remote attackers to execute arbitrary code via a crafted chunked encoded request.
15069| [CVE-2003-0821] Microsoft Excel 97, 2000, and 2002 allows remote attackers to execute arbitrary code via a spreadsheet with a malicious XLM (Excel 4) macro that bypasses the macro security model.
15070| [CVE-2003-0820] Microsoft Word 97, 98(J), 2000, and 2002, and Microsoft Works Suites 2001 through 2004, do not properly check the length of the "Macro names" data value, which could allow remote attackers to execute arbitrary code via a buffer overflow attack.
15071| [CVE-2003-0819] Buffer overflow in the H.323 filter of Microsoft Internet Security and Acceleration Server 2000 allows remote attackers to execute arbitrary code in the Microsoft Firewall Service via certain H.323 traffic, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.
15072| [CVE-2003-0818] Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DLL, and other Microsoft executables and libraries on Windows NT 4.0, 2000, and XP, allow remote attackers to execute arbitrary code via ASN.1 BER encodings with (1) very large length fields that cause arbitrary heap data to be overwritten, or (2) modified bit strings.
15073| [CVE-2003-0807] Buffer overflow in the COM Internet Services and in the RPC over HTTP Proxy components for Microsoft Windows NT Server 4.0, NT 4.0 Terminal Server Edition, 2000, XP, and Server 2003 allows remote attackers to cause a denial of service via a crafted request.
15074| [CVE-2003-0806] Buffer overflow in the Windows logon process (winlogon) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1, when a member of a domain, allows remote attackers to execute arbitrary code.
15075| [CVE-2003-0719] Buffer overflow in the Private Communications Transport (PCT) protocol implementation in the Microsoft SSL library, as used in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via PCT 1.0 handshake packets.
15076| [CVE-2003-0665] Buffer overflow in the ActiveX control for Microsoft Access Snapshot Viewer for Access 97, 2000, and 2002 allows remote attackers to execute arbitrary code via long parameters to the control.
15077| [CVE-2003-0664] Microsoft Word 2002, 2000, 97, and 98(J) does not properly check certain properties of a document, which allows attackers to bypass the macro security model and automatically execute arbitrary macros via a malicious document.
15078| [CVE-2003-0662] Buffer overflow in Troubleshooter ActiveX Control (Tshoot.ocx) in Microsoft Windows 2000 SP4 and earlier allows remote attackers to execute arbitrary code via an HTML document with a long argument to the RunQuery2 method.
15079| [CVE-2003-0660] The Authenticode capability in Microsoft Windows NT through Server 2003 does not prompt the user to download and install ActiveX controls when the system is low on memory, which could allow remote attackers execute arbitrary code without user approval.
15080| [CVE-2003-0533] Stack-based buffer overflow in certain Active Directory service functions in LSASRV.DLL of the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via a packet that causes the DsRolerUpgradeDownlevelServer function to create long debug entries for the DCPROMO.LOG log file, as exploited by the Sasser worm.
15081| [CVE-2003-0526] Cross-site scripting (XSS) vulnerability in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to inject arbitrary web script via a URL containing the script in the domain name portion, which is not properly cleansed in the default error pages (1) 500.htm for "500 Internal Server error" or (2) 404.htm for "404 Not Found."
15082| [CVE-2003-0506] Microsoft NetMeeting 3.01 2000 before SP4 allows remote attackers to cause a denial of service (shutdown of NetMeeting conference) via malformed packets, as demonstrated via the chat conversation.
15083| [CVE-2003-0505] Directory traversal vulnerability in Microsoft NetMeeting 3.01 2000 before SP4 allows remote attackers to read arbitrary files via "..\.." (dot dot) sequences in a file transfer request.
15084| [CVE-2003-0496] Microsoft SQL Server before Windows 2000 SP4 allows local users to gain privileges as the SQL Server user by calling the xp_fileexist extended stored procedure with a named pipe as an argument instead of a normal file.
15085| [CVE-2003-0352] Buffer overflow in a certain DCOM interface for RPC in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary code via a malformed message, as exploited by the Blaster/MSblast/LovSAN and Nachi/Welchia worms.
15086| [CVE-2003-0345] Buffer overflow in the SMB capability for Microsoft Windows XP, 2000, and NT allows remote attackers to cause a denial of service and possibly execute arbitrary code via an SMB packet that specifies a smaller buffer length than is required.
15087| [CVE-2003-0232] Microsoft SQL Server 7, 2000, and MSDE allows local users to execute arbitrary code via a certain request to the Local Procedure Calls (LPC) port that leads to a buffer overflow.
15088| [CVE-2003-0231] Microsoft SQL Server 7, 2000, and MSDE allows local or remote authenticated users to cause a denial of service (crash or hang) via a long request to a named pipe.
15089| [CVE-2003-0230] Microsoft SQL Server 7, 2000, and MSDE allows local users to gain privileges by hijacking a named pipe during the authentication of another user, aka the "Named Pipe Hijacking" vulnerability.
15090| [CVE-2003-0227] The logging capability for unicast and multicast transmissions in the ISAPI extension for Microsoft Windows Media Services in Microsoft Windows NT 4.0 and 2000, nsiislog.dll, allows remote attackers to cause a denial of service in Internet Information Server (IIS) and execute arbitrary code via a certain network request.
15091| [CVE-2003-0118] SQL injection vulnerability in the Document Tracking and Administration (DTA) website of Microsoft BizTalk Server 2000 and 2002 allows remote attackers to execute operating system commands via a request to (1) rawdocdata.asp or (2) RawCustomSearchField.asp containing an embedded SQL statement.
15092| [CVE-2003-0117] Buffer overflow in the HTTP receiver function (BizTalkHTTPReceive.dll ISAPI) of Microsoft BizTalk Server 2002 allows attackers to execute arbitrary code via a certain request to the HTTP receiver.
15093| [CVE-2003-0110] The Winsock Proxy service in Microsoft Proxy Server 2.0 and the Microsoft Firewall service in Internet Security and Acceleration (ISA) Server 2000 allow remote attackers to cause a denial of service (CPU consumption or packet storm) via a spoofed, malformed packet to UDP port 1745.
15094| [CVE-2003-0109] Buffer overflow in ntdll.dll on Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute arbitrary code, as demonstrated via a WebDAV request to IIS 5.0.
15095| [CVE-2003-0011] Unknown vulnerability in the DNS intrusion detection application filter for Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service (blocked traffic to DNS servers) via a certain type of incoming DNS request that is not properly handled.
15096| [CVE-2003-0007] Microsoft Outlook 2002 does not properly handle requests to encrypt email messages with V1 Exchange Server Security certificates, which causes Outlook to send the email in plaintext, aka "Flaw in how Outlook 2002 handles V1 Exchange Server Security Certificates could lead to Information Disclosure."
15097| [CVE-2003-0003] Buffer overflow in the RPC Locator service for Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute arbitrary code via an RPC call to the service containing certain parameter information.
15098| [CVE-2003-0002] Cross-site scripting vulnerability (XSS) in ManualLogin.asp script for Microsoft Content Management Server (MCMS) 2001 allows remote attackers to execute arbitrary script via the REASONTXT parameter.
15099| [CVE-2002-2101] Microsoft Outlook 2002 allows remote attackers to execute arbitrary JavaScript code, even when scripting is disabled, via an "about:" or "javascript:" URI in the href attribute of an "a" tag.
15100| [CVE-2002-2100] Microsoft Outlook 2002 allows remote attackers to embed bypass the file download restrictions for attachments via an HTML email message that uses an IFRAME to reference malicious content.
15101| [CVE-2002-1984] Microsoft Internet Explorer 5.0.1 through 6.0 on Windows 2000 or Windows XP allows remote attackers to cause a denial of service (crash) via an OBJECT tag that contains a crafted CLASSID (CLSID) value of "CLSID:00022613-0000-0000-C000-000000000046".
15102| [CVE-2002-1981] Microsoft SQL Server 2000 through SQL Server 2000 SP2 allows the "public" role to execute the (1) sp_MSSetServerProperties or (2) sp_MSsetalertinfo stored procedures, which allows attackers to modify configuration including SQL server startup and alert settings.
15103| [CVE-2002-1933] The terminal services screensaver for Microsoft Windows 2000 does not automatically lock the terminal window if the window is minimized, which could allow local users to gain access to the terminal server window.
15104| [CVE-2002-1932] Microsoft Windows XP and Windows 2000, when configured to send administrative alerts and the "Do not overwrite events (clear log manually)" option is set, does not notify the administrator when the log reaches its maximum size, which allows local users and remote attackers to avoid detection.
15105| [CVE-2002-1876] Microsoft Exchange 2000 allows remote authenticated attackers to cause a denial of service via a large number of rapid requests, which consumes all of the licenses that are granted to Exchange by IIS.
15106| [CVE-2002-1873] Microsoft Exchange 2000, when used with Microsoft Remote Procedure Call (MSRPC), allows remote attackers to cause a denial of service (crash or memory consumption) via malformed MSRPC calls.
15107| [CVE-2002-1872] Microsoft SQL Server 6.0 through 2000, with SQL Authentication enabled, uses weak password encryption (XOR), which allows remote attackers to sniff and decrypt the password.
15108| [CVE-2002-1776] ** DISPUTED ** NOTE: this issue has been disputed by the vendor. Symantec Norton AntiVirus 2002 allows remote attackers to bypass virus protection via a Word Macro virus with a .nch or .dbx extension, which is automatically recognized and executed as a Microsoft Office document. NOTE: the vendor has disputed this issue, acknowledging that the initial scan is bypassed, but the Office plug-in would detect the virus before it is executed.
15109| [CVE-2002-1712] Microsoft Windows 2000 allows remote attackers to cause a denial of service (memory consumption) by sending a flood of empty TCP/IP packets with the ACK and FIN bits set to the NetBIOS port (TCP/139), as demonstrated by stream3.
15110| [CVE-2002-1256] The SMB signing capability in the Server Message Block (SMB) protocol in Microsoft Windows 2000 and Windows XP allows attackers to disable the digital signing settings in an SMB session to force the data to be sent unsigned, then inject data into the session without detection, e.g. by modifying group policy information sent from a domain controller.
15111| [CVE-2002-1255] Microsoft Outlook 2002 allows remote attackers to cause a denial of service (repeated failure) via an email message with a certain invalid header field that is accessed using POP3, IMAP, or WebDAV, aka "E-mail Header Processing Flaw Could Cause Outlook 2002 to Fail."
15112| [CVE-2002-1214] Buffer overflow in Microsoft PPTP Service on Windows XP and Windows 2000 allows remote attackers to cause a denial of service (hang) and possibly execute arbitrary code via a certain PPTP packet with malformed control data.
15113| [CVE-2002-1184] The system root folder of Microsoft Windows 2000 has default permissions of Everyone group with Full access (Everyone:F) and is in the search path when locating programs during login or application launch from the desktop, which could allow attackers to gain privileges as other users via Trojan horse programs.
15114| [CVE-2002-1145] The xp_runwebtask stored procedure in the Web Tasks component of Microsoft SQL Server 7.0 and 2000, Microsoft Data Engine (MSDE) 1.0, and Microsoft Desktop Engine (MSDE) 2000 can be executed by PUBLIC, which allows an attacker to gain privileges by updating a webtask that is owned by the database owner through the msdb.dbo.mswebtasks table, which does not have strong permissions.
15115| [CVE-2002-1141] An input validation error in the Sun Microsystems RPC library Services for Unix 3.0 Interix SD, as implemented on Microsoft Windows NT4, 2000, and XP, allows remote attackers to cause a denial of service via malformed fragmented RPC client packets, aka "Denial of service by sending an invalid RPC request."
15116| [CVE-2002-1140] The Sun Microsystems RPC library Services for Unix 3.0 Interix SD, as implemented on Microsoft Windows NT4, 2000, and XP, allows remote attackers to cause a denial of service (service hang) via malformed packet fragments, aka "Improper parameter size check leading to denial of service."
15117| [CVE-2002-1138] Microsoft SQL Server 7.0 and 2000, including Microsoft Data Engine (MSDE) 1.0 and Microsoft Desktop Engine (MSDE) 2000, writes output files for scheduled jobs under its own privileges instead of the entity that launched it, which allows attackers to overwrite system files, aka "Flaw in Output File Handling for Scheduled Jobs."
15118| [CVE-2002-1137] Buffer overflow in the Database Console Command (DBCC) that handles user inputs in Microsoft SQL Server 7.0 and 2000, including Microsoft Data Engine (MSDE) 1.0 and Microsoft Desktop Engine (MSDE) 2000, allows attackers to execute arbitrary code via a long SourceDB argument in a "non-SQL OLEDB data source" such as FoxPro, a variant of CAN-2002-0644.
15119| [CVE-2002-1123] Buffer overflow in the authentication function for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 allows remote attackers to execute arbitrary code via a long request to TCP port 1433, aka the "Hello" overflow.
15120| [CVE-2002-1117] Veritas Backup Exec 8.5 and earlier requires that the "RestrictAnonymous" registry key for Microsoft Exchange 2000 must be set to 0, which enables anonymous listing of the SAM database and shares.
15121| [CVE-2002-1056] Microsoft Outlook 2000 and 2002, when configured to use Microsoft Word as the email editor, does not block scripts that are used while editing email messages in HTML or Rich Text Format (RTF), which could allow remote attackers to execute arbitrary scripts via an email that the user forwards or replies to.
15122| [CVE-2002-0982] Microsoft SQL Server 2000 SP2, when configured as a distributor, allows attackers to execute arbitrary code via the @scriptfile parameter to the sp_MScopyscript stored procedure.
15123| [CVE-2002-0975] Buffer overflow in Microsoft DirectX Files Viewer ActiveX control (xweb.ocx) 2.0.6.15 and earlier allows remote attackers to execute arbitrary via a long File parameter.
15124| [CVE-2002-0863] Remote Data Protocol (RDP) version 5.0 in Microsoft Windows 2000 and RDP 5.1 in Windows XP does not encrypt the checksums of plaintext session data, which could allow a remote attacker to determine the contents of encrypted sessions via sniffing, aka "Weak Encryption in RDP Protocol."
15125| [CVE-2002-0861] Microsoft Office Web Components (OWC) 2000 and 2002 allows remote attackers to bypass the "Allow paste operations via script" setting, even when it is disabled, via the (1) Copy method of the Cell object or (2) the Paste method of the Range object.
15126| [CVE-2002-0860] The LoadText method in the spreadsheet component in Microsoft Office Web Components (OWC) 2000 and 2002 allows remote attackers to read arbitrary files through Internet Explorer via a URL that redirects to the target file.
15127| [CVE-2002-0859] Buffer overflow in the OpenDataSource function of the Jet engine on Microsoft SQL Server 2000 allows remote attackers to execute arbitrary code.
15128| [CVE-2002-0729] Microsoft SQL Server 2000 allows remote attackers to cause a denial of service via a malformed 0x08 packet that is missing a colon separator.
15129| [CVE-2002-0727] The Host function in Microsoft Office Web Components (OWC) 2000 and 2002 is exposed in components that are marked as safe for scripting, which allows remote attackers to execute arbitrary commands via the setTimeout method.
15130| [CVE-2002-0724] Buffer overflow in SMB (Server Message Block) protocol in Microsoft Windows NT, Windows 2000, and Windows XP allows attackers to cause a denial of service (crash) via a SMB_COM_TRANSACTION packet with a request for the (1) NetShareEnum, (2) NetServerEnum2, or (3) NetServerEnum3, aka "Unchecked Buffer in Network Share Provider Can Lead to Denial of Service".
15131| [CVE-2002-0721] Microsoft SQL Server 7.0 and 2000 installs with weak permissions for extended stored procedures that are associated with helper functions, which could allow unprivileged users, and possibly remote attackers, to run stored procedures with administrator privileges via (1) xp_execresultset, (2) xp_printstatements, or (3) xp_displayparamstmt.
15132| [CVE-2002-0719] SQL injection vulnerability in the function that services for Microsoft Content Management Server (MCMS) 2001 allows remote attackers to execute arbitrary commands via an MCMS resource request for image files or other files.
15133| [CVE-2002-0718] Web authoring command in Microsoft Content Management Server (MCMS) 2001 allows attackers to authenticate and upload executable content, by modifying the upload location, aka "Program Execution via MCMS Authoring Function."
15134| [CVE-2002-0700] Buffer overflow in a system function that performs user authentication for Microsoft Content Management Server (MCMS) 2001 allows attackers to execute code in the Local System context by authenticating to a web page that calls the function, aka "Unchecked Buffer in MDAC Function Could Enable SQL Server Compromise."
15135| [CVE-2002-0699] Unknown vulnerability in the Certificate Enrollment ActiveX Control in Microsoft Windows 98, Windows 98 Second Edition, Windows Millennium, Windows NT 4.0, Windows 2000, and Windows XP allow remote attackers to delete digital certificates on a user's system via HTML.
15136| [CVE-2002-0695] Buffer overflow in the Transact-SQL (T-SQL) OpenRowSet component of Microsoft Data Access Components (MDAC) 2.5 through 2.7 for SQL Server 7.0 or 2000 allows remote attackers to execute arbitrary code via a query that calls the OpenRowSet command.
15137| [CVE-2002-0694] The HTML Help facility in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP uses the Local Computer Security Zone when opening .chm files from the Temporary Internet Files folder, which allows remote attackers to execute arbitrary code via HTML mail that references or inserts a malicious .chm file containing shortcuts that can be executed, aka "Code Execution via Compiled HTML Help File."
15138| [CVE-2002-0693] Buffer overflow in the HTML Help ActiveX Control (hhctrl.ocx) in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute code via (1) a long parameter to the Alink function, or (2) script containing a long argument to the showHelp function.
15139| [CVE-2002-0692] Buffer overflow in SmartHTML Interpreter (shtml.dll) in Microsoft FrontPage Server Extensions (FPSE) 2000 and 2002 allows remote attackers to cause a denial of service (CPU consumption) or run arbitrary code, respectively, via a certain type of web file request.
15140| [CVE-2002-0650] The keep-alive mechanism for Microsoft SQL Server 2000 allows remote attackers to cause a denial of service (bandwidth consumption) via a "ping" style packet to the Resolution Service (UDP port 1434) with a spoofed IP address of another SQL Server system, which causes the two servers to exchange packets in an infinite loop.
15141| [CVE-2002-0649] Multiple buffer overflows in the Resolution Service for Microsoft SQL Server 2000 and Microsoft Desktop Engine 2000 (MSDE) allow remote attackers to cause a denial of service or execute arbitrary code via UDP packets to port 1434 in which (1) a 0x04 byte that causes the SQL Monitor thread to generate a long registry key name, or (2) a 0x08 byte with a long string causes heap corruption, as exploited by the Slammer/Sapphire worm.
15142| [CVE-2002-0645] SQL injection vulnerability in stored procedures for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 may allow authenticated users to execute arbitrary commands.
15143| [CVE-2002-0644] Buffer overflow in several Database Consistency Checkers (DBCCs) for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 allows members of the db_owner and db_ddladmin roles to execute arbitrary code.
15144| [CVE-2002-0643] The installation of Microsoft Data Engine 1.0 (MSDE 1.0), and Microsoft SQL Server 2000 creates setup.iss files with insecure permissions and does not delete them after installation, which allows local users to obtain sensitive data, including weakly encrypted passwords, to gain privileges, aka "SQL Server Installation Process May Leave Passwords on System."
15145| [CVE-2002-0642] The registry key containing the SQL Server service account information in Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, has insecure permissions, which allows local users to gain privileges, aka "Incorrect Permission on SQL Server Service Account Registry Key."
15146| [CVE-2002-0641] Buffer overflow in bulk insert procedure of Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, allows attackers with database administration privileges to execute arbitrary code via a long filename in the BULK INSERT query.
15147| [CVE-2002-0624] Buffer overflow in the password encryption function of Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, allows remote attackers to gain control of the database and execute arbitrary code via SQL Server Authentication, aka "Unchecked Buffer in Password Encryption Procedure."
15148| [CVE-2002-0623] Buffer overflow in AuthFilter ISAPI filter on Microsoft Commerce Server 2000 and 2002 allows remote attackers to execute arbitrary code via long authentication data, aka "New Variant of the ISAPI Filter Buffer Overrun".
15149| [CVE-2002-0622] The Office Web Components (OWC) package installer for Microsoft Commerce Server 2000 allows remote attackers to execute commands by passing the commands as input to the OWC package installer, aka "OWC Package Command Execution".
15150| [CVE-2002-0621] Buffer overflow in the Office Web Components (OWC) package installer used by Microsoft Commerce Server 2000 allows remote attackers to cause the process to fail or run arbitrary code in the LocalSystem security context via certain input to the OWC package installer.
15151| [CVE-2002-0620] Buffer overflow in the Profile Service of Microsoft Commerce Server 2000 allows remote attackers to cause the server to fail or run arbitrary code in the LocalSystem security context via an input field using an affected API.
15152| [CVE-2002-0619] The Mail Merge Tool in Microsoft Word 2002 for Windows, when Microsoft Access is present on a system, allows remote attackers to execute Visual Basic (VBA) scripts within a mail merge document that is saved in HTML format, aka a "Variant of MS00-071, Word Mail Merge Vulnerability" (CVE-2000-0788).
15153| [CVE-2002-0618] The Macro Security Model in Microsoft Excel 2000 and 2002 for Windows allows remote attackers to execute code in the Local Computer zone by embedding HTML scripts within an Excel workbook that contains an XSL stylesheet, aka "Excel XSL Stylesheet Script Execution".
15154| [CVE-2002-0617] The Macro Security Model in Microsoft Excel 2000 and 2002 for Windows allows remote attackers to execute code by creating a hyperlink on a drawing shape in a source workbook that points to a destination workbook containing an autoexecute macro, aka "Hyperlinked Excel Workbook Macro Bypass."
15155| [CVE-2002-0616] The Macro Security Model in Microsoft Excel 2000 and 2002 for Windows allows remote attackers to execute code by attaching an inline macro to an object within an Excel workbook, aka the "Excel Inline Macros Vulnerability."
15156| [CVE-2002-0597] LANMAN service on Microsoft Windows 2000 allows remote attackers to cause a denial of service (CPU/memory exhaustion) via a stream of malformed data to microsoft-ds port 445.
15157| [CVE-2002-0444] Microsoft Windows 2000 running the Terminal Server 90-day trial version, and possibly other versions, does not apply group policies to incoming users when the number of connections to the SYSVOL share exceeds the maximum, e.g. with a maximum number of licenses, which can allow remote authenticated users to bypass group policies.
15158| [CVE-2002-0443] Microsoft Windows 2000 allows local users to bypass the policy that prohibits reusing old passwords by changing the current password before it expires, which does not enable the check for previous passwords.
15159| [CVE-2002-0373] The Windows Media Device Manager (WMDM) Service in Microsoft Windows Media Player 7.1 on Windows 2000 systems allows local users to obtain LocalSystem rights via a program that calls the WMDM service to connect to an invalid local storage device, aka "Privilege Elevation through Windows Media Device Manager Service".
15160| [CVE-2002-0371] Buffer overflow in gopher client for Microsoft Internet Explorer 5.1 through 6.0, Proxy Server 2.0, or ISA Server 2000 allows remote attackers to execute arbitrary code via a gopher:// URL that redirects the user to a real or simulated gopher server that sends a long response.
15161| [CVE-2002-0368] The Store Service in Microsoft Exchange 2000 allows remote attackers to cause a denial of service (CPU consumption) via a mail message with a malformed RFC message attribute, aka "Malformed Mail Attribute can Cause Exchange 2000 to Exhaust CPU Resources."
15162| [CVE-2002-0224] The MSDTC (Microsoft Distributed Transaction Service Coordinator) for Microsoft Windows 2000, Microsoft IIS 5.0 and SQL Server 6.5 through SQL 2000 0.0 allows remote attackers to cause a denial of service (crash or hang) via malformed (random) input.
15163| [CVE-2002-0187] Cross-site scripting vulnerability in the SQLXML component of Microsoft SQL Server 2000 allows an attacker to execute arbitrary script via the root parameter as part of an XML SQL query, aka "Script Injection via XML Tag."
15164| [CVE-2002-0186] Buffer overflow in the SQLXML ISAPI extension of Microsoft SQL Server 2000 allows remote attackers to execute arbitrary code via data queries with a long content-type parameter, aka "Unchecked Buffer in SQLXML ISAPI Extension."
15165| [CVE-2002-0154] Buffer overflows in extended stored procedures for Microsoft SQL Server 7.0 and 2000 allow remote attackers to cause a denial of service or execute arbitrary code via a database query with certain long arguments.
15166| [CVE-2002-0152] Buffer overflow in various Microsoft applications for Macintosh allows remote attackers to cause a denial of service (crash) or execute arbitrary code by invoking the file:// directive with a large number of / characters, which affects Internet Explorer 5.1, Outlook Express 5.0 through 5.0.2, Entourage v. X and 2001, PowerPoint v. X, 2001, and 98, and Excel v. X and 2001 for Macintosh.
15167| [CVE-2002-0055] SMTP service in Microsoft Windows 2000, Windows XP Professional, and Exchange 2000 allows remote attackers to cause a denial of service via a command with a malformed data transfer (BDAT) request.
15168| [CVE-2002-0054] SMTP service in (1) Microsoft Windows 2000 and (2) Internet Mail Connector (IMC) in Exchange Server 5.5 does not properly handle responses to NTLM authentication, which allows remote attackers to perform mail relaying via an SMTP AUTH command using null session credentials.
15169| [CVE-2002-0050] Buffer overflow in AuthFilter ISAPI filter on Microsoft Commerce Server 2000 allows remote attackers to execute arbitrary code via long authentication data.
15170| [CVE-2002-0049] Microsoft Exchange Server 2000 System Attendant gives "Everyone" group privileges to the WinReg key, which could allow remote attackers to read or modify registry keys.
15171| [CVE-2002-0034] The Microsoft CONVERT.EXE program, when used on Windows 2000 and Windows XP systems, does not apply the default NTFS permissions when converting a FAT32 file system, which could cause the conversion to produce a file system with less secure permissions than expected.
15172| [CVE-2002-0018] In Microsoft Windows NT and Windows 2000, a trusting domain that receives authorization information from a trusted domain does not verify that the trusted domain is authoritative for all listed SIDs, which allows remote attackers to gain Domain Administrator privileges on the trusting domain by injecting SIDs from untrusted domains into the authorization data that comes from from the trusted domain.
15173| [CVE-2001-1533] ** DISPUTED * Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service via a flood of fragmented UDP packets. NOTE: the vendor disputes this issue, saying that it requires high bandwidth to exploit, and the server does not experience any instability. Therefore this "laws of physics" issue might not be included in CVE.
15174| [CVE-2001-1451] Memory leak in the SNMP LAN Manager (LANMAN) MIB extension for Microsoft Windows 2000 before SP3, when the Print Spooler is not running, allows remote attackers to cause a denial of service (memory consumption) via a large number of GET or GETNEXT requests.
15175| [CVE-2001-1319] Microsoft Exchange 5.5 2000 allows remote attackers to cause a denial of service (hang) via exceptional BER encodings for the LDAP filter type field, as demonstrated by the PROTOS LDAPv3 test suite.
15176| [CVE-2001-1099] The default configuration of Norton AntiVirus for Microsoft Exchange 2000 2.x allows remote attackers to identify the recipient's INBOX file path by sending an email with an attachment containing malicious content, which includes the path in the rejection notice.
15177| [CVE-2001-0986] SQLQHit.asp sample file in Microsoft Index Server 2.0 allows remote attackers to obtain sensitive information such as the physical path, file attributes, or portions of source code by directly calling sqlqhit.asp with a CiScope parameter set to (1) webinfo, (2) extended_fileinfo, (3) extended_webinfo, or (4) fileinfo.
15178| [CVE-2001-0718] Vulnerability in (1) Microsoft Excel 2002 and earlier and (2) Microsoft PowerPoint 2002 and earlier allows attackers to bypass macro restrictions and execute arbitrary commands by modifying the data stream in the document.
15179| [CVE-2001-0666] Outlook Web Access (OWA) in Microsoft Exchange 2000 allows an authenticated user to cause a denial of service (CPU consumption) via a malformed OWA request for a deeply nested folder within the user's mailbox.
15180| [CVE-2001-0658] Cross-site scripting (CSS) vulnerability in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause other clients to execute certain script or read cookies via malicious script in an invalid URL that is not properly quoted in an error message.
15181| [CVE-2001-0628] Microsoft Word 2000 does not check AutoRecovery (.asd) files for macros, which allows a local attacker to execute arbitrary macros with the user ID of the Word user.
15182| [CVE-2001-0547] Memory leak in the proxy service in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows local attackers to cause a denial of service (resource exhaustion).
15183| [CVE-2001-0546] Memory leak in H.323 Gatekeeper Service in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service (resource exhaustion) via a large amount of malformed H.323 data.
15184| [CVE-2001-0542] Buffer overflows in Microsoft SQL Server 7.0 and 2000 allow attackers with access to SQL Server to execute arbitrary code through the functions (1) raiserror, (2) formatmessage, or (3) xp_sprintf. NOTE: the C runtime format string vulnerability reported in MS01-060 is identified by CVE-2001-0879.
15185| [CVE-2001-0538] Microsoft Outlook View ActiveX Control in Microsoft Outlook 2002 and earlier allows remote attackers to execute arbitrary commands via a malicious HTML e-mail message or web page.
15186| [CVE-2001-0509] Vulnerabilities in RPC servers in (1) Microsoft Exchange Server 2000 and earlier, (2) Microsoft SQL Server 2000 and earlier, (3) Windows NT 4.0, and (4) Windows 2000 allow remote attackers to cause a denial of service via malformed inputs.
15187| [CVE-2001-0505] Multiple memory leaks in Microsoft Services for Unix 2.0 allow remote attackers to cause a denial of service (memory exhaustion) via a large number of malformed requests to (1) the Telnet service, or (2) the NFS service.
15188| [CVE-2001-0504] Vulnerability in authentication process for SMTP service in Microsoft Windows 2000 allows remote attackers to use incorrect credentials to gain privileges and conduct activites such as mail relaying.
15189| [CVE-2001-0501] Microsoft Word 2002 and earlier allows attackers to automatically execute macros without warning the user by embedding the macros in a manner that escapes detection by the security scanner.
15190| [CVE-2001-0351] Microsoft Windows 2000 telnet service allows a local user to make a certain system call that allows the user to terminate a Telnet session and cause a denial of service.
15191| [CVE-2001-0350] Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, which allows local users to execute arbitrary commands by creating a named pipe with the predictable name and associating a malicious program with it, the second of two variants of this vulnerability.
15192| [CVE-2001-0349] Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, which allows local users to execute arbitrary commands by creating a named pipe with the predictable name and associating a malicious program with it, the first of two variants of this vulnerability.
15193| [CVE-2001-0348] Microsoft Windows 2000 telnet service allows attackers to cause a denial of service (crash) via a long logon command that contains a backspace.
15194| [CVE-2001-0347] Information disclosure vulnerability in Microsoft Windows 2000 telnet service allows remote attackers to determine the existence of user accounts such as Guest, or log in to the server without specifying the domain name, via a malformed userid.
15195| [CVE-2001-0346] Handle leak in Microsoft Windows 2000 telnet service allows attackers to cause a denial of service by starting a large number of sessions and terminating them.
15196| [CVE-2001-0345] Microsoft Windows 2000 telnet service allows attackers to prevent idle Telnet sessions from timing out, causing a denial of service by creating a large number of idle sessions.
15197| [CVE-2001-0344] An SQL query method in Microsoft SQL Server 2000 Gold and 7.0 using Mixed Mode allows local database users to gain privileges by reusing a cached connection of the sa administrator account.
15198| [CVE-2001-0340] An interaction between the Outlook Web Access (OWA) service in Microsoft Exchange 2000 Server and Internet Explorer allows attackers to execute malicious script code against a user's mailbox via a message attachment that contains HTML code, which is executed automatically.
15199| [CVE-2001-0261] Microsoft Windows 2000 Encrypted File System does not properly destroy backups of files that are encrypted, which allows a local attacker to recover the text of encrypted files.
15200| [CVE-2001-0245] Microsoft Index Server 2.0 in Windows NT 4.0, and Indexing Service in Windows 2000, allows remote attackers to read server-side include files via a malformed search request, aka a new variant of the "Malformed Hit-Highlighting" vulnerability.
15201| [CVE-2001-0244] Buffer overflow in Microsoft Index Server 2.0 allows remote attackers to execute arbitrary commands via a long search parameter.
15202| [CVE-2001-0240] Microsoft Word before Word 2002 allows attackers to automatically execute macros without warning the user via a Rich Text Format (RTF) document that links to a template with the embedded macro.
15203| [CVE-2001-0239] Microsoft Internet Security and Acceleration (ISA) Server 2000 Web Proxy allows remote attackers to cause a denial of service via a long web request with a specific type.
15204| [CVE-2001-0237] Memory leak in Microsoft 2000 domain controller allows remote attackers to cause a denial of service by repeatedly connecting to the Kerberos service and then disconnecting without sending any data.
15205| [CVE-2001-0146] IIS 5.0 and Microsoft Exchange 2000 allow remote attackers to cause a denial of service (memory allocation error) by repeatedly sending a series of specially formatted URL's.
15206| [CVE-2001-0048] The "Configure Your Server" tool in Microsoft 2000 domain controllers installs a blank password for the Directory Service Restore Mode, which allows attackers with physical access to the controller to install malicious programs, aka the "Directory Service Restore Mode Password" vulnerability.
15207| [CVE-2001-0005] Buffer overflow in the parsing mechanism of the file loader in Microsoft PowerPoint 2000 allows attackers to execute arbitrary commands.
15208| [CVE-2001-0003] Web Extender Client (WEC) in Microsoft Office 2000, Windows 2000, and Windows Me does not properly process Internet Explorer security settings for NTLM authentication, which allows attackers to obtain NTLM credentials and possibly obtain the password, aka the "Web Client NTLM Authentication" vulnerability.
15209| [CVE-2000-1218] The default configuration for the domain name resolver for Microsoft Windows 98, NT 4.0, 2000, and XP sets the QueryIpMatching parameter to 0, which causes Windows to accept DNS updates from hosts that it did not query, which allows remote attackers to poison the DNS cache.
15210| [CVE-2000-1217] Microsoft Windows 2000 before Service Pack 2 (SP2), when running in a non-Windows 2000 domain and using NTLM authentication, and when credentials of an account are locally cached, allows local users to bypass account lockout policies and make an unlimited number of login attempts, aka the "Domain Account Lockout" vulnerability.
15211| [CVE-2000-1209] The "sa" account is installed with a default null password on (1) Microsoft SQL Server 2000, (2) SQL Server 7.0, and (3) Data Engine (MSDE) 1.0, including third party packages that use these products such as (4) Tumbleweed Secure Mail (MMS) (5) Compaq Insight Manager, and (6) Visio 2000, which allows remote attackers to gain privileges, as exploited by worms such as Voyager Alpha Force and Spida.
15212| [CVE-2000-1139] The installation of Microsoft Exchange 2000 before Rev. A creates a user account with a known password, which could allow attackers to gain privileges, aka the "Exchange User Account" vulnerability.
15213| [CVE-2000-1088] The xp_SetSQLSecurity function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.
15214| [CVE-2000-1087] The xp_proxiedmetadata function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.
15215| [CVE-2000-1086] The xp_printstatements function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.
15216| [CVE-2000-1085] The xp_peekqueue function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.
15217| [CVE-2000-1079] Interactions between the CIFS Browser Protocol and NetBIOS as implemented in Microsoft Windows 95, 98, NT, and 2000 allow remote attackers to modify dynamic NetBIOS name cache entries via a spoofed Browse Frame Request in a unicast or UDP broadcast datagram.
15218| [CVE-2000-0942] The CiWebHitsFile component in Microsoft Indexing Services for Windows 2000 allows remote attackers to conduct a cross site scripting (CSS) attack via a CiRestriction parameter in a .htw request, aka the "Indexing Services Cross Site Scripting" vulnerability.
15219| [CVE-2000-0854] When a Microsoft Office 2000 document is launched, the directory of that document is first used to locate DLL's such as riched20.dll and msi.dll, which could allow an attacker to execute arbitrary commands by inserting a Trojan Horse DLL into the same directory as the document.
15220| [CVE-2000-0771] Microsoft Windows 2000 allows local users to cause a denial of service by corrupting the local security policy via malformed RPC traffic, aka the "Local Security Policy Corruption" vulnerability.
15221| [CVE-2000-0765] Buffer overflow in the HTML interpreter in Microsoft Office 2000 allows an attacker to execute arbitrary commands via a long embedded object tag, aka the "Microsoft Office HTML Object Tag" vulnerability.
15222| [CVE-2000-0756] Microsoft Outlook 2000 does not properly process long or malformed fields in vCard (.vcf) files, which allows attackers to cause a denial of service.
15223| [CVE-2000-0710] The shtml.exe component of Microsoft FrontPage 2000 Server Extensions 1.1 allows remote attackers determine the physical path of the server components by requesting an invalid URL whose name includes a standard DOS device name.
15224| [CVE-2000-0709] The shtml.exe component of Microsoft FrontPage 2000 Server Extensions 1.1 allows remote attackers to cause a denial of service in some components by requesting a URL whose name includes a standard DOS device name.
15225| [CVE-2000-0637] Microsoft Excel 97 and 2000 allows an attacker to execute arbitrary commands by specifying a malicious .dll using the Register.ID function, aka the "Excel REGISTER.ID Function" vulnerability.
15226| [CVE-2000-0621] Microsoft Outlook 98 and 2000, and Outlook Express 4.0x and 5.0x, allow remote attackers to read files on the client's system via a malformed HTML message that stores files outside of the cache, aka the "Cache Bypass" vulnerability.
15227| [CVE-2000-0597] Microsoft Office 2000 (Excel and PowerPoint) and PowerPoint 97 are marked as safe for scripting, which allows remote attackers to force Internet Explorer or some email clients to save files to arbitrary locations via the Visual Basic for Applications (VBA) SaveAs function, aka the "Office HTML Script" vulnerability.
15228| [CVE-2000-0331] Buffer overflow in Microsoft command processor (CMD.EXE) for Windows NT and Windows 2000 allows a local user to cause a denial of service via a long environment variable, aka the "Malformed Environment Variable" vulnerability.
15229| [CVE-2000-0277] Microsoft Excel 97 and 2000 does not warn the user when executing Excel Macro Language (XLM) macros in external text files, which could allow an attacker to execute a macro virus, aka the "XLM Text Macro" vulnerability.
15230| [CVE-2013-2557] The sandbox protection mechanism in Microsoft Internet Explorer 9 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, as demonstrated against Adobe Flash Player by VUPEN during a Pwn2Own competition at CanSecWest 2013.
15231| [CVE-2013-2556] Unspecified vulnerability in Microsoft Windows 7 allows attackers to bypass the ASLR protection mechanism via unknown vectors, as demonstrated against Adobe Flash Player by VUPEN during a Pwn2Own competition at CanSecWest 2013.
15232| [CVE-2013-2554] Unspecified vulnerability in Microsoft Windows 7 allows attackers to bypass the ASLR and DEP protection mechanisms via unknown vectors, as demonstrated against Firefox by VUPEN during a Pwn2Own competition at CanSecWest 2013, a different vulnerability than CVE-2013-0787.
15233| [CVE-2013-2553] Unspecified vulnerability in the kernel in Microsoft Windows 7 allows local users to gain privileges via unknown vectors, as demonstrated by Nils and Jon of MWR Labs during a Pwn2Own competition at CanSecWest 2013, a different vulnerability than CVE-2013-0912.
15234| [CVE-2013-2552] Unspecified vulnerability in Microsoft Internet Explorer 10 on Windows 8 allows remote attackers to bypass the sandbox protection mechanism by leveraging access to a Medium integrity process, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2013.
15235| [CVE-2013-2551] Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2013, aka "Internet Explorer Use After Free Vulnerability," a different vulnerability than CVE-2013-1308 and CVE-2013-1309.
15236| [CVE-2013-1347] Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly allocated or (2) is deleted, as exploited in the wild in May 2013.
15237| [CVE-2013-1305] HTTP.sys in Microsoft Windows 8, Windows Server 2012, and Windows RT allows remote attackers to cause a denial of service (infinite loop) via a crafted HTTP header, aka "HTTP.sys Denial of Service Vulnerability."
15238| [CVE-2013-1290] Microsoft SharePoint Server 2013, in certain configurations involving legacy My Sites, does not properly establish default access controls for a SharePoint list, which allows remote authenticated users to bypass intended restrictions on reading list items via a direct request for a list's location, aka "Incorrect Access Rights Information Disclosure Vulnerability."
15239| [CVE-2013-1289] Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2010 SP1, Groove Server 2010 SP1, SharePoint Foundation 2010 SP1, and Office Web Apps 2010 SP1 allows remote attackers to inject arbitrary web script or HTML via a crafted string, aka "HTML Sanitization Vulnerability."
15240| [CVE-2013-1284] Race condition in the kernel in Microsoft Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages improper handling of objects in memory, aka "Kernel Race Condition Vulnerability."
15241| [CVE-2013-0096] Writer in Microsoft Windows Essentials 2011 and 2012 allows remote attackers to bypass proxy settings and overwrite arbitrary files via crafted URL parameters, aka "Windows Essentials Improper URI Handling Vulnerability."
15242| [CVE-2013-0086] Microsoft OneNote 2010 SP1 does not properly determine buffer sizes during memory allocation, which allows remote attackers to obtain sensitive information via a crafted OneNote file, aka "Buffer Size Validation Vulnerability."
15243| [CVE-2013-0085] Buffer overflow in Microsoft SharePoint Server 2010 SP1 and SharePoint Foundation 2010 SP1 allows remote attackers to cause a denial of service (W3WP process crash and site outage) via a crafted URL, aka "Buffer Overflow Vulnerability."
15244| [CVE-2013-0084] Directory traversal vulnerability in Microsoft SharePoint Server 2010 SP1 and SharePoint Foundation 2010 SP1 allows remote attackers to bypass intended read restrictions for content, and hijack user accounts, via a crafted URL, aka "SharePoint Directory Traversal Vulnerability."
15245| [CVE-2013-0083] Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2010 SP1 allows remote attackers to inject arbitrary web script or HTML via crafted content, leading to administrative command execution, aka "SharePoint XSS Vulnerability."
15246| [CVE-2013-0080] Microsoft SharePoint Server 2010 SP1 and SharePoint Foundation 2010 SP1 allow remote attackers to bypass intended read restrictions for content, and hijack user accounts, via a crafted URL, aka "Callback Function Vulnerability."
15247| [CVE-2013-0079] Microsoft Visio Viewer 2010 SP1 allows remote attackers to execute arbitrary code via a crafted Visio file that triggers incorrect memory allocation, aka "Visio Viewer Tree Object Type Confusion Vulnerability."
15248| [CVE-2013-0005] The WCF Replace function in the Open Data (aka OData) protocol implementation in Microsoft .NET Framework 3.5, 3.5 SP1, 3.5.1, and 4, and the Management OData IIS Extension on Windows Server 2012, allows remote attackers to cause a denial of service (resource consumption and daemon restart) via crafted values in HTTP requests, aka "Replace Denial of Service Vulnerability."
15249| [CVE-2012-4969] Use-after-free vulnerability in the CMshtmlEd::Exec function in mshtml.dll in Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code via a crafted web site, as exploited in the wild in September 2012.
15250| [CVE-2012-4792] Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not properly allocated or (2) is deleted, as demonstrated by a CDwnBindInfo object, and exploited in the wild in December 2012.
15251| [CVE-2012-3456] Heap-based buffer overflow in the read function in filters/words/msword-odf/wv2/src/styles.cpp in the Microsoft import filter in Calligra 2.4.3 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted ODF style in an ODF document. NOTE: this is the same vulnerability as CVE-2012-3455, but it was SPLIT by the CNA even though Calligra and KOffice share the same codebase.
15252| [CVE-2012-3455] Heap-based buffer overflow in the read function in filters/words/msword-odf/wv2/src/styles.cpp in the Microsoft import filter in KOffice 2.3.3 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted ODF style in an ODF document. NOTE: this is the same vulnerability as CVE-2012-3456, but it was SPLIT by the CNA even though Calligra and KOffice share the same codebase.
15253| [CVE-2012-2290] The client in EMC NetWorker Module for Microsoft Applications (NMM) 2.2.1, 2.3 before build 122, and 2.4 before build 375 allows remote attackers to execute arbitrary code by sending a crafted message over a TCP communication channel.
15254| [CVE-2012-2284] The (1) install and (2) upgrade processes in EMC NetWorker Module for Microsoft Applications (NMM) 2.2.1, 2.3 before build 122, and 2.4 before build 375, when Exchange Server is used, allow local users to read cleartext administrator credentials via unspecified vectors.
15255| [CVE-2012-1945] Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 allow local users to obtain sensitive information via an HTML document that loads a shortcut (aka .lnk) file for display within an IFRAME element, as demonstrated by a network share implemented by (1) Microsoft Windows or (2) Samba.
15256| [CVE-2012-1894] Microsoft Office for Mac 2011 uses world-writable permissions for the "Applications/Microsoft Office 2011/" directory and certain other directories, which allows local users to gain privileges by placing a Trojan horse executable file in one of these directories, aka "Office for Mac Improper Folder Permissions Vulnerability."
15257| [CVE-2012-1892] Cross-site scripting (XSS) vulnerability in Microsoft Visual Studio Team Foundation Server 2010 SP1 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka "XSS Vulnerability."
15258| [CVE-2012-1891] Heap-based buffer overflow in Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2 and Windows Data Access Components (WDAC) 6.0 allows remote attackers to execute arbitrary code via crafted XML data that triggers access to an uninitialized object in memory, aka "ADO Cachesize Heap Overflow RCE Vulnerability."
15259| [CVE-2012-1888] Buffer overflow in Microsoft Visio 2010 SP1 and Visio Viewer 2010 SP1 allows remote attackers to execute arbitrary code via a crafted Visio file, aka "Visio DXF File Format Buffer Overflow Vulnerability."
15260| [CVE-2012-1876] Microsoft Internet Explorer 6 through 9, and 10 Consumer Preview, does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by attempting to access a nonexistent object, leading to a heap-based buffer overflow, aka "Col Element Remote Code Execution Vulnerability," as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2012.
15261| [CVE-2012-1861] Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2010 Gold and SP1, SharePoint Foundation 2010 Gold and SP1, and Office Web Apps 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via crafted JavaScript elements in a URL, aka "SharePoint Script in Username Vulnerability."
15262| [CVE-2012-1859] Cross-site scripting (XSS) vulnerability in scriptresx.ashx in Microsoft SharePoint Server 2010 Gold and SP1, SharePoint Foundation 2010 Gold and SP1, and Office Web Apps 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via crafted JavaScript elements in a URL, aka "XSS scriptresx.ashx Vulnerability."
15263| [CVE-2012-1857] Cross-site scripting (XSS) vulnerability in the Enterprise Portal component in Microsoft Dynamics AX 2012 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "Dynamics AX Enterprise Portal XSS Vulnerability."
15264| [CVE-2012-1849] Untrusted search path vulnerability in Microsoft Lync 2010, 2010 Attendee, and 2010 Attendant allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .ocsmeet file, aka "Lync Insecure Library Loading Vulnerability."
15265| [CVE-2012-1545] Microsoft Internet Explorer 6 through 9, and 10 Consumer Preview, allows remote attackers to bypass Protected Mode or cause a denial of service (memory corruption) by leveraging access to a Low integrity process, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2012.
15266| [CVE-2012-1436] The Microsoft EXE file parser in AhnLab V3 Internet Security 2011.01.18.00, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an EXE file with a \2D\6C\68 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different EXE parser implementations.
15267| [CVE-2012-1435] The Microsoft EXE file parser in AhnLab V3 Internet Security 2011.01.18.00, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an EXE file with a \50\4B\4C\49\54\45 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different EXE parser implementations.
15268| [CVE-2012-1434] The Microsoft EXE file parser in AhnLab V3 Internet Security 2011.01.18.00, Emsisoft Anti-Malware 5.1.0.1, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an EXE file with a \19\04\00\10 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different EXE parser implementations.
15269| [CVE-2012-1433] The Microsoft EXE file parser in AhnLab V3 Internet Security 2011.01.18.00, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an EXE file with a \4a\46\49\46 character sequence at a certain location. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different EXE parser implementations.
15270| [CVE-2012-0447] Mozilla Firefox 4.x through 9.0, Thunderbird 5.0 through 9.0, and SeaMonkey before 2.7 do not properly initialize data for image/vnd.microsoft.icon images, which allows remote attackers to obtain potentially sensitive information by reading a PNG image that was created through conversion from an ICO image.
15271| [CVE-2012-0147] Microsoft Forefront Unified Access Gateway (UAG) 2010 SP1 and SP1 Update 1 does not properly configure the default web site, which allows remote attackers to obtain sensitive information via a crafted HTTPS request, aka "Unfiltered Access to UAG Default Website Vulnerability."
15272| [CVE-2012-0146] Open redirect vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 SP1 and SP1 Update 1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL, aka "UAG Blind HTTP Redirect Vulnerability."
15273| [CVE-2012-0145] Cross-site scripting (XSS) vulnerability in wizardlist.aspx in Microsoft Office SharePoint Server 2010 Gold and SP1 and SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via JavaScript sequences in a URL, aka "XSS in wizardlist.aspx Vulnerability."
15274| [CVE-2012-0144] Cross-site scripting (XSS) vulnerability in themeweb.aspx in Microsoft Office SharePoint Server 2010 Gold and SP1 and SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via JavaScript sequences in a URL, aka "XSS in themeweb.aspx Vulnerability."
15275| [CVE-2012-0138] Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitrary code via crafted attributes in a Visio file, aka "VSD File Format Memory Corruption Vulnerability," a different vulnerability than CVE-2012-0019, CVE-2012-0020, CVE-2012-0136, and CVE-2012-0137.
15276| [CVE-2012-0137] Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitrary code via crafted attributes in a Visio file, aka "VSD File Format Memory Corruption Vulnerability," a different vulnerability than CVE-2012-0019, CVE-2012-0020, CVE-2012-0136, and CVE-2012-0138.
15277| [CVE-2012-0136] Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitrary code via crafted attributes in a Visio file, aka "VSD File Format Memory Corruption Vulnerability," a different vulnerability than CVE-2012-0019, CVE-2012-0020, CVE-2012-0137, and CVE-2012-0138.
15278| [CVE-2012-0020] Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitrary code via crafted attributes in a Visio file, aka "VSD File Format Memory Corruption Vulnerability," a different vulnerability than CVE-2012-0019, CVE-2012-0136, CVE-2012-0137, and CVE-2012-0138.
15279| [CVE-2012-0019] Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitrary code via crafted attributes in a Visio file, aka "VSD File Format Memory Corruption Vulnerability," a different vulnerability than CVE-2012-0020, CVE-2012-0136, CVE-2012-0137, and CVE-2012-0138.
15280| [CVE-2012-0018] Microsoft Visio Viewer 2010 Gold and SP1 does not properly validate attributes in Visio files, which allows remote attackers to execute arbitrary code via a crafted file, aka "VSD File Format Memory Corruption Vulnerability."
15281| [CVE-2012-0017] Cross-site scripting (XSS) vulnerability in inplview.aspx in Microsoft SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via JavaScript sequences in a URL, aka "XSS in inplview.aspx Vulnerability."
15282| [CVE-2011-4695] Unspecified vulnerability in Microsoft Windows 7 SP1, when Java is installed, allows local users to bypass Internet Explorer sandbox restrictions and gain privileges via unknown vectors, as demonstrated by the White Phosphorus wp_ie_sandbox_escape module for Immunity CANVAS. NOTE: as of 20111207, this disclosure has no actionable information. However, because the module author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.
15283| [CVE-2011-2012] Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 does not properly validate session cookies, which allows remote attackers to cause a denial of service (IIS outage) via unspecified network traffic, aka "Null Session Cookie Crash."
15284| [CVE-2011-2010] The Microsoft Office Input Method Editor (IME) for Simplified Chinese in Microsoft Pinyin IME 2010, Office Pinyin SimpleFast Style 2010, and Office Pinyin New Experience Style 2010 does not properly restrict access to configuration options, which allows local users to gain privileges via the Microsoft Pinyin (aka MSPY) IME toolbar, aka "Pinyin IME Elevation Vulnerability."
15285| [CVE-2011-1969] Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 provides the MicrosoftClient.jar file containing a signed Java applet, which allows remote attackers to execute arbitrary code on client machines via unspecified vectors, aka "Poisoned Cup of Code Execution Vulnerability."
15286| [CVE-2011-1897] Cross-site scripting (XSS) vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Default Reflected XSS Vulnerability."
15287| [CVE-2011-1896] Cross-site scripting (XSS) vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "ExcelTable Reflected XSS Vulnerability."
15288| [CVE-2011-1895] CRLF injection vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 allows remote attackers to inject arbitrary HTTP headers, and conduct HTTP response splitting attacks and cross-site scripting (XSS) attacks, via unspecified vectors, aka "ExcelTable Response Splitting XSS Vulnerability."
15289| [CVE-2011-1891] Cross-site scripting (XSS) vulnerability in Microsoft Windows SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and SP1, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters in a request to a script, aka "Contact Details Reflected XSS Vulnerability."
15290| [CVE-2011-1890] Cross-site scripting (XSS) vulnerability in EditForm.aspx in Microsoft Office SharePoint Server 2010 and SharePoint Foundation 2010 allows remote attackers to inject arbitrary web script or HTML via a post, aka "Editform Script Injection Vulnerability."
15291| [CVE-2011-1889] The NSPLookupServiceNext function in the client in Microsoft Forefront Threat Management Gateway (TMG) 2010 allows remote attackers to execute arbitrary code via vectors involving unspecified requests, aka "TMG Firewall Client Memory Corruption Vulnerability."
15292| [CVE-2011-1417] Integer overflow in QuickLook, as used in Apple Mac OS X before 10.6.7 and MobileSafari in Apple iOS before 4.2.7 and 4.3.x before 4.3.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a Microsoft Office document with a crafted size field in the OfficeArtMetafileHeader, related to OfficeArtBlip, as demonstrated on the iPhone by Charlie Miller and Dion Blazakis during a Pwn2Own competition at CanSecWest 2011.
15293| [CVE-2011-1347] Unspecified vulnerability in Microsoft Internet Explorer 8 on Windows 7 allows remote attackers to bypass Protected Mode and create arbitrary files by leveraging access to a Low integrity process, as demonstrated by Stephen Fewer as the third of three chained vulnerabilities during a Pwn2Own competition at CanSecWest 2011.
15294| [CVE-2011-1346] Unspecified vulnerability in Microsoft Internet Explorer 8 on Windows 7 allows remote attackers to execute arbitrary code via unknown vectors, as demonstrated by Stephen Fewer as the second of three chained vulnerabilities during a Pwn2Own competition at CanSecWest 2011.
15295| [CVE-2011-1345] Microsoft Internet Explorer 6, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, as demonstrated by Stephen Fewer as the first of three chained vulnerabilities during a Pwn2Own competition at CanSecWest 2011, aka "Object Management Memory Corruption Vulnerability."
15296| [CVE-2011-1265] The Bluetooth Stack 2.1 in Microsoft Windows Vista SP1 and SP2 and Windows 7 Gold and SP1 does not prevent access to objects in memory that (1) were not properly initialized or (2) have been deleted, which allows remote attackers to execute arbitrary code via crafted Bluetooth packets, aka "Bluetooth Stack Vulnerability."
15297| [CVE-2011-0653] Cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint Server 2010 Gold and SP1, and SharePoint Foundation 2010, allows remote attackers to inject arbitrary web script or HTML via the URI, aka "XSS in SharePoint Calendar Vulnerability."
15298| [CVE-2011-0647] The irccd.exe service in EMC Replication Manager Client before 5.3 and NetWorker Module for Microsoft Applications 2.1.x and 2.2.x allows remote attackers to execute arbitrary commands via the RunProgram function to TCP port 6542.
15299| [CVE-2011-0627] Adobe Flash Player before 10.3.181.14 on Windows, Mac OS X, Linux, and Solaris and before 10.3.185.21 on Android allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content, as possibly exploited in the wild in May 2011 by a Microsoft Office document with an embedded .swf file.
15300| [CVE-2011-0037] Microsoft Malware Protection Engine before 1.1.6603.0, as used in Microsoft Malicious Software Removal Tool (MSRT), Windows Defender, Security Essentials, Forefront Client Security, Forefront Endpoint Protection 2010, and Windows Live OneCare, allows local users to gain privileges via a crafted value of an unspecified user registry key.
15301| [CVE-2011-0027] Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2, and Windows Data Access Components (WDAC) 6.0, does not properly validate memory allocation for internal data structures, which allows remote attackers to execute arbitrary code, possibly via a large CacheSize property that triggers an integer wrap and a buffer overflow, aka "ADO Record Memory Vulnerability." NOTE: this might be a duplicate of CVE-2010-1117 or CVE-2010-1118.
15302| [CVE-2011-0026] Integer signedness error in the SQLConnectW function in an ODBC API (odbc32.dll) in Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2, and Windows Data Access Components (WDAC) 6.0, allows remote attackers to execute arbitrary code via a long string in the Data Source Name (DSN) and a crafted szDSN argument, which bypasses a signed comparison and leads to a buffer overflow, aka "DSN Overflow Vulnerability."
15303| [CVE-2010-4643] Heap-based buffer overflow in Impress in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Truevision TGA (TARGA) file in an ODF or Microsoft Office document.
15304| [CVE-2010-4253] Heap-based buffer overflow in Impress in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file in an ODF or Microsoft Office document, as demonstrated by a PowerPoint (aka PPT) document.
15305| [CVE-2010-4121] ** DISPUTED ** The TCP-to-ODBC gateway in IBM Tivoli Provisioning Manager for OS Deployment 7.1.1.3 does not require authentication for SQL statements, which allows remote attackers to modify, create, or read database records via a session on TCP port 2020. NOTE: the vendor disputes this issue, stating that the "default Microsoft Access database is not password protected because it is intended to be used for evaluation purposes only."
15306| [CVE-2010-3967] Untrusted search path vulnerability in Microsoft Windows Movie Maker (WMM) 2.6 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a Movie Maker (MSWMM) file, aka "Insecure Library Loading Vulnerability."
15307| [CVE-2010-3962] Use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code via vectors related to Cascading Style Sheets (CSS) token sequences and the clip attribute, aka an "invalid flag reference" issue or "Uninitialized Memory Corruption Vulnerability," as exploited in the wild in November 2010.
15308| [CVE-2010-3936] Cross-site scripting (XSS) vulnerability in Signurl.asp in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, 2010 Update 1, and 2010 Update 2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "XSS in Signurl.asp Vulnerability."
15309| [CVE-2010-3889] Unspecified vulnerability in Microsoft Windows on 32-bit platforms allows local users to gain privileges via unknown vectors, as exploited in the wild in July 2010 by the Stuxnet worm, and identified by Microsoft researchers and other researchers.
15310| [CVE-2010-3888] Unspecified vulnerability in Microsoft Windows on 32-bit platforms allows local users to gain privileges via unknown vectors, as exploited in the wild in July 2010 by the Stuxnet worm, and identified by Kaspersky Lab researchers and other researchers.
15311| [CVE-2010-3497] Symantec Norton AntiVirus 2011 does not properly interact with the processing of hcp:// URLs by the Microsoft Help and Support Center, which makes it easier for remote attackers to execute arbitrary code via malware that is correctly detected by this product, but with a detection approach that occurs too late to stop the code execution. NOTE: the researcher indicates that a vendor response was received, stating that this issue "falls into the work of our Firewall and not our AV (per our methodology of layers of defense)."
15312| [CVE-2010-3454] Multiple off-by-one errors in the WW8DopTypography::ReadFromMem function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted typography information in a Microsoft Word .DOC file that triggers an out-of-bounds write.
15313| [CVE-2010-3453] The WW8ListManager::WW8ListManager function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 does not properly handle an unspecified number of list levels in user-defined list styles in WW8 data in a Microsoft Word document, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted .DOC file that triggers an out-of-bounds write.
15314| [CVE-2010-3141] Untrusted search path vulnerability in Microsoft PowerPoint 2010 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse pptimpconv.dll that is located in the same folder as a .odp, .pot, .potm, .potx, .ppa, .pps, .ppsm, .ppsx, .ppt, .pptm, .pptx, .pwz, .sldm, or .sldx file.
15315| [CVE-2010-2743] The kernel-mode drivers in Microsoft Windows XP SP3 do not properly perform indexing of a function-pointer table during the loading of keyboard layouts from disk, which allows local users to gain privileges via a crafted application, as demonstrated in the wild in July 2010 by the Stuxnet worm, aka "Win32k Keyboard Layout Vulnerability." NOTE: this might be a duplicate of CVE-2010-3888 or CVE-2010-3889.
15316| [CVE-2010-2734] Cross-site scripting (XSS) vulnerability in the mobile portal in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, 2010 Update 1, and 2010 Update 2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "XSS Issue on UAG Mobile Portal Website in Forefront Unified Access Gateway Vulnerability."
15317| [CVE-2010-2733] Cross-site scripting (XSS) vulnerability in the Web Monitor in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, 2010 Update 1, and 2010 Update 2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "UAG XSS Allows EOP Vulnerability."
15318| [CVE-2010-2732] Open redirect vulnerability in the web interface in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, 2010 Update 1, and 2010 Update 2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, aka "UAG Redirection Spoofing Vulnerability."
15319| [CVE-2010-2564] Buffer overflow in Microsoft Windows Movie Maker (WMM) 2.1, 2.6, and 6.0 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted project file, aka "Movie Maker Memory Corruption Vulnerability."
15320| [CVE-2010-1184] The Microsoft wireless keyboard uses XOR encryption with a key derived from the MAC address, which makes it easier for remote attackers to obtain keystroke information and inject arbitrary commands via a nearby wireless device, as demonstrated by Keykeriki 2.
15321| [CVE-2010-1118] Unspecified vulnerability in Internet Explorer 8 on Microsoft Windows 7 allows remote attackers to execute arbitrary code via unknown vectors, possibly related to a use-after-free issue, as demonstrated by Peter Vreugdenhil during a Pwn2Own competition at CanSecWest 2010.
15322| [CVE-2010-1117] Heap-based buffer overflow in Internet Explorer 8 on Microsoft Windows 7 allows remote attackers to discover the base address of a Windows .dll file, and possibly have unspecified other impact, via unknown vectors, as demonstrated by Peter Vreugdenhil during a Pwn2Own competition at CanSecWest 2010.
15323| [CVE-2010-0806] Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object, as exploited in the wild in March 2010, aka "Uninitialized Memory Corruption Vulnerability."
15324| [CVE-2010-0716] _layouts/Upload.aspx in the Documents module in Microsoft SharePoint before 2010 uses URLs with the same hostname and port number for a web site's primary files and individual users' uploaded files (aka attachments), which allows remote authenticated users to leverage same-origin relationships and conduct cross-site scripting (XSS) attacks by uploading TXT files, a related issue to CVE-2008-5026. NOTE: the vendor disputes the significance of this issue, because cross-domain isolation can be implemented when needed.
15325| [CVE-2009-3555] The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate renegotiation handshakes with an existing connection, which allows man-in-the-middle attackers to insert data into HTTPS sessions, and possibly other types of sessions protected by TLS or SSL, by sending an unauthenticated request that is processed retroactively by a server in a post-renegotiation context, related to a "plaintext injection" attack, aka the "Project Mogul" issue.
15326| [CVE-2008-5750] Argument injection vulnerability in Microsoft Internet Explorer 8 beta 2 on Windows XP SP3 allows remote attackers to execute arbitrary commands via the --renderer-path option in a chromehtml: URI.
15327| [CVE-2008-5556] ** DISPUTED ** The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 does not recognize attack patterns designed to operate against web pages that are encoded with utf-7, which allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks by injecting crafted utf-7 content. NOTE: the vendor reportedly disputes this issue, stating "Behaviour is by design."
15328| [CVE-2008-5555] Microsoft Internet Explorer 8.0 Beta 2 relies on the XDomainRequestAllowed HTTP header to authorize data exchange between domains, which allows remote attackers to bypass the product's XSS Filter protection mechanism, and conduct XSS and cross-domain attacks, by injecting this header after a CRLF sequence, related to "XDomainRequest Allowed Injection (XAI)." NOTE: the vendor has reportedly stated that the XSS Filter intentionally does not attempt to "address every conceivable XSS attack scenario."
15329| [CVE-2008-5554] The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 does not properly handle some HTTP headers that appear after a CRLF sequence in a URI, which allows remote attackers to bypass the XSS protection mechanism and conduct XSS or redirection attacks, as demonstrated by the (1) Location and (2) Set-Cookie HTTP headers. NOTE: the vendor has reportedly stated that the XSS Filter intentionally does not attempt to "address every conceivable XSS attack scenario."
15330| [CVE-2008-5553] The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 disables itself upon encountering a certain X-XSS-Protection HTTP header, which allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks by injecting this header after a CRLF sequence. NOTE: the vendor has reportedly stated that the XSS Filter intentionally does not attempt to "address every conceivable XSS attack scenario."
15331| [CVE-2008-5552] The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks via a CRLF sequence in conjunction with a crafted Content-Type header, as demonstrated by a header with a utf-7 charset value. NOTE: the vendor has reportedly stated that the XSS Filter intentionally does not attempt to "address every conceivable XSS attack scenario."
15332| [CVE-2008-5551] The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks by injecting data at two different positions within an HTML document, related to STYLE elements and the CSS expression property, aka a "double injection."
15333| [CVE-2008-5180] Microsoft Communicator, and Communicator in Microsoft Office 2010 beta, allows remote attackers to cause a denial of service (memory consumption) via a large number of SIP INVITE requests, which trigger the creation of many sessions.
15334| [CVE-2008-4211] Integer signedness error in (1) QuickLook in Apple Mac OS X 10.5.5 and (2) Office Viewer in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via a crafted Microsoft Excel file that triggers an out-of-bounds memory access, related to "handling of columns."
15335| [CVE-2007-5351] Unspecified vulnerability in Server Message Block Version 2 (SMBv2) signing support in Microsoft Windows Vista allows remote attackers to force signature re-computation and execute arbitrary code via a crafted SMBv2 packet, aka "SMBv2 Signing Vulnerability."
15336| [CVE-2007-2729] Comodo Firewall Pro 2.4.18.184 and Comodo Personal Firewall 2.3.6.81, and probably older Comodo Firewall versions, do not properly test for equivalence of process identifiers for certain Microsoft Windows API functions in the NT kernel 5.0 and greater, which allows local users to call these functions, and bypass firewall rules or gain privileges, via a modified identifier that is one, two, or three greater than the canonical identifier.
15337| [CVE-2007-1534] DFSR.exe in Windows Meeting Space in Microsoft Windows Vista remains available for remote connections on TCP port 5722 for 2 minutes after Windows Meeting Space is closed, which allows remote attackers to have an unknown impact by connecting to this port during the time window.
15338| [CVE-2007-0341] Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.8.1 and earlier, when Microsoft Internet Explorer 6 is used, allows remote attackers to inject arbitrary web script or HTML via a javascript: URI in a CSS style in the convcharset parameter to the top-level URI, a different vulnerability than CVE-2005-0992.
15339| [CVE-2006-5559] The Execute method in the ADODB.Connection 2.7 and 2.8 ActiveX control objects (ADODB.Connection.2.7 and ADODB.Connection.2.8) in the Microsoft Data Access Components (MDAC) 2.5 SP3, 2.7 SP1, 2.8, and 2.8 SP1 does not properly track freed memory when the second argument is a BSTR, which allows remote attackers to cause a denial of service (Internet Explorer crash) and possibly execute arbitrary code via certain strings in the second and third arguments.
15340| [CVE-2006-4686] Buffer overflow in the Extensible Stylesheet Language Transformations (XSLT) processing in Microsoft XML Parser 2.6 and XML Core Services 3.0 through 6.0 allows remote attackers to execute arbitrary code via a crafted Web page.
15341| [CVE-2006-4685] The XMLHTTP ActiveX control in Microsoft XML Parser 2.6 and XML Core Services 3.0 through 6.0 does not properly handle HTTP server-side redirects, which allows remote user-assisted attackers to access content from other domains.
15342| [CVE-2006-1359] Microsoft Internet Explorer 6 and 7 Beta 2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a certain createTextRange call on a checkbox object, which results in a dereference of an invalid table pointer.
15343| [CVE-2006-0761] Buffer overflow in BlackBerry Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server 2.2 and 4.0 before SP3 Hotfix 4 for IBM Lotus Domino, 3.6 before SP7 and 5.0 before SP3 Hotfix 3 for Microsoft Exchangem, and 4.0 for Novell GroupWise before SP3 Hotfix 1 might allow user-assisted remote attackers to execute arbitrary code on the server via a crafted Microsoft Word document that is opened on a wireless device.
15344| [CVE-2006-0753] Memory leak in Microsoft Internet Explorer 6 for Windows XP Service Pack 2 allows remote attackers to cause a denial of service (memory consumption) via JavaScript that uses setInterval to repeatedly call a function to set the value of window.status.
15345| [CVE-2006-0544] urlmon.dll in Microsoft Internet Explorer 7.0 beta 2 (aka 7.0.5296.0) allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a BGSOUND element with its SRC attribute set to "file://" followed by a large number of "-" (dash of hyphen) characters.
15346| [CVE-2006-0003] Unspecified vulnerability in the RDS.Dataspace ActiveX control, which is contained in ActiveX Data Objects (ADO) and distributed in Microsoft Data Access Components (MDAC) 2.7 and 2.8, allows remote attackers to execute arbitrary code via unknown attack vectors.
15347| [CVE-2005-1929] Multiple heap-based buffer overflows in (1) isaNVWRequest.dll and (2) relay.dll in Trend Micro ServerProtect Management Console 5.58 and earlier, as used in Control Manager 2.5 and 3.0 and Damage Cleanup Server 1.1, allow remote attackers to execute arbitrary code via "wrapped" length values in Chunked transfer requests. NOTE: the original report suggests that the relay.dll issue is related to a problem in which a Microsoft Foundation Classes (MFC) static library returns invalid values under heavy load. As such, this might not be a vulnerability in Trend Micro's product.
15348| [CVE-2005-0852] Microsoft Windows XP SP1 allows local users to cause a denial of service (system crash) via an empty datagram to a raw IP over IP socket (IP protocol 4), as originally demonstrated using code in Python 2.3.
15349| [CVE-2004-1322] Cisco Unity 2.x, 3.x, and 4.x, when integrated with Microsoft Exchange, has several hard coded usernames and passwords, which allows remote attackers to gain unauthorized access and change configuration settings or read outgoing or incoming e-mail messages.
15350| [CVE-2003-1306] Microsoft URLScan 2.5, with the RemoveServerHeader option enabled, allows remote attackers to obtain sensitive information (server name and version) via an HTTP request that generates certain errors such as 400 "Bad Request," which leak the Server header in the response.
15351| [CVE-2003-0903] Buffer overflow in a component of Microsoft Data Access Components (MDAC) 2.5 through 2.8 allows remote attackers to execute arbitrary code via a malformed UDP response to a broadcast request.
15352| [CVE-2003-0353] Buffer overflow in a component of SQL-DMO for Microsoft Data Access Components (MDAC) 2.5 through 2.7 allows remote attackers to execute arbitrary code via a long response to a broadcast request to UDP port 1434.
15353| [CVE-2002-1918] Buffer overflow in Microsoft Active Data Objects (ADO) in Microsoft MDAC 2.5 through 2.7 allows remote attackers to have unknown impact with unknown attack vectors. NOTE: due to the lack of details available regarding this issue, perhaps it should be REJECTED.
15354| [CVE-2002-1142] Heap-based buffer overflow in the Remote Data Services (RDS) component of Microsoft Data Access Components (MDAC) 2.1 through 2.6, and Internet Explorer 5.01 through 6.0, allows remote attackers to execute code via a malformed HTTP request to the Data Stub.
15355| [CVE-2002-1015] RealJukebox 2 1.0.2.340 and 1.0.2.379, and RealOne Player Gold 6.0.10.505, allows remote attackers to execute arbitrary script in the Local computer zone by inserting the script into the skin.ini file of an RJS archive, then referencing skin.ini from a web page after it has been extracted, which is parsed as HTML by Internet Explorer or other Microsoft-based web readers.
15356| [CVE-2002-0697] Microsoft Metadirectory Services (MMS) 2.2 allows remote attackers to bypass authentication and modify sensitive data by using an LDAP client to directly connect to MMS and bypass the checks for MMS credentials.
15357| [CVE-2002-0057] XMLHTTP control in Microsoft XML Core Services 2.6 and later does not properly handle IE Security Zone settings, which allows remote attackers to read arbitrary files by specifying a local file as an XML Data Source.
15358| [CVE-2001-1218] Microsoft Internet Explorer for Unix 5.0SP1 allows local users to possibly cause a denial of service (crash) in CDE or the X server on Solaris 2.6 by rapidly scrolling Chinese characters or maximizing the window.
15359| [CVE-2000-0563] The URLConnection function in MacOS Runtime Java (MRJ) 2.1 and earlier and the Microsoft virtual machine (VM) for MacOS allows a malicious web site operator to connect to arbitrary hosts using a HTTP redirection, in violation of the Java security model.
15360| [CVE-1999-1097] Microsoft NetMeeting 2.1 allows one client to read the contents of another client's clipboard via a CTRL-C in the chat box when the box is empty.
15361|
15362| SecurityFocus - https://www.securityfocus.com/bid/:
15363| [83154] Microsoft Windows 2000 Server CVE-2004-0540 Remote Security Vulnerability
15364| [45297] Microsoft Exchange Server 2007 Infinite Loop Remote Denial of Service Vulnerability
15365| [43419] Microsoft Excel 2002 Memory Corruption Vulnerability
15366| [43189] Microsoft Visual C++ 2008 Redistributable Package DLL Loading Arbitrary Code Execution Vulnerability
15367| [42742] Microsoft PowerPoint 2007 Multiple DLL Loading Arbitrary Code Execution Vulnerability
15368| [42695] Microsoft Groove 2007 'mso.dll' DLL Loading Arbitrary Code Execution Vulnerability
15369| [42681] Microsoft Visio 2003 'mfc71enu.dll' DLL Loading Arbitrary Code Execution Vulnerability
15370| [41843] Microsoft Outlook Web Access for Exchange Server 2003 Cross Site Request Forgery Vulnerability
15371| [39776] Microsoft SharePoint Server 2007 '_layouts/help.aspx' Cross Site Scripting Vulnerability
15372| [37196] RETIRED: Microsoft December 2009 Advance Notification Multiple Vulnerabilities
15373| [36940] RETIRED: Microsoft November 2009 Advance Notification Multiple Vulnerabilities
15374| [36633] RETIRED: Microsoft October 2009 Advance Notification Multiple Vulnerabilities
15375| [36239] RETIRED: Microsoft September 2009 Advance Notification Multiple Vulnerabilities
15376| [35974] RETIRED: Microsoft August 2009 Advance Notification Multiple Vulnerabilities
15377| [35617] RETIRED: Microsoft July 2009 Advance Notification Multiple Vulnerabilities
15378| [35213] RETIRED: Microsoft June 2009 Advance Notification Multiple Vulnerabilities
15379| [34867] RETIRED: Microsoft May 2009 Advance Notification Multiple Vulnerabilities
15380| [34532] Microsoft IAG 2007 ActiveX Control Multiple Stack Based Buffer Overflow Vulnerabilities
15381| [34469] Microsoft Word 2000 WordPerfect Converter Remote Code Execution Vulnerability
15382| [34450] RETIRED: Microsoft April 2009 Advance Notification Multiple Vulnerabilities
15383| [34005] RETIRED: Microsoft March 2009 Advance Notification Multiple Vulnerabilities
15384| [33639] RETIRED: Microsoft February 2009 Advance Notification Multiple Vulnerabilities
15385| [33170] RETIRED: Microsoft January 2009 Advance Notification Multiple Vulnerabilities
15386| [32632] RETIRED: Microsoft December 2008 Advance Notification Multiple Vulnerabilities
15387| [32153] Retired: Microsoft November 2008 Advance Notification Multiple Vulnerabilities
15388| [31667] Retired: Microsoft October 2008 Advance Notification Multiple Vulnerabilities
15389| [31129] RETIRED: Microsoft SQL Server 2000 'sqlvdir.dll' ActiveX Buffer Overflow Vulnerability
15390| [31014] RETIRED: Microsoft September 2008 Advance Notification Multiple Vulnerabilities
15391| [30593] RETIRED: Microsoft August 2008 Advance Notification Multiple Vulnerabilities
15392| [30075] RETIRED: Microsoft July 2008 Advance Notification Multiple Vulnerabilities
15393| [29576] RETIRED: Microsoft June 2008 Advance Notification Multiple Vulnerabilities
15394| [29108] RETIRED: Microsoft May 2008 Advance Notification Multiple Vulnerabilities
15395| [28598] RETIRED: Microsoft April 2008 Advance Notification Multiple Vulnerabilities
15396| [28124] Retired: Microsoft March 2008 Advance Notification Multiple Vulnerabilities
15397| [27674] RETIRED: Microsoft February 2008 Advance Notification Multiple Vulnerabilities
15398| [27119] RETIRED: Microsoft January 2008 Advance Notification Multiple Vulnerabilities
15399| [26739] RETIRED: Microsoft December 2007 Advance Notification Multiple Vulnerabilities
15400| [26414] Microsoft Forms 2.0 ActiveX Control Memory Access Violation Denial of Service Vulnerabilities
15401| [26380] Retired: Microsoft November 2007 Advance Notification Multiple Vulnerabilities
15402| [25991] RETIRED: Microsoft Office 2000 and XP Unspecified Word Document Handling DoS Vulnerability
15403| [25922] RETIRED: Microsoft October 2007 Advance Notification Multiple Vulnerabilities
15404| [25573] RETIRED: Microsoft September 2007 Advance Notification Multiple Vulnerabilities
15405| [25247] Retired: Microsoft August 2007 Advance Notification Multiple Vulnerabilities
15406| [24771] Retired: Microsoft July 2007 Advance Notification Multiple Vulnerabilities
15407| [24366] RETIRED: Microsoft June 2007 Advance Notification Multiple Vulnerabilities
15408| [24118] Microsoft Office 2000 UA OUACTRL.OCX ActiveX Control Buffer Overflow Vulnerability
15409| [23800] RETIRED: Microsoft May 2007 Advance Notification Multiple Vulnerabilities
15410| [23380] Microsoft Word 2007 WWLib.DLL Unspecified Document File Buffer Overflow Vulnerability
15411| [23335] RETIRED: Microsoft April 2007 Advance Notification Multiple Vulnerabilities
15412| [22716] Microsoft Office 2003 Denial of Service Vulnerability
15413| [22567] Microsoft Word 2000/2002 Document Stream Remote Code Execution Vulnerability
15414| [22328] RETIRED: Microsoft Word 2003 Unspecified Code Execution Vulnerability
15415| [22225] Microsoft Word 2000 Malformed Function Code Execution Vulnerability
15416| [21611] Microsoft Project Server 2003 PDSRequest.ASP XML Request Information Disclosure Vulnerability
15417| [21495] Microsoft Windows 2000 Remote Installation Service Remote Code Execution Vulnerability
15418| [20843] Microsoft Visual Studio 2005 WMI Object Broker Remote Code Execution Vulnerability
15419| [19636] Microsoft Windows 2000 Multiple COM Object Instantiation Code Execution Vulnerabilities
15420| [19388] Microsoft Windows 2000 Kernel Local Privilege Escalation Vulnerability
15421| [17134] Microsoft Commerce Server 2002 Authentication Bypass Vulnerability
15422| [16634] Microsoft PowerPoint 2000 Remote Information Disclosure Vulnerability
15423| [14772] Microsoft Exchange Server 2003 Exchange Information Store Denial Of Service Vulnerability
15424| [14093] Microsoft Update Rollup 1 for Windows 2000 SP4 Released - Multiple Vulnerabilities Fixed
15425| [13564] Microsoft SQL Server 2000 Multiple Vulnerabilities
15426| [13008] Microsoft Windows Server 2003 SMB Redirector Local Denial Of Service Vulnerability
15427| [12972] Microsoft Windows Server 2003 Service Pack 1 Released - Multiple Vulnerabilities Fixed
15428| [12913] Microsoft Outlook 2002 Connector For IBM Lotus Domino Policy Bypass Vulnerability
15429| [12824] Microsoft InfoPath 2003 Insecure Information Storage Vulnerability
15430| [12641] Microsoft Windows 2000 Group Policy Bypass Vulnerability
15431| [12141] Microsoft FrontPage 2000 Internet Publishing Service Provider DAV File Upload Vulnerability
15432| [11820] Microsoft Windows 2000 Resource Kit W3Who.DLL Multiple Remote Vulnerabilities
15433| [11446] Microsoft Outlook 2003 Security Policy Bypass Vulnerability
15434| [11387] Microsoft Windows 2003 Services Default SACL Access Right Weakness
15435| [10901] Microsoft Windows 2000/XP CRL File Failed Integrity Check Denial Of Service Vulnerability
15436| [10693] Microsoft Windows 2000 Media Player Control Media Preview Script Execution Vulnerability
15437| [10484] Microsoft ISA Server 2000 FTP Bounce Filtering Vulnerability
15438| [10480] Microsoft ISA Server 2000 Site And Content Rule Bypass Vulnerability
15439| [10440] Microsoft Windows 2000 Domain Expired Account Security Policy Violation Weakness
15440| [10369] Microsoft Outlook 2003 Media File Script Execution Vulnerability
15441| [10307] Microsoft Outlook 2003 Predictable File Location Weakness
15442| [10114] Microsoft Windows 2000 Domain Controller LDAP Denial Of Service Vulnerability
15443| [9409] Microsoft Exchange Server 2003 Outlook Web Access Random Mailbox Access Vulnerability
15444| [9408] Microsoft ISA Server 2000 H.323 Filter Remote Buffer Overflow Vulnerability
15445| [9118] Microsoft Exchange Server 2003 Outlook Web Access Lowered Security Settings Weakness
15446| [8833] Microsoft Windows 2000 TroubleShooter ActiveX Control Buffer Overflow Vulnerability
15447| [8522] Multiple Microsoft Windows 2003 Stack Protection Implementation Weaknesses
15448| [8397] Microsoft Windows 2000 Subnet Bandwidth Manager RSVP Server Authority Hijacking Vulnerability
15449| [8104] Microsoft Windows 2000 Unauthorized RPC Connection Weakness
15450| [8098] Microsoft Windows 2000 Terminal Services Named Pipe System Account Access Vulnerability
15451| [8093] Microsoft Windows 2000 Active Directory Forest Origin Validation Vulnerability
15452| [8090] Microsoft Windows 2000 ShellExecute() Buffer Overflow Vulnerability
15453| [8089] Microsoft Windows 2000 Unspecified Cryptnet.DLL Memory Leakage Vulnerability
15454| [8086] Microsoft Windows 2000 Port Name Buffers Potential Buffer Overflow Vulnerability
15455| [8085] Microsoft Windows 2000 ModifyDN Request Denial of Service Vulnerability
15456| [8083] Microsoft Windows 2000 Domain Controller Spoofing Vulnerability
15457| [8081] Microsoft Windows 2000 USBH_IoctlGetNodeConnectionDriverKeyName Information Disclosure Vulnerability
15458| [8063] Microsoft Commerce Server 2002 Weak Registry Key Permissions Weakness
15459| [8045] Microsoft Windows 2000 SP4 Released - Multiple Vulnerabilities Fixed
15460| [7930] Microsoft Windows 2000 Active Directory Remote Stack Overflow Vulnerability
15461| [7788] Microsoft Windows 2000/XP/2003 IPV6 ICMP Flood Denial Of Service Vulnerability
15462| [7469] Microsoft BizTalk Server 2002 HTTP Receiver Buffer Overflow Vulnerability
15463| [7360] Microsoft Windows 2000/XP Registry Editor Custom Permissions Weakness
15464| [7102] Microsoft Windows 2000 Help Facility .CNT File :Link Buffer Overflow Vulnerability
15465| [6769] Microsoft Windows 2000 RPC Service Privilege Escalation Vulnerability
15466| [6766] Microsoft Windows 2000 NetBIOS Continuation Packets Kernel Memory Leak Vulnerability
15467| [6667] Microsoft Outlook 2002 V1 Exchange Server Security Certificate Information Leakage Vulnerability
15468| [6319] Microsoft Outlook 2002 Email Header Processing Denial of Service Vulnerability
15469| [6030] Microsoft Windows 2000 SNMP Printer Query Denial of Service Vulnerability
15470| [5972] Microsoft Windows 2000/XP Full Event Log Administrative Alert Weakness
15471| [5922] Microsoft Content Management Server 2001 Cross-Site Scripting Vulnerability
15472| [5480] Microsoft Windows 2000 Network Connection Manager Privilege Elevation Vulnerability
15473| [5422] Microsoft Content Management Server 2001 SQL Injection Vulnerability
15474| [5421] Microsoft Content Management Server 2001 Arbitrary Upload Location Vulnerability
15475| [5420] Microsoft Content Management Server 2001 User Authentication Buffer Overflow Vulnerability
15476| [5415] Microsoft Windows 2000 Insecure Default File Permissions Vulnerability
15477| [5413] Microsoft Exchange 2000 Post Authorization License Exhaustion Denial Of Service Vulnerability
15478| [5412] Microsoft Exchange 2000 Multiple MSRPC Denial Of Service Vulnerabilities
15479| [5312] Microsoft SQL Server 2000 Resolution Service Denial of Service Vulnerability
15480| [5311] Microsoft SQL Server 2000 Resolution Service Stack Overflow Vulnerability
15481| [5310] Microsoft SQL Server 2000 Resolution Service Heap Overflow Vulnerability
15482| [5309] Microsoft SQL Server 2000 sp_MScopyscript SQL Injection Vulnerability
15483| [5307] Microsoft SQL Server 2000 Database Consistency Checkers Buffer Overflow Vulnerability
15484| [5253] Microsoft Windows 2000 Narrator Password Disclosure Vulnerability
15485| [5205] Microsoft SQL Server 2000 Incorrect Registry Key Permissions Vulnerability
15486| [5111] Microsoft Commerce Server 2000 OWC Package Installer Local Command Execution Vulnerability
15487| [5014] Microsoft SQL Server 2000 Password Encrypt Procedure Buffer Overflow Vulnerability
15488| [4881] Microsoft Exchange 2000 Malformed Mail Attribute DoS Vulnerability
15489| [4853] Microsoft Commerce Server 2000 Profile Service Buffer Overflow Vulnerability
15490| [4852] Microsoft Windows 2000 Remote Access Service Buffer Overflow Vulnerability
15491| [4847] Microsoft SQL Server 2000 Bulk Insert Procedure Buffer Overflow Vulnerability
15492| [4797] Microsoft MSDE/SQL Server 2000 Desktop Engine Default Configuration Vulnerability
15493| [4683] Microsoft Windows 2000 / NT Path Precedence Vulnerability
15494| [4532] Microsoft Windows 2000 Lanman Denial of Service Vulnerability
15495| [4438] Microsoft Windows 2000 Group Policy Evasion Vulnerability
15496| [4426] Microsoft Windows 2000 / NT / XP MUP UNC Request Buffer Overflow Vulnerability
15497| [4287] Microsoft Windows 2000 / NT 4.0 Process Handle Local Privilege Elevation Vulnerability
15498| [4256] Microsoft Windows 2000 Password Policy Bypass Vulnerability
15499| [4157] Microsoft Commerce Server 2000 ISAPI Buffer Overflow Vulnerability
15500| [4095] Microsoft Windows 2000 Server Terminal Services Failure To Lock Terminal Vulnerability
15501| [3652] Microsoft Windows 2000 Internet Key Exchange DoS Vulnerability
15502| [3481] Microsoft Windows 2000/XP GDI Denial of Service Vulnerability
15503| [3479] Microsoft Windows 2000 NTFS With Macintosh Client Directory Permission Vulnerability
15504| [3445] Microsoft Windows 2000/NT Terminal Server Service RDP DoS Vulnerability
15505| [3339] Microsoft Index Server 2.0 File Information and Path Disclosure Vulnerability
15506| [3305] Norton AntiVirus for Microsoft Exchange 2000 Information Disclosure Vulnerability
15507| [3291] Microsoft Windows 2000 RunAs Service Denial of Services Vulnerability
15508| [3215] Microsoft Windows 2000 IrDA Buffer Overflow Denial of Service Vulnerability
15509| [3185] Microsoft Windows 2000 RunAs Service Named Pipe Hijacking Vulnerability
15510| [3184] Microsoft Windows 2000 RunAs User Credentials Exposure Vulnerability
15511| [3146] Microsoft Windows 2000 System File Replacement Vulnerability
15512| [3115] Microsoft Windows NT and 2000 Command Prompt Reboot Vulnerability
15513| [3063] Microsoft Windows 2000 Unauthorized Password Change Vulnerability
15514| [3033] Microsoft Windows 2000 Task Manager Process Termination Vulnerability
15515| [2988] Microsoft Windows 2000 SMTP Improper Authentication Vulnerability
15516| [2929] Microsoft Windows 2000 LDAP SSL Password Modification Vulnerability
15517| [2849] Microsoft Windows 2000 Telnet Privilege Escalation Vulnerability
15518| [2846] Microsoft Windows 2000 Telnet System Call DoS Vulnerability
15519| [2844] Microsoft Windows 2000 Telnet Service DoS Vulnerability
15520| [2843] Microsoft Windows 2000 Telnet Multiple Sessions DoS Vulnerability
15521| [2838] Microsoft Windows 2000 Telnet Username DoS Vulnerability
15522| [2460] Microsoft Windows 2000 Event Viewer Buffer Overflow Vulnerability
15523| [2441] Microsoft Exchange 2000 / IIS 5.0 Multiple Invalid URL Request DoS Vulnerability
15524| [2394] Microsoft Windows 2000 Domain Controller DoS Vulnerability
15525| [2341] Microsoft Windows 2000 Network DDE Escalated Privileges Vulnerability
15526| [2326] Microsoft Windows 2000 RDP DoS Vulnerability
15527| [2133] Microsoft Windows 2000 Directory Services Restore Mode Blank Password Vulnerability
15528| [2066] Microsoft Windows NT 4.0 / 2000 SNMP Registry Key Modification Vulnerability
15529| [2018] Microsoft Windows 2000 Telnet Session Timeout DoS Vulnerability
15530| [2007] Microsoft Windows 2000 DNS Memory Leak Vulnerability
15531| [1973] Microsoft Windows 2000 Domain Account Lockout Bypass Vulnerability
15532| [1958] Microsoft Exchange 2000 Server EUSR_EXSTOREEVENT Account Vulnerability
15533| [1933] Microsoft Indexing Services for Windows 2000 File Verification Vulnerability
15534| [1899] Microsoft Windows 2000 ActiveX Control Buffer Overflow Vulnerability
15535| [1811] Microsoft Site Server 2.0 with IIS 4.0 Malicious File Upload Vulnerability
15536| [1758] Microsoft Windows 2000 Unattended Install OEMPreinstall Vulnerability
15537| [1753] Microsoft Windows NT 4.0 / 2000 Spoofed LPC Request Vulnerability
15538| [1748] Microsoft Windows NT 4.0 / 2000 Predictable LPC Message Identifier Multiple Vulnerabilities
15539| [1745] Microsoft Windows NT 4.0 / 2000 LPC Zone Memory Depletion DoS Vulnerability
15540| [1729] Microsoft Windows 2000 Simplified Chinese IME Vulnerability
15541| [1695] Microsoft Proxy 2.0 FTP Permissions Bypass Vulnerability
15542| [1692] Microsoft Proxy 2.0 Internal Network Access Vulnerability
15543| [1683] Microsoft Windows 2000 telnet.exe NTLM Authentication Vulnerability
15544| [1673] Microsoft Windows 2000 Malformed RPC Packet DoS Vulnerability
15545| [1651] Microsoft Windows 2000 Still Image Service Privilege Escalation Vulnerability
15546| [1632] Microsoft Windows 98 / NT 4.0 / 2000 File Extension Validation Vulnerability
15547| [1620] Microsoft Windows 9x / NT 4.0 / 2000 NetBIOS Cache Corruption Vulnerability
15548| [1613] Microsoft Windows 2000 Local Security Policy Corruption Vulnerability
15549| [1566] Microsoft Word 97 / 2000 Mail Merge Code Execution Vulnerability
15550| [1561] Microsoft Word / Excel / Powerpoint 2000 Object Tag Buffer Overflow Vulnerability
15551| [1535] Microsoft Windows 2000 Named Pipes Predictability Vulnerability
15552| [1507] Microsoft Windows NT 4.0 / 2000 Unspecified Executable Path Vulnerability
15553| [1451] Microsoft Excel 97 / 2000 Register.ID Vulnerability
15554| [1435] Microsoft FrontPage 2000 Server Extensions Denial Of Service Vulnerability
15555| [1415] Microsoft Windows 2000 Remote CPU-overload Vulnerability
15556| [1414] Microsoft Windows 2000 Telnet Server DoS Vulnerability
15557| [1399] Microsoft Internet Explorer 5.01 and Excel/Powerpoint 2000 ActiveX Object Execution Vulnerability
15558| [1398] Microsoft Internet Explorer 5.01 and Access 2000 / 97 VBA Code Execution Vulnerability
15559| [1350] Microsoft Windows 2000 Windows Station Access Vulnerability
15560| [1304] Microsoft Windows NT 4.0 / 2000 SMB Write Request DoS Vulnerability
15561| [1301] Microsoft Windows NT 4.0 / 2000 Ignored SMB Response DoS Vulnerability
15562| [1295] Microsoft Windows 2000 Default 40-bit Encrypted Protected Store Vulnerability
15563| [1198] Microsoft Windows 2000 Default SYSKEY Configuration Vulnerability
15564| [1197] Microsoft Office 2000 UA Control Vulnerability
15565| [990] Microsoft Windows 2000 Install Unprotected ADMIN$ Share Vulnerability
15566| [945] Microsoft SMS 2.0 Default Permissions Vulnerability
15567| [539] Microsoft Windows 2000 EFS Vulnerability
15568| [180] Microsoft Windows April Fools 2001 Vulnerability
15569| [71487] Microsoft December 2014 Advance Notification Multiple Vulnerabilities
15570| [70966] RETIRED: Microsoft November 2014 Advance Notification Multiple Vulnerabilities
15571| [70367] RETIRED: Microsoft October 2014 Advance Notification Multiple Vulnerabilities
15572| [69636] RETIRED: Microsoft September 2014 Advance Notification Multiple Vulnerabilities
15573| [69108] Microsoft August 2014 Advance Notification Multiple Vulnerabilities
15574| [68367] Microsoft July 2014 Advance Notification Multiple Vulnerabilities
15575| [67905] Microsoft June 2014 Advance Notification Multiple Vulnerabilities
15576| [67298] Microsoft May 2014 Advance Notification Multiple Vulnerabilities
15577| [66639] RETIRED: Microsoft April 2014 Advance Notification Multiple Vulnerabilities
15578| [66016] Microsoft March 2014 Notification Multiple Vulnerabilities
15579| [65426] Microsoft February 2014 Notification Multiple Vulnerabilities
15580| [64757] RETIRED: Microsoft January 2014 Advance Notification Multiple Vulnerabilities
15581| [64083] RETIRED: Microsoft December 2013 Advance Notification Multiple Vulnerabilities
15582| [63604] RETIRED: Microsoft November 2013 Advance Notification Multiple Vulnerabilities
15583| [62797] RETIRED: Microsoft October 2013 Advance Notification Multiple Vulnerabilities
15584| [62228] RETIRED: Microsoft September 2013 Advance Notification Multiple Vulnerabilities
15585| [62181] Microsoft Office Pinyin IME 2010 CVE-2013-3859 Local Privilege Escalation Vulnerability
15586| [61686] Microsoft August 2013 Advance Notification Multiple Vulnerabilities
15587| [60960] RETIRED: Microsoft July 2013 Advance Notification Multiple Vulnerabilities
15588| [60394] Microsoft June 2013 Advance Notification Multiple Vulnerabilities
15589| [59785] RETIRED: Microsoft May 2013 Advance Notification Multiple Vulnerabilities
15590| [58881] RETIRED: Microsoft April 2013 Advance Notification Multiple Vulnerabilities
15591| [58380] RETIRED: Microsoft March 2013 Advance Notification Multiple Vulnerabilities
15592| [57846] RETIRED: Microsoft February 2013 Advance Notification Multiple Vulnerabilities
15593| [57137] RETIRED: Microsoft January 2013 Advance Notification Multiple Vulnerabilities
15594| [56838] RETIRED: Microsoft December 2012 Advance Notification Multiple Vulnerabilities
15595| [56450] RETIRED: Microsoft November 2012 Advance Notification Multiple Vulnerabilities
15596| [56304] Microsoft Office Excel 2010 Memory Corruption Denial of Service Vulnerability
15597| [55794] RETIRED: Microsoft October 2012 Advance Notification Multiple Vulnerabilities
15598| [55472] RETIRED: Microsoft September 2012 Advance Notification Multiple Vulnerabilities
15599| [54944] RETIRED: Microsoft August 2012 Advance Notification Multiple Vulnerabilities
15600| [54318] RETIRED: Microsoft July 2012 Advance Notification Multiple Vulnerabilities
15601| [53862] RETIRED: Microsoft June 2012 Advance Notification Multiple Vulnerabilities
15602| [53372] RETIRED: Microsoft May 2012 Advance Notification Multiple Vulnerabilities
15603| [52910] RETIRED: Microsoft April 2012 Advance Notification Multiple Vulnerabilities
15604| [52366] RETIRED: Microsoft March 2012 Advance Notification Multiple Vulnerabilities
15605| [51944] RETIRED: Microsoft February 2012 Advance Notification Multiple Vulnerabilities
15606| [51289] RETIRED: Microsoft January 2012 Advance Notification Multiple Vulnerabilities
15607| [50980] RETIRED: Microsoft December 2011 Advance Notification Multiple Vulnerabilities
15608| [50513] RETIRED: Microsoft November 2011 Advance Notification Multiple Vulnerabilities
15609| [49994] RETIRED: Microsoft October 2011 Advance Notification Multiple Vulnerabilities
15610| [49515] RETIRED: Microsoft September 2011 Advance Notification Multiple Vulnerabilities
15611| [49017] RETIRED: Microsoft August 2011 Advance Notification Multiple Vulnerabilities
15612| [48616] RETIRED: Microsoft July 2011 Advance Notification Multiple Vulnerabilities
15613| [48235] Microsoft Lync Server 2010 'ReachJoin.aspx' Remote Command Injection Vulnerability
15614| [48193] RETIRED: Microsoft June 2011 Advance Notification Multiple Vulnerabilities
15615| [47725] RETIRED: Microsoft May 2011 Advance Notification Multiple Vulnerabilities
15616| [47255] RETIRED: Microsoft April 2011 Advance Notification Multiple Vulnerabilities
15617| [46675] RETIRED: Microsoft March 2011 Advance Notification Multiple Vulnerabilities
15618| [46132] RETIRED: Microsoft February 2011 Advance Notification Multiple Vulnerabilities
15619| [45696] RETIRED: Microsoft January 2011 Advance Notification Multiple Vulnerabilities
15620| [45307] RETIRED: Microsoft December 2010 Advance Notification Multiple Vulnerabilities
15621| [44649] RETIRED: Microsoft November 2010 Advance Notification Multiple Vulnerabilities
15622| [43831] RETIRED: Microsoft October 2010 Advance Notification Multiple Vulnerabilities
15623| [43115] RETIRED: Microsoft September 2010 Advance Notification Multiple Vulnerabilities
15624| [42234] RETIRED: Microsoft August 2010 Advance Notification Multiple Vulnerabilities
15625| [41474] RETIRED: Microsoft July 2010 Advance Notification Multiple Vulnerabilities
15626| [40548] RETIRED: Microsoft June 2010 Advance Notification Multiple Vulnerabilities
15627| [39961] RETIRED: Microsoft May 2010 Advance Notification Multiple Vulnerabilities
15628| [39313] RETIRED: Microsoft April 2010 Advance Notification Multiple Vulnerabilities
15629| [38540] RETIRED: Microsoft March 2010 Advance Notification Multiple Vulnerabilities
15630| [38096] RETIRED: Microsoft February 2010 Advance Notification Multiple Vulnerabilities
15631| [37887] RETIRED: Microsoft January 2010 Advance Notification Multiple Vulnerabilities
15632| [37664] RETIRED: Microsoft January 2010 Advance Notification Multiple Vulnerabilities
15633| [32642] Microsoft Word RTF Malformed Control Word Variant 2 Remote Code Execution Vulnerability
15634|
15635| IBM X-Force - https://exchange.xforce.ibmcloud.com:
15636| [82417] Microsoft Windows Knowledge Base Article 2801261 update is not installed
15637| [82415] Microsoft Windows Knowledge Base Article 2807986 update is not installed
15638| [82410] Microsoft Windows Knowledge Base Article 2809289 update is not installed
15639| [81859] Microsoft Windows Knowledge Base Article 2802968 update is not installed
15640| [81857] Microsoft Windows Knowledge Base Article 2809279 update is not installed
15641| [81668] Microsoft Windows Knowledge Base Article 2800277 update is not installed
15642| [77323] Microsoft Windows Knowledge Base Article 2706045 update is not installed
15643| [75949] Microsoft Windows Knowledge Base Article 2707960 update is not installed
15644| [75942] Microsoft Windows Knowledge Base Article 2706726 update is not installed
15645| [75934] Microsoft Windows Knowledge Base Article 2709162 update is not installed
15646| [75926] Microsoft Windows Knowledge Base Article 2709100 update is not installed
15647| [75905] Microsoft Windows Knowledge Base Article 2707956 update is not installed
15648| [71991] Microsoft Windows Knowledge Base Article 2607664 update is not installed
15649| [71542] Microsoft Windows Knowledge Base Article 2607702 update is not installed
15650| [70945] Microsoft Windows Knowledge Base Article 2603381 update is not installed
15651| [70150] Microsoft Windows Knowledge Base Article 2607670 update is not installed
15652| [67755] Microsoft Windows Knowledge Base Article 2503665 update is not installed
15653| [67749] Microsoft Windows Knowledge Base Article 2507938 update is not installed
15654| [66845] Microsoft Windows Knowledge Base Article 2506014 update is not installed
15655| [66844] Microsoft Windows Knowledge Base Article 2501584 update is not installed
15656| [66448] Microsoft Windows Knowledge Base Article 2508272 update is not installed
15657| [66442] Microsoft Windows Knowledge Base Article 2509553 update is not installed
15658| [66440] Microsoft Windows Knowledge Base Article 2508429 update is not installed
15659| [66438] Microsoft Windows Knowledge Base Article 2507618 update is not installed
15660| [66430] Microsoft Windows Knowledge Base Article 2503658 update is not installed
15661| [66425] Microsoft Windows Knowledge Base Article 2506223 update is not installed
15662| [65570] Microsoft Windows Knowledge Base Article 2500212 update is not installed
15663| [65568] Microsoft Windows Knowledge Base Article 2508062 update is not installed
15664| [63840] Microsoft Visual C++ 2008 Redistributable Package dynamic-linked library (DLL) code execution
15665| [63780] Microsoft PowerPoint 2007 dynamic-linked library (rpawinet.dll) code execution
15666| [63775] Microsoft Visio 2003 dynamic-linked library (mfc71enu.dll) code execution
15667| [63586] Microsoft Windows Knowledge Base Article 2207559 update is not installed
15668| [63573] Microsoft Windows Knowledge Base Article 2407132 update is not installed
15669| [62797] Microsoft Windows Knowledge Base Article 2305420 update is not installed
15670| [62149] Microsoft Windows Knowledge Base Article 2207566 update is not installed
15671| [62133] Microsoft Windows Knowledge Base Article 2405882 update is not installed
15672| [53980] Microsoft Windows 2000 License Logging Server buffer overflow
15673| [53601] Microsoft Office 2008 for Mac user ID 502 security bypass
15674| [50973] Microsoft Windows Server 2003 and Vista win32k.sys denial of service
15675| [50759] Microsoft Windows 2000 Active Directory LDAP code execution
15676| [48595] Microsoft Word 2007 Email as PDF information disclosure
15677| [46102] Microsoft Windows 2003 SP2 is not installed on the system
15678| [46101] Microsoft Windows 2003 SP1 is not installed on the system
15679| [45186] Microsoft SQL Server 2000 SQLVDIRLib.SQLVDirControl ActiveX control buffer overflow
15680| [37200] Microsoft SQL Server 2000 Service Pack 1 update is not installed
15681| [37198] Microsoft SQL Server 2000 Service Pack 3 update is not installed
15682| [34634] Microsoft Windows Server 2003 Active Directory information disclosure
15683| [34599] Microsoft Windows Server 2003 terminal server security bypass
15684| [34473] Microsoft Office 2000 ActiveX control buffer overflow
15685| [33713] Microsoft Word 2007 multiple unspecified denial of service
15686| [33712] Microsoft Word 2007 wwlib.dll buffer overflow
15687| [32631] Microsoft SQL Server 2000 Service Pack 2 update is not installed
15688| [31821] Microsoft Windows time zone update for year 2007
15689| [31196] Microsoft Office 2003 Brazilian Grammar Checker buffer overflow
15690| [30905] Microsoft Project Server 2003 pdsrequest.asp information disclosure
15691| [29546] Microsoft Windows 2000/2003 user logoff initiated
15692| [29545] Microsoft Windows 2000/2003 system time changed
15693| [29544] Microsoft Windows 2000/2003 system security access removed
15694| [29543] Microsoft Windows 2000/2003 security access granted
15695| [29542] Microsoft Windows 2000/2003 SAM notification package loaded
15696| [29541] Microsoft Windows 2000/2003 primary security token issued
15697| [29540] Microsoft Windows 2000/2003 user password reset successful
15698| [29539] Microsoft Windows 2000/2003 object indirectly accessed
15699| [29538] Microsoft Windows 2000/2003 object handle duplicated
15700| [29537] Microsoft Windows 2000/2003 logon with explicit credentials success
15701| [29536] Microsoft Windows 2000/2003 logon attempt using explicit credentials unsuccessful
15702| [29535] Microsoft Windows 2000/2003 IPSEC policy agent failed
15703| [29534] Microsoft Windows 2000/2003 IPSEC policy agent disabled
15704| [29533] Microsoft Windows 2000/2003 IPSEC policy agent changed
15705| [29532] Microsoft Windows 2000/2003 IKE security association established
15706| [29531] Microsoft Windows 2000/2003 IKE quick mode association ended
15707| [29530] Microsoft Windows 2000/2003 IKE main mode association ended
15708| [29529] Microsoft Windows 2000/2003 IKE association negotiation failed
15709| [29528] Microsoft Windows 2000/2003 IKE association peer authentication failed
15710| [29527] Microsoft Windows 2000/2003 IKE association failed invalid proposal
15711| [29526] Microsoft Windows 2000/2003 IKE association failed authentication parameters
15712| [29525] Microsoft Windows 2000/2003 DPAPI master key backup attempted
15713| [29524] Microsoft Windows 2000/2003 DPAPI key recovery attempted
15714| [29523] Microsoft Windows 2000/2003 DPAPI auditable data unprotected
15715| [29522] Microsoft Windows 2000/2003 administrative group security descriptor set
15716| [29521] Microsoft Windows 2000/2003 account name changed
15717| [29507] Microsoft Office 2003 unspecified PowerPoint NULL pointer dereference denial of service
15718| [28512] Microsoft Internet Explorer multiple Windows 2000 COM object denial of service
15719| [28005] Microsoft Windows 2000 Management Console (MMC) resource file cross-site scripting
15720| [26118] Microsoft Office 2003 mailto: information disclosure
15721| [25330] Microsoft Commerce Server 2002 authfiles/login.asp authentication bypass
15722| [24474] Microsoft Windows 2000 LDAP client accepts untrusted CA
15723| [24473] Microsoft Windows 2000 event ID 565 not logged
15724| [24472] Microsoft Windows 2000 Event ID 1704 records incorrect group policy settings
15725| [24407] Microsoft Windows 2000 SECEDIT command fails to set ACLs correctly
15726| [24405] Microsoft Windows 2000 UPN credentials with trailing dot group policy bypass
15727| [24403] Microsoft Windows 2000 WideCharToMultiByte() incorrect Japanese character conversion
15728| [24402] Microsoft Windows 2000 Terminal Service client IP not logged
15729| [24400] Microsoft Windows 2000 domain authentication can be bypassed by a local administrator
15730| [23066] Microsoft Windows XP and 2000 Server MSRPC memory allocation denial of service
15731| [22318] Microsoft SQL Server 2000 Service Pack 4 update is not installed
15732| [22183] Microsoft Exchange Server 2003 public folder denial of service
15733| [21345] Microsoft Windows 2000 Update Rollup 1 for Service Pack 4 has not been installed
15734| [21315] Microsoft Outlook 2002 connector for Domino bypass restrictions
15735| [19969] Multiple Microsoft Windows Server 2003 Edition printer driver denial of service
15736| [19965] Multiple Microsoft Windows Server 2003 Editions SMB redirector denial of service
15737| [19727] Microsoft Windows 2000 GDI32.DLL denial of service
15738| [19629] Microsoft Exchange Server 2003 folder denial of service
15739| [17826] Microsoft Outlook 2003 CID security bypass
15740| [17624] Microsoft Windows XP and Windows Server 2003 Compressed Folders buffer overflow
15741| [17621] Microsoft Windows 2003 SMTP service code execution
15742| [17560] Microsoft Windows 2000 and XP GDI library denial of service
15743| [17521] Microsoft Windows 2000 Service Pack 4 is not installed
15744| [16913] Microsoft Windows 2003 users with Synchronize directory service data privilege
15745| [16912] Microsoft Windows 2003 groups with Synchronize directory service data privilege
15746| [16909] Microsoft Windows 2003 groups with Remove computer from docking station privilege
15747| [16907] Microsoft Windows 2003 users with Create global objects privilege
15748| [16905] Microsoft Windows 2003 users or groups with Create global objects privilege
15749| [16851] Microsoft Windows 2003 and XP WinKey and U key denial of service
15750| [16704] Microsoft Windows 2000 Media Player control code execution
15751| [16582] Microsoft Windows Server 2003 kernel CPU denial of service
15752| [16572] Microsoft Windows 2003 Users with Impersonate a client after authentication privilege
15753| [16570] Microsoft Windows 2003 Users with Create global objects privilege
15754| [16564] Microsoft Windows 2003 Groups with Create global objects privilege
15755| [16562] Microsoft Windows 2003 Groups with "
15756| [16522] Microsoft Windows 2003 Impersonate a client after authentication privilege
15757| [16521] Microsoft Windows 2003 Deny Logon Through Terminal Services privilege
15758| [16520] Microsoft Windows 2003 Create global objects privilege
15759| [16276] Microsoft Windows 2000 Advanced Server fully qualified domain name security bypass
15760| [16173] Microsoft Outlook 2003 OLE object bypass restricted security zone
15761| [16119] Microsoft Outlook 2000 URL spoofing
15762| [16104] Microsoft Outlook 2003 predictable file location could allow code execution
15763| [16095] Microsoft Windows XP and Windows Server 2003 HCP URL code execution
15764| [15704] Microsoft Windows XP and Windows Server 2003 HCP URL code execution
15765| [15700] Microsoft Windows 2000 Domain Controller LSASS LDAP message denial of service
15766| [15632] Microsoft Windows 2000 Utility Manger allows privilege escalation
15767| [15414] Microsoft Outlook 2002 mailto URL allows execution of code
15768| [15263] Microsoft Windows XP and 2000 Server kernel allows elevated privileges
15769| [15057] Microsoft Windows XP and Windows Server 2003 smbmount Linux client denial of service
15770| [15038] Microsoft Windows 2000 Server Windows Media Services denial of service
15771| [15037] Microsoft Windows Server 2003 WINS /GS flag denial of service
15772| [14178] Microsoft ISA Exchange Server 2003 MS04-002 patch is not installed
15773| [14167] Microsoft ISA Server 2000 H.323 filter buffer overflow
15774| [13426] Microsoft Windows 2000 and XP RPC race condition
15775| [13423] Microsoft Windows 2000 Local Troubleshooter ActiveX control buffer overflow
15776| [13407] Microsoft Windows 2000 Server mqsvc.exe MQLocateBegin packet buffer overflow
15777| [13385] Microsoft Windows Server 2003 "
15778| [13211] Microsoft Windows 2000 and XP URG memory leak
15779| [13171] Microsoft Windows Server 2003 can allow attacker to bypass mechanism used to detect buffer overflows
15780| [13131] Microsoft Windows 2000 Message Queue Manager buffer overflow
15781| [12684] Microsoft Exchange Server OWA Outlook 2003 denial of service
15782| [12652] Microsoft Windows 2000 and NT 4.0 Server IIS ISAPI nsiislog.dll extension POST request buffer overflow
15783| [12620] Microsoft Windows 2000 Server SMTP FILETIME denial of service
15784| [12543] Microsoft Windows 2000 Accessibility Utility Manager could allow an attacker to gain privileges
15785| [12493] Microsoft Windows Shell32.dll 2000 ShellExecute function buffer overflow
15786| [12489] Microsoft Windows 2000 Server Active Directory buffer overflow
15787| [12128] Microsoft Windows 2000 and Windows NT MS03-019 patch is not installed
15788| [12092] Microsoft Windows 2000 and NT 4.0 Server IIS ISAPI nsiislog.dll extension buffer overflow
15789| [12048] Microsoft Windows 2000 and Windows Server 2003 LAN Manager hash creation enabled
15790| [11901] Microsoft BizTalk Server 2002 SQL injection
15791| [11900] Microsoft BizTalk Server 2002 HTTP Receiver function buffer overflow
15792| [11816] Microsoft Windows 2000 Terminal Services MSGINA.DLL insecure access permissions
15793| [11696] Microsoft Windows 2000 Terminal Services man-in-the-middle attack
15794| [11617] Microsoft Windows 2000 MS03-007 patch is not installed on the system
15795| [11546] Microsoft Windows 2000 Windows Help Facility .cnt file buffer overflow
15796| [11329] Microsoft Windows NT and 2000 cmd.exe CD path name buffer overflow
15797| [11274] Microsoft Windows 2000 NetBIOS continuation packets denial of service
15798| [11273] Microsoft Windows 2000 RPC service could allow an attacker to gain elevated privileges
15799| [11216] Microsoft Windows NT and 2000 command prompt denial of service
15800| [11141] Microsoft Windows 2000 Terminal Services MSGINA.DLL denial of service
15801| [11133] Microsoft Outlook 2002 using V1 Exchange Server Security certificates transmits plaintext emails
15802| [10843] Microsoft Windows 2000 and XP SMB signing group policy modification
15803| [10431] Microsoft Windows 2000 SNMP LANMAN Extension memory leak denial of service
15804| [10400] Microsoft Windows 2000 RPC TCP port 135 denial of service
15805| [10377] Microsoft Windows XP and 2000 administrative alerts fail when security event log is full
15806| [10199] Microsoft Windows 2000/XP PPTP packet buffer overflow
15807| [10195] Microsoft FrontPage Server Extensions (FPSE) 2002 SmartHTML Interpreter buffer overflow
15808| [10194] Microsoft FrontPage Server Extensions (FPSE) 2000 SmartHTML Interpreter denial of service
15809| [9946] Microsoft Windows 2000 Terminal Services session screensaver fails to lock the console
15810| [9856] Microsoft Windows 2000 NCM handler routine could allow elevated privileges
15811| [9779] Microsoft Windows 2000 weak system partition permissions
15812| [9752] Microsoft Windows 2000 Service Pack 3 is not installed
15813| [9746] Microsoft Windows 2000 HTML Help item parameter buffer overflow
15814| [9625] Microsoft Windows 2000 Narrator allows login information to be audible
15815| [9154] Microsoft Data Engine (MSDE) and Microsoft SQL Server 2000 Desktop Engine have a default blank "
15816| [8867] Microsoft Windows 2000 LanMan denial of service
15817| [8813] Microsoft Windows 2000 Terminal Services allows attacker to bypass group policy settings
15818| [8759] Microsoft Windows 2000 could allow an attacker to block the application of Group Policy settings
15819| [8752] Microsoft Windows NT, 2000, and XP MUP buffer overflow
15820| [8739] Microsoft Windows 2000 DCOM memory leak
15821| [8708] Microsoft Outlook 2000 and 2002 executes embedded script in object tag when replying or forwarding HTML mail
15822| [8402] Microsoft Windows 2000 allows an attacker to bypass password policy
15823| [8307] Microsoft Windows 2000, Windows XP, and Exchange 2000 SMTP data transfer command denial of service
15824| [8304] Microsoft Windows 2000 and Exchange 5.5 SMTP service unauthorized mail privileges
15825| [8254] Microsoft Commerce Server 2000 AuthFilter ISAPI filter buffer overflow
15826| [8199] Microsoft Windows 2000 Terminal Services unlocked client
15827| [8094] Microsoft Windows 2000 and Interix 2.2 Telnet protocol option buffer overflow
15828| [8092] Microsoft Exchange 2000 System Attendant sets incorrect registry permissions
15829| [8043] Microsoft Windows NT, 2000, and XP using NTFS could allow files to be hidden
15830| [8037] Microsoft Windows 2000 empty TCP packet denial of service
15831| [8023] Microsoft Windows NT and Windows 2000 SIDs could allow an attacker to gain elevated privileges in another domain
15832| [7919] Microsoft IIS 4.0 and Norton Internet Security 2001 default permissions could allow an attacker to modify log files
15833| [7667] Microsoft Windows 2000 IKE UDP packet flood denial of service
15834| [7566] Microsoft IIS 2.0 and 3.0 upgraded to Microsoft IIS 4.0 fails to remove the ism.dll file
15835| [7538] Microsoft Windows 2000 and XP Terminal services allow an attacker to spoof IP addresses
15836| [7533] Microsoft Windows 2000 RunAs service denial of service
15837| [7532] Microsoft Windows 2000 RunAs service allows local attacker to bypass pipe authentication
15838| [7531] Microsoft Windows 2000 RunAs service reveals sensitive information
15839| [7528] Microsoft Windows NT and Windows 2000 malformed RPC request denial of service
15840| [7409] Microsoft Windows 2000 and Windows XP GDI denial of service
15841| [7302] Microsoft Windows NT and 2000 Terminal Server malformed RDP packet series denial of service
15842| [7008] Microsoft Windows 2000 IrDA device denial of service
15843| [6977] Microsoft Windows NT and 2000 NNTP memory leak denial of service
15844| [6931] Microsoft Windows 2000 without Service Pack 2
15845| [6919] Microsoft Windows 2000 Task Manager does not terminate malicious files with the same name as a system process
15846| [6912] Microsoft Windows NT and 2000 Terminal Server RDP memory leak denial of service
15847| [6876] Microsoft Windows 2000 could allow an attacker to change network passwords
15848| [6803] Microsoft Windows 2000 SMTP service allows mail relaying
15849| [6745] Microsoft Windows 2000 LDAP function could allow domain user password change
15850| [6669] Microsoft Windows 2000 Telnet system call denial of service
15851| [6668] Microsoft Windows 2000 Telnet handle leak denial of service
15852| [6667] Microsoft Windows 2000 Telnet multiple idle sessions denial of service
15853| [6666] Microsoft Windows 2000 Telnet username denial of service
15854| [6665] Microsoft Windows 2000 Telnet service weak domain authentication
15855| [6664] Microsoft Windows 2000 Telnet service predictable pipe names could allow elevation of privileges
15856| [6652] Microsoft Exchange 2000 OWA script execution
15857| [6590] Microsoft Windows 2000 debug registers allow attacker to gain elevated privileges
15858| [6506] Microsoft Windows 2000 Server Kerberos denial of service
15859| [6443] Microsoft Windows 2000 catalog file could remove installed hotfixes
15860| [6160] Microsoft Windows 2000 event viewer buffer overflow
15861| [6136] Microsoft Windows 2000 domain controller denial of service
15862| [6035] Microsoft Windows 2000 Server RDP denial of service
15863| [5973] Microsoft Windows 2000 EFS allows local user to recover sensitive data
15864| [5936] Microsoft Windows 2000 Server Directory Service Restore Mode allows user to login with blank password
15865| [5800] Microsoft Windows 2000 Index Service ActiveX controls allow unauthorized access to file information
15866| [5623] Microsoft Windows NT and 2000 Phone Book service buffer overflow
15867| [5598] Microsoft Windows 2000 Telnet daemon could allow a denial of service
15868| [5585] Microsoft Windows 2000 brute force attack
15869| [5502] Microsoft Windows 2000 Indexing Services ixsso.query
15870| [5467] Microsoft Windows 2000 System Monitor ActiveX control buffer overflow
15871| [5399] Microsoft Windows NT and 2000 Network Monitor buffer overflow
15872| [5301] Microsoft Windows 2000 Simplified Chinese IME State Recognition
15873| [5263] Microsoft Office 2000 executes .dll without users knowledge
15874| [5242] Microsoft Windows 2000 Telnet client NTLM authentication weakness
15875| [5222] Microsoft Windows 2000 malformed RPC packet denial of service
15876| [5203] Microsoft Windows 2000 still image service
15877| [5171] Microsoft Windows 2000 Local Security Policy corruption
15878| [5080] Microsoft Office 2000 HTML object tag buffer overflow
15879| [5033] Microsoft Windows 2000 without Service Pack 1
15880| [5031] Microsoft Windows 2000 Service Control Manager named pipe could allow a unauthorized user to gain privileges
15881| [5015] Microsoft Windows NT and 2000 executable path
15882| [4887] Microsoft Windows 2000 Kerberos ticket renewed
15883| [4886] Microsoft Windows 2000 logon session reconnected
15884| [4885] Microsoft Windows 2000 logon session disconnected
15885| [4882] Microsoft Windows 2000 Kerberos pre-authentication failed
15886| [4873] Microsoft Windows 2000 user account mapped for logon
15887| [4872] Microsoft Windows 2000 account logon failed
15888| [4871] Microsoft Windows 2000 account used for logon
15889| [4855] Microsoft Windows 2000 group type change
15890| [4842] Microsoft Internet Explorer and Microsoft Powerpoint 2000 ActiveX object execution
15891| [4841] Microsoft Internet Explorer and Microsoft Access 2000 VBA code execution
15892| [4823] Microsoft Windows 2000 Telnet server binary stream denial of service
15893| [4819] Microsoft Windows 2000 default SYSKEY configuration
15894| [4787] Microsoft Windows 2000 user account locked out
15895| [4786] Microsoft Windows 2000 computer account created
15896| [4785] Microsoft Windows 2000 computer account changed
15897| [4784] Microsoft Windows 2000 computer account deleted
15898| [4714] Microsoft Windows 2000 "
15899| [4589] Microsoft Windows 2000 protected store can be compromised by brute force attack
15900| [4278] Microsoft Windows 2000 unattended install does not secure All Users profile
15901| [4138] Microsoft Windows 2000 system file integrity feature is disabled
15902| [4086] Microsoft Windows 2000 may not start Jaz drives correctly
15903| [4085] Microsoft Windows 2000 non-Gregorial calendar error
15904| [4084] Microsoft Windows 2000 may prevent Adobe FrameMaker files from being saved in some formats
15905| [4083] Microsoft Windows 2000 Terminal Services may damage Office files saved as HTML
15906| [4082] Microsoft Windows 2000 and Iomega parallel port drives display error
15907| [4080] Microsoft Windows 2000 AOL image support
15908| [4079] Microsoft Windows 2000 High Encryption Pack
15909| [3854] Microsoft Office 2000 security setting
15910| [1376] Microsoft Proxy 2.0 denial of service
15911| [86256] Microsoft Windows Knowledge Base Article 2876063 update is not installed
15912| [86097] Microsoft Windows Knowledge Base Article 2859537 update is not installed
15913| [86091] Microsoft Windows Knowledge Base Article 2868623 update is not installed
15914| [86089] Microsoft Windows Knowledge Base Article 2862772 update is not installed
15915| [86075] Microsoft Windows Knowledge Base Article 2850869 update is not installed
15916| [86073] Microsoft Windows Knowledge Base Article 2873872 update is not installed
15917| [86070] Microsoft Windows Knowledge Base Article 2849568 update is not installed
15918| [85245] Microsoft Windows Knowledge Base Article 2848295 update is not installed
15919| [85244] Microsoft Windows Knowledge Base Article 2847927 update is not installed
15920| [85243] Microsoft Windows Knowledge Base Article 2861561 update is not installed
15921| [85236] Microsoft Windows Knowledge Base Article 2850851 update is not installed
15922| [85227] Microsoft Windows Knowledge Base Article 2847883 update is not installed
15923| [85223] Microsoft Windows Knowledge Base Article 2846071 update is not installed
15924| [85205] Microsoft Windows Knowledge Base Article 2845187 update is not installed
15925| [84621] Microsoft Windows Knowledge Base Article 2845690 update is not installed
15926| [84619] Microsoft Windows Knowledge Base Article 2839894 update is not installed
15927| [84617] Microsoft Windows Knowledge Base Article 2839571 update is not installed
15928| [84615] Microsoft Windows Knowledge Base Article 2839229 update is not installed
15929| [84613] Microsoft Windows Knowledge Base Article 2838727 update is not installed
15930| [84156] Microsoft Windows Knowledge Base Article 2847204 update is not installed
15931| [83912] Microsoft Windows Knowledge Base Article 2829254 update is not installed
15932| [83910] Microsoft Windows Knowledge Base Article 2829530 update is not installed
15933| [83898] Microsoft Windows Knowledge Base Article 2830397 update is not installed
15934| [83886] Microsoft Windows Knowledge Base Article 2830399 update is not installed
15935| [83884] Microsoft Windows Knowledge Base Article 2834692 update is not installed
15936| [83882] Microsoft Windows Knowledge Base Article 2834695 update is not installed
15937| [83880] Microsoft Windows Knowledge Base Article 2836440 update is not installed
15938| [83876] Microsoft Windows Knowledge Base Article 2840221 update is not installed
15939| [83192] Microsoft Windows Knowledge Base Article 2817183 update is not installed
15940| [83100] Microsoft Windows Knowledge Base Article 2830914 update is not installed
15941| [83098] Microsoft Windows Knowledge Base Article 2829996 update is not installed
15942| [83093] Microsoft Windows Knowledge Base Article 2828223 update is not installed
15943| [83091] Microsoft Windows Knowledge Base Article 2813170 update is not installed
15944| [83088] Microsoft Windows Knowledge Base Article 2827663 update is not installed
15945| [83086] Microsoft Windows Knowledge Base Article 2823482 update is not installed
15946| [83084] Microsoft Windows Knowledge Base Article 2821818 update is not installed
15947| [83082] Microsoft Windows Knowledge Base Article 2820917 update is not installed
15948| [82600] Microsoft Windows Knowledge Base Article 2813707 update is not installed
15949| [82424] Microsoft Windows Knowledge Base Article 2814124 update is not installed
15950| [82422] Microsoft Windows Knowledge Base Article 2780176 update is not installed
15951| [82401] Microsoft Windows Knowledge Base Article 2813682 update is not installed
15952| [82399] Microsoft Windows Knowledge Base Article 2816264 update is not installed
15953| [81683] Microsoft Windows Knowledge Base Article 2780091 update is not installed
15954| [81681] Microsoft Windows Knowledge Base Article 2784242 update is not installed
15955| [81680] Microsoft Windows Knowledge Base Article 2790113 update is not installed
15956| [81678] Microsoft Windows Knowledge Base Article 2790655 update is not installed
15957| [81676] Microsoft Windows Knowledge Base Article 2790978 update is not installed
15958| [81674] Microsoft Windows Knowledge Base Article 2797052 update is not installed
15959| [81672] Microsoft Windows Knowledge Base Article 2799494 update is not installed
15960| [81666] Microsoft Windows Knowledge Base Article 2778344 update is not installed
15961| [81634] Microsoft Windows Knowledge Base Article 2792100 update is not installed
15962| [81339] Microsoft Windows Knowledge Base Article 2799329 update is not installed
15963| [80875] Microsoft Windows Knowledge Base Article 2756145 update is not installed
15964| [80872] Microsoft Windows Knowledge Base Article 2769324 update is not installed
15965| [80867] Microsoft Windows Knowledge Base Article 2769327 update is not installed
15966| [80865] Microsoft Windows Knowledge Base Article 2769369 update is not installed
15967| [80863] Microsoft Windows Knowledge Base Article 2778930 update is not installed
15968| [80861] Microsoft Windows Knowledge Base Article 2785220 update is not installed
15969| [80365] Microsoft Windows Knowledge Base Article 2761465 update is not installed
15970| [80360] Microsoft Windows Knowledge Base Article 2765809 update is not installed
15971| [80358] Microsoft Windows Knowledge Base Article 2770660 update is not installed
15972| [80356] Microsoft Windows Knowledge Base Article 2780642 update is not installed
15973| [80352] Microsoft Windows Knowledge Base Article 2783534 update is not installed
15974| [80349] Microsoft Windows Knowledge Base Article 2784126 update is not installed
15975| [79693] Microsoft Windows Knowledge Base Article 2745030 update is not installed
15976| [79687] Microsoft Windows Knowledge Base Article 2761451 update is not installed
15977| [79683] Microsoft Windows Knowledge Base Article 2761226 update is not installed
15978| [79679] Microsoft Windows Knowledge Base Article 2758857 update is not installed
15979| [79677] Microsoft Windows Knowledge Base Article 2727528 update is not installed
15980| [78864] Microsoft Windows Knowledge Base Article 2754670 update is not installed
15981| [78862] Microsoft Windows Knowledge Base Article 2743555 update is not installed
15982| [78858] Microsoft Windows Knowledge Base Article 2754849 update is not installed
15983| [78856] Microsoft Windows Knowledge Base Article 2724197 update is not installed
15984| [78853] Microsoft Windows Knowledge Base Article 2741517 update is not installed
15985| [78851] Microsoft Windows Knowledge Base Article 2742319 update is not installed
15986| [78848] Microsoft Windows Knowledge Base Article 2742321 update is not installed
15987| [78760] Microsoft Windows Knowledge Base Article 2744842 update is not installed
15988| [78077] Microsoft Windows Knowledge Base Article 2741528 update is not installed
15989| [78075] Microsoft Windows Knowledge Base Article 2720184 update is not installed
15990| [78071] Microsoft Windows Knowledge Base Article 2748552 update is not installed
15991| [77512] Microsoft Windows Knowledge Base Article 2740358 update is not installed
15992| [77362] Microsoft Windows Knowledge Base Article 2733918 update is not installed
15993| [77360] Microsoft Windows Knowledge Base Article 2733829 update is not installed
15994| [77357] Microsoft Windows Knowledge Base Article 2733594 update is not installed
15995| [77352] Microsoft Windows Knowledge Base Article 2731879 update is not installed
15996| [77350] Microsoft Windows Knowledge Base Article 2731847 update is not installed
15997| [77348] Microsoft Windows Knowledge Base Article 2723135 update is not installed
15998| [77346] Microsoft Windows Knowledge Base Article 2722913 update is not installed
15999| [77342] Microsoft Windows Knowledge Base Article 2720573 update is not installed
16000| [77325] Microsoft Windows Knowledge Base Article 2719584 update is not installed
16001| [76808] Microsoft Windows Knowledge Base Article 2721015 update is not installed
16002| [76725] Microsoft Windows Knowledge Base Article 2722479 update is not installed
16003| [76724] Microsoft Windows Knowledge Base Article 2719177 update is not installed
16004| [76721] Microsoft Windows Knowledge Base Article 2718523 update is not installed
16005| [76718] Microsoft Windows Knowledge Base Article 2698365 update is not installed
16006| [76711] Microsoft Windows Knowledge Base Article 2695502 update is not installed
16007| [76704] Microsoft Windows Knowledge Base Article 2691442 update is not installed
16008| [76702] Microsoft Windows Knowledge Base Article 2655992 update is not installed
16009| [75963] Microsoft Windows Knowledge Base Article 2699988 update is not installed
16010| [75939] Microsoft Windows Knowledge Base Article 2685939 update is not installed
16011| [75928] Microsoft Windows Knowledge Base Article 2711167 update is not installed
16012| [75136] Microsoft Windows Knowledge Base Article 2693777 update is not installed
16013| [75132] Microsoft Windows Knowledge Base Article 2690533 update is not installed
16014| [75130] Microsoft Windows Knowledge Base Article 2688338 update is not installed
16015| [75127] Microsoft Windows Knowledge Base Article 2681578 update is not installed
16016| [75123] Microsoft Windows Knowledge Base Article 2680352 update is not installed
16017| [75116] Microsoft Windows Knowledge Base Article 2597981 update is not installed
16018| [74556] Microsoft Windows Knowledge Base Article 2639185 update is not installed
16019| [74384] Microsoft Windows Knowledge Base Article 2675157 update is not installed
16020| [74378] Microsoft Windows Knowledge Base Article 2671605 update is not installed
16021| [74373] Microsoft Windows Knowledge Base Article 2664258 update is not installed
16022| [74369] Microsoft Windows Knowledge Base Article 2663860 update is not installed
16023| [73543] Microsoft Windows Knowledge Base Article 2671387 update is not installed
16024| [73540] Microsoft Windows Knowledge Base Article 2665364 update is not installed
16025| [73538] Microsoft Windows Knowledge Base Article 2651019 update is not installed
16026| [73536] Microsoft Windows Knowledge Base Article 2651018 update is not installed
16027| [73533] Microsoft Windows Knowledge Base Article 2647170 update is not installed
16028| [73530] Microsoft Windows Knowledge Base Article 2641653 update is not installed
16029| [72887] Microsoft Windows Knowledge Base Article 2663841 update is not installed
16030| [72873] Microsoft Windows Knowledge Base Article 2663830 update is not installed
16031| [72867] Microsoft Windows Knowledge Base Article 2663510 update is not installed
16032| [72857] Microsoft Windows Knowledge Base Article 2661637 update is not installed
16033| [72855] Microsoft Windows Knowledge Base Article 2660465 update is not installed
16034| [72853] Microsoft Windows Knowledge Base Article 2653956 update is not installed
16035| [72851] Microsoft Windows Knowledge Base Article 2654428 update is not installed
16036| [72849] Microsoft Windows Knowledge Base Article 2651026 update is not installed
16037| [72846] Microsoft Windows Knowledge Base Article 2647516 update is not installed
16038| [72841] Microsoft Windows Knowledge Base Article 2645640 update is not installed
16039| [72838] Microsoft Windows Knowledge Base Article 2643719 update is not installed
16040| [72029] Microsoft Windows Knowledge Base Article 2638420 update is not installed
16041| [72003] Microsoft Windows Knowledge Base Article 2646524 update is not installed
16042| [71998] Microsoft Windows Knowledge Base Article 2644615 update is not installed
16043| [71995] Microsoft Windows Knowledge Base Article 2643584 update is not installed
16044| [71994] Microsoft Windows Knowledge Base Article 2636391 update is not installed
16045| [71565] Microsoft Windows Knowledge Base Article 2648048 update is not installed
16046| [71562] Microsoft Windows Knowledge Base Article 2640241 update is not installed
16047| [71560] Microsoft Windows Knowledge Base Article 2640045 update is not installed
16048| [71558] Microsoft Windows Knowledge Base Article 2639417 update is not installed
16049| [71557] Microsoft Windows Knowledge Base Article 2639142 update is not installed
16050| [71554] Microsoft Windows Knowledge Base Article 2633171 update is not installed
16051| [71552] Microsoft Windows Knowledge Base Article 2624667 update is not installed
16052| [71550] Microsoft Windows Knowledge Base Article 2620712 update is not installed
16053| [71548] Microsoft Windows Knowledge Base Article 2618451 update is not installed
16054| [71546] Microsoft Windows Knowledge Base Article 2618444 update is not installed
16055| [71538] Microsoft Windows Knowledge Base Article 2590602 update is not installed
16056| [70951] Microsoft Windows Knowledge Base Article 2630837 update is not installed
16057| [70949] Microsoft Windows Knowledge Base Article 2620704 update is not installed
16058| [70947] Microsoft Windows Knowledge Base Article 2617657 update is not installed
16059| [70943] Microsoft Windows Knowledge Base Article 2588516 update is not installed
16060| [70152] Microsoft Windows Knowledge Base Article 2623699 update is not installed
16061| [70140] Microsoft Windows Knowledge Base Article 2652016 update is not installed
16062| [70130] Microsoft Windows Knowledge Base Article 2586448 update is not installed
16063| [70115] Microsoft Windows Knowledge Base Article 2567053 update is not installed
16064| [69501] Microsoft Windows Knowledge Base Article 2587634 update is not installed
16065| [69498] Microsoft Windows Knowledge Base Article 2587505 update is not installed
16066| [69492] Microsoft Windows Knowledge Base Article 2571621 update is not installed
16067| [69490] Microsoft Windows Knowledge Base Article 2570947 update is not installed
16068| [68840] Microsoft Windows Knowledge Base Article 2451858 update is not installed
16069| [68833] Microsoft Windows Knowledge Base Article 2567943 update is not installed
16070| [68831] Microsoft Windows Knowledge Base Article 2570222 update is not installed
16071| [68829] Microsoft Windows Knowledge Base Article 2567951 update is not installed
16072| [68827] Microsoft Windows Knowledge Base Article 2578230 update is not installed
16073| [68825] Microsoft Windows Knowledge Base Article 2546250 update is not installed
16074| [68823] Microsoft Windows Knowledge Base Article 2559049 update is not installed
16075| [68816] Microsoft Windows Knowledge Base Article 2556532 update is not installed
16076| [68814] Microsoft Windows Knowledge Base Article 2560656 update is not installed
16077| [68812] Microsoft Windows Knowledge Base Article 2560978 update is not installed
16078| [68809] Microsoft Windows Knowledge Base Article 2562485 update is not installed
16079| [68806] Microsoft Windows Knowledge Base Article 2566454 update is not installed
16080| [68804] Microsoft Windows Knowledge Base Article 2563894 update is not installed
16081| [68801] Microsoft Windows Knowledge Base Article 2567680 update is not installed
16082| [68315] Microsoft Windows Knowledge Base Article 2555917 update is not installed
16083| [68299] Microsoft Windows Knowledge Base Article 2566220 update is not installed
16084| [68283] Microsoft Windows Knowledge Base Article 2560847 update is not installed
16085| [67955] Microsoft Windows Knowledge Base Article 2530548 update is not installed
16086| [67943] Microsoft Windows Knowledge Base Article 2544521 update is not installed
16087| [67762] Microsoft Windows Knowledge Base Article 2543893 update is not installed
16088| [67759] Microsoft Windows Knowledge Base Article 2544893 update is not installed
16089| [67757] Microsoft Windows Knowledge Base Article 2476490 update is not installed
16090| [67753] Microsoft Windows Knowledge Base Article 2514842 update is not installed
16091| [67751] Microsoft Windows Knowledge Base Article 2518295 update is not installed
16092| [67737] Microsoft Windows Knowledge Base Article 2520426 update is not installed
16093| [67733] Microsoft Windows Knowledge Base Article 2525694 update is not installed
16094| [67731] Microsoft Windows Knowledge Base Article 2525835 update is not installed
16095| [67728] Microsoft Windows Knowledge Base Article 2535512 update is not installed
16096| [67725] Microsoft Windows Knowledge Base Article 2536275 update is not installed
16097| [67722] Microsoft Windows Knowledge Base Article 2536276 update is not installed
16098| [67718] Microsoft Windows Knowledge Base Article 2537146 update is not installed
16099| [67709] Microsoft Windows Knowledge Base Article 2538814 update is not installed
16100| [67302] Microsoft Windows Knowledge Base Article 2545814 update is not installed
16101| [67101] Microsoft Windows Knowledge Base Article 2524426 update is not installed
16102| [66446] Microsoft Windows Knowledge Base Article 2514666 update is not installed
16103| [66444] Microsoft Windows Knowledge Base Article 2511455 update is not installed
16104| [66436] Microsoft Windows Knowledge Base Article 2497640 update is not installed
16105| [66432] Microsoft Windows Knowledge Base Article 2527308 update is not installed
16106| [66428] Microsoft Windows Knowledge Base Article 2489979 update is not installed
16107| [66423] Microsoft Windows kernel-mode driver (win32k.sys) variant 29 privilege escalation
16108| [66422] Microsoft Windows kernel-mode driver (win32k.sys) variant 28 privilege escalation
16109| [66421] Microsoft Windows kernel-mode driver (win32k.sys) variant 27 privilege escalation
16110| [66420] Microsoft Windows kernel-mode driver (win32k.sys) variant 26 privilege escalation
16111| [66419] Microsoft Windows kernel-mode driver (win32k.sys) variant 25 privilege escalation
16112| [66418] Microsoft Windows kernel-mode driver (win32k.sys) variant 24 privilege escalation
16113| [66417] Microsoft Windows kernel-mode driver (win32k.sys) variant 23 privilege escalation
16114| [66416] Microsoft Windows kernel-mode driver (win32k.sys) variant 22 privilege escalation
16115| [66415] Microsoft Windows kernel-mode driver (win32k.sys) variant 21 privilege escalation
16116| [66414] Microsoft Windows kernel-mode driver (win32k.sys) variant 20 privilege escalation
16117| [66396] Microsoft Windows kernel-mode driver (win32k.sys) variant 2 privilege escalation
16118| [66394] Microsoft Windows Knowledge Base Article 2485663 update is not installed
16119| [65588] Microsoft Windows Knowledge Base Article 2489279 update is not installed
16120| [65581] Microsoft Windows Knowledge Base Article 2510030 update is not installed
16121| [65580] Microsoft Windows Knowledge Base Article 2489283 update is not installed
16122| [65575] Microsoft Windows Knowledge Base Article 2489293 update is not installed
16123| [65573] Microsoft Windows Knowledge Base Article 2494047 update is not installed
16124| [64973] Microsoft Windows Knowledge Base Article 2478960 update is not installed
16125| [64971] Microsoft Windows Knowledge Base Article 2479628 update is not installed
16126| [64927] Microsoft Windows Knowledge Base Article 2393802 update is not installed
16127| [64925] Microsoft Windows Knowledge Base Article 2451879 update is not installed
16128| [64920] Microsoft Windows Knowledge Base Article 2475792 update is not installed
16129| [64918] Microsoft Windows Knowledge Base Article 2476687 update is not installed
16130| [64916] Microsoft Windows Knowledge Base Article 2478953 update is not installed
16131| [64914] Microsoft Windows Knowledge Base Article 2482017 update is not installed
16132| [64910] Microsoft Windows Knowledge Base Article 2483185 update is not installed
16133| [64909] Microsoft Windows Knowledge Base Article 2484015 update is not installed
16134| [64907] Microsoft Windows Knowledge Base Article 2485376 update is not installed
16135| [64905] Microsoft Windows Knowledge Base Article 2489256 update is not installed
16136| [64902] Microsoft Windows Knowledge Base Article 2496930 update is not installed
16137| [64342] Microsoft Windows Knowledge Base Article 2451910 update is not installed
16138| [64339] Microsoft Windows Knowledge Base Article 2478935 update is not installed
16139| [63584] Microsoft Windows Knowledge Base Article 2424434 update is not installed
16140| [63582] Microsoft Windows Knowledge Base Article 2423089 update is not installed
16141| [63580] Microsoft Windows Knowledge Base Article 2436673 update is not installed
16142| [63571] Microsoft Windows Knowledge Base Article 2440591 update is not installed
16143| [63569] Microsoft Windows Knowledge Base Article 2385678 update is not installed
16144| [63566] Microsoft Windows Knowledge Base Article 2442962 update is not installed
16145| [63564] Microsoft Windows Knowledge Base Article 2345316 update is not installed
16146| [63562] Microsoft Windows Knowledge Base Article 2296199 update is not installed
16147| [63558] Microsoft Windows Knowledge Base Article 2416400 update is not installed
16148| [63550] Microsoft Windows Knowledge Base Article 2447961 update is not installed
16149| [63548] Microsoft Windows Knowledge Base Article 2443105 update is not installed
16150| [63546] Microsoft Windows Knowledge Base Article 2455005 update is not installed
16151| [63544] Microsoft Windows Knowledge Base Article 2292970 update is not installed
16152| [62805] Microsoft Windows Knowledge Base Article 2316074 update is not installed
16153| [62793] Microsoft Windows Knowledge Base Article 2293386 update is not installed
16154| [62789] Microsoft Windows Knowledge Base Article 2423930 update is not installed
16155| [62170] Microsoft Windows Knowledge Base Article 2296011 update is not installed
16156| [62166] Microsoft Windows Knowledge Base Article 2294255 update is not installed
16157| [62163] Microsoft Windows Knowledge Base Article 2281679 update is not installed
16158| [62154] Microsoft Windows Knowledge Base Article 2279986 update is not installed
16159| [62147] Microsoft Windows Knowledge Base Article 2160841 update is not installed
16160| [62134] Microsoft Windows Knowledge Base Article 2412048 update is not installed
16161| [62129] Microsoft Windows Knowledge Base Article 2387149 update is not installed
16162| [62126] Microsoft Windows Knowledge Base Article 2378111 update is not installed
16163| [62123] Microsoft Windows Knowledge Base Article 2360937 update is not installed
16164| [62118] Microsoft Windows Knowledge Base Article 2293211 update is not installed
16165| [62104] Microsoft Windows Knowledge Base Article 2360131 update is not installed
16166| [62098] Microsoft Windows Knowledge Base Article 2293194 update is not installed
16167| [62069] Microsoft Windows Knowledge Base Article 2418042 update is not installed
16168| [61519] Microsoft Windows Knowledge Base Article 2121546 update is not installed
16169| [61517] Microsoft Windows Knowledge Base Article 2259922 update is not installed
16170| [61514] Microsoft Windows Knowledge Base Article 2267960 update is not installed
16171| [61510] Microsoft Windows Knowledge Base Article 2315011 update is not installed
16172| [61507] Microsoft Windows Knowledge Base Article 2320113 update is not installed
16173| [61504] Microsoft Windows Knowledge Base Article 2347290 update is not installed
16174| [60736] Microsoft Windows Knowledge Base Article 2265906 update is not installed
16175| [60734] Microsoft Windows Knowledge Base Article 2269638 update is not installed
16176| [60728] Microsoft Windows Knowledge Base Article 2269707 update is not installed
16177| [60724] Microsoft Windows Knowledge Base Article 2286198 update is not installed
16178| [60713] Microsoft Windows Knowledge Base Article 2183461 update is not installed
16179| [60698] Microsoft Windows Knowledge Base Article 2160329 update is not installed
16180| [60686] Microsoft Windows Knowledge Base Article 2115168 update is not installed
16181| [60684] Microsoft Windows Knowledge Base Article 2079403 update is not installed
16182| [60680] Microsoft Windows Knowledge Base Article 2264072 update is not installed
16183| [59901] Microsoft Windows Knowledge Base Article 2229593 update is not installed
16184| [59898] Microsoft Windows Knowledge Base Article 2229593 update is not installed
16185| [58913] Microsoft Windows Knowledge Base Article 2027452 update is not installed
16186| [58891] Microsoft Windows Knowledge Base Article 2028554 update is not installed
16187| [17004] Microsoft Windows XP Service Pack 2 is not installed on the system
16188| [9187] Microsoft Passport SDK 2.1 Component Configuration Document (CCD) permission
16189| [9146] Microsoft Passport SDK 2.1 events reporting disabled
16190| [9068] Microsoft Passport SDK 2.1 registry default permission exposure
16191| [9067] Microsoft Passport SDK 2.1 default test site exposure
16192| [9066] Microsoft Passport SDK 2.1 Adventure Works Sample Site exposure
16193| [9065] Microsoft Passport SDK 2.1 Adventure Works Sample Site global.asa file default permission exposure
16194| [9064] Microsoft Passport SDK 2.1 default time window exposure
16195| [1271] Microsoft IIS version 2 installed
16196| [621] Microsoft IIS 3.0 script source revealed by appending 2E to requests
16197|
16198| Exploit-DB - https://www.exploit-db.com:
16199| [30756] Microsoft Forms 2.0 ActiveX Control 2.0 Memory Access Violation Denial of Service Vulnerabilities
16200| [30749] Microsoft Office 2003 Web Component Memory Access Violation Denial of Service Vulnerability
16201| [30636] Microsoft Windows 2000/2003 Recursive DNS Spoofing Vulnerability (2)
16202| [30635] Microsoft Windows 2000/2003 Recursive DNS Spoofing Vulnerability (1)
16203| [30281] Microsoft .Net Framework <= 2.0 - Multiple Null Byte Injection Vulnerabilities
16204| [29664] Microsoft Office Publisher 2007 - Remote Denial of Service (DoS) Vulnerability
16205| [29660] Microsoft Office 2003 - Denial of Service (DoS) Vulnerability
16206| [29630] Microsoft Windows 2003/XP ReadDirectoryChangesW Information Disclosure Vulnerability
16207| [29524] Microsoft Word 2000 - Malformed Function Code Execution Vulnerability
16208| [28420] Microsoft Windows 2000 Multiple COM Object Instantiation Code Execution Vulnerabilities
16209| [28357] Microsoft Windows Explorer 2000/2003/XP Drag and Drop Remote Code Execution Vulnerability
16210| [28227] Microsoft Windows 2000/XP Registry Access Local Denial of Service Vulnerability
16211| [28226] Microsoft PowerPoint 2003 PPT File Closure Memory Corruption
16212| [28225] Microsoft PowerPoint 2003 powerpnt.exe Unspecified Issue
16213| [28224] Microsoft PowerPoint 2003 mso.dll PPT Processing Unspecified Code Execution
16214| [28198] Microsoft Office 2000/2002 Property Code Execution Vulnerability
16215| [28189] Microsoft Excel 2000-2004 Style Handling and Repair Remote Code Execution Vulnerability
16216| [28087] Microsoft Office 2003 Embedded Shockwave Flash Object Security Bypass Weakness
16217| [28005] Microsoft Exchange Server 2000/2003 Outlook Web Access Script Injection Vulnerability
16218| [26690] Microsoft Windows 2000/2003/XP CreateRemoteThread Local Denial of Service Vulnerability
16219| [26517] Microsoft Office PowerPoint 2007 - Crash PoC
16220| [26341] Microsoft Windows 2000/2003/XP MSDTC TIP Denial of Service Vulnerability
16221| [26222] Microsoft Windows 2000/2003/XP Keyboard Event Privilege Escalation Weakness
16222| [25384] Microsoft Windows 2000/XP Internet Protocol Validation Remote Code Execution Vulnerability (2)
16223| [25383] Microsoft Windows 2000/XP Internet Protocol Validation Remote Code Execution Vulnerability (1)
16224| [25231] Microsoft Windows 2000/2003/XP Graphical Device Interface Library Denial of Service Vulnerability
16225| [25085] Microsoft Office XP 2000/2002 HTML Link Processing Remote Buffer Overflow Vulnerability
16226| [25084] Microsoft Outlook 2003 Web Access Login Form Remote URI Redirection Vulnerability
16227| [25050] Microsoft Windows 2000/2003/XP winhlp32 Phrase Heap Overflow Vulnerability
16228| [25049] Microsoft Windows 2000/2003/XP winhlp32 Phrase Integer Overflow Vulnerability
16229| [24686] Microsoft Outlook 2003 Security Policy Bypass Vulnerability
16230| [24277] Microsoft Windows 2000/NT 4 POSIX Subsystem Buffer Overflow Local Privilege Escalation Vulnerability
16231| [24114] Microsoft Outlook 2003Mail Client E-mail Address Verification Weakness
16232| [24101] Microsoft Outlook 2003 Predictable File Location Weakness
16233| [23989] Microsoft Windows 2000/NT 4 Local Descriptor Table Local Privilege Escalation Vulnerability
16234| [23796] Microsoft Outlook 2002 Mailto Parameter Quoting Zone Bypass Vulnerability
16235| [23019] Microsoft Windows 2000 Subnet Bandwidth Manager RSVP Server Authority Hijacking Vulnerability
16236| [22919] Microsoft ISA Server 2000 Cross-Site Scripting Vulnerabilities
16237| [22883] Microsoft Windows 2000 CreateFile API Named Pipe Privilege Escalation Vulnerability (2)
16238| [22882] Microsoft Windows 2000 CreateFile API Named Pipe Privilege Escalation Vulnerability (1)
16239| [22837] Microsoft Windows 2000/NT 4 Media Services NSIISlog.DLL Remote Buffer Overflow
16240| [22782] Microsoft Windows 2000 Active Directory Remote Stack Overflow Vulnerability
16241| [22591] Microsoft Office Excel 2007 - WriteAV Crash PoC
16242| [22555] Microsoft BizTalk Server 2000/2002 DTA RawCustomSearchField.asp SQL Injection
16243| [22554] Microsoft BizTalk Server 2000/2002 DTA rawdocdata.asp SQL Injection Vulnerability
16244| [22553] Microsoft BizTalk Server 2002 HTTP Receiver Buffer Overflow Vulnerability
16245| [22528] Microsoft Windows 2000 RegEdit.EXE Registry Key Value Buffer Overflow Vulnerability
16246| [22354] Microsoft Windows 2000 Help Facility .CNT File :Link Buffer Overflow Vulnerability
16247| [21920] Microsoft Content Management Server 2001 Cross-Site Scripting Vulnerability
16248| [21718] Microsoft SQL 2000/7.0 Agent Jobs Privilege Elevation Vulnerability
16249| [21693] Microsoft SQL Server 2000 User Authentication Remote Buffer Overflow Vulnerability
16250| [21652] Microsoft SQL Server 2000 Resolution Service Heap Overflow Vulnerability
16251| [21651] Microsoft SQL Server 2000 sp_MScopyscript SQL Injection Vulnerability
16252| [21650] Microsoft SQL Server 2000 Database Consistency Checkers Buffer Overflow Vulnerability
16253| [21549] Microsoft SQL Server 2000 Password Encrypt Procedure Buffer Overflow Vulnerability
16254| [21541] Microsoft SQL Server 2000 SQLXML Script Injection Vulnerability
16255| [21540] Microsoft SQL Server 2000 SQLXML Buffer Overflow Vulnerability
16256| [21389] Microsoft Windows 2000 Lanman Denial of Service Vulnerability (2)
16257| [21388] Microsoft Windows 2000 Lanman Denial of Service Vulnerability (1)
16258| [21344] Microsoft Windows 2000 / NT 4.0 Process Handle Local Privilege Elevation Vulnerability
16259| [21258] Microsoft Windows 2000/NT 4 NTFS File Hiding Vulnerability
16260| [21246] Microsoft Windows 2000/NT 4 TCP Stack DoS Vulnerability (2)
16261| [21245] Microsoft Windows 2000/NT 4 TCP Stack DoS Vulnerability (1)
16262| [21172] Microsoft Windows 2000 Internet Key Exchange DoS Vulnerability (2)
16263| [21171] Microsoft Windows 2000 Internet Key Exchange DoS Vulnerability (1)
16264| [21131] Microsoft Windows 2000/XP GDI Denial of Service Vulnerability
16265| [21123] Microsoft Windows 2000/NT Terminal Server Service RDP DoS Vulnerability
16266| [21113] Microsoft Index Server 2.0 File Information and Path Disclosure Vulnerability
16267| [21099] Microsoft Windows 2000 RunAs Service Denial of Services Vulnerability
16268| [21069] Microsoft Windows 2000 RunAs Service Named Pipe Hijacking Vulnerability
16269| [20907] Microsoft Windows 2000 Telnet Username DoS Vulnerability
16270| [20802] Microsoft IIS 2.0/3.0 Long URL Denial of Service Vulnerability
16271| [20763] Microsoft ISA Server 2000 Web Proxy DoS Vulnerability
16272| [20571] Microsoft Outlook 2000 0/98 0/Express 5.5 Concealed Attachment Vulnerability
16273| [20481] Microsoft IIS 2.0/3.0 Appended Dot Script Source Disclosure Vulnerability
16274| [20399] Microsoft Indexing Services for Windows 2000 File Verification Vulnerability
16275| [20335] Microsoft Indexing Services for Windows 2000/NT 4.0 .htw Cross-Site Scripting Vulnerability
16276| [20305] Microsoft Site Server 2.0 with IIS 4.0 - File Upload Vulnerability
16277| [20265] Microsoft Windows NT 4.0 / 2000 Spoofed LPC Request Vulnerability
16278| [20257] Microsoft Windows NT 4.0 / 2000 Predictable LPC Message Identifier Multiple Vulnerabilities
16279| [20255] Microsoft Windows NT 4.0 / 2000 LPC Zone Memory Depletion DoS Vulnerability
16280| [20222] Microsoft Windows 2000 telnet.exe NTLM Authentication Vulnerability
16281| [20209] Microsoft Windows 2000 Still Image Service Privilege Escalation Vulnerability
16282| [20133] Microsoft Windows 2000 Named Pipes Predictability Vulnerability
16283| [20122] Microsoft Office SharePoint Server 2007 Remote Code Execution
16284| [20096] Microsoft IIS 2.0/3.0/4.0/5.0/5.1 Internal IP Address Disclosure Vulnerability
16285| [20048] Microsoft Windows 2000 Remote CPU-overload Vulnerability
16286| [20047] Microsoft Windows 2000 Telnet Server DoS Vulnerability
16287| [19830] Microsoft Index Server 2.0 '%20' ASP Source Disclosure Vulnerability
16288| [19742] microsoft iis 3.0/4.0,microsoft index server 2.0 - Directory Traversal
16289| [19734] Microsoft Virtual Machine 2000 Series/3000 Series getSystemResource Vulnerability
16290| [19731] microsoft index server 2.0/indexing services for windows 2000 - Directory Traversal
16291| [19728] Microsoft Systems Management Server 2.0 Default Permissions Vulnerability
16292| [19425] Microsoft Data Access Components (MDAC) <= 2.1,Microsoft IIS 3.0/4.0,Microsoft Index Server 2.0,Microsoft Site Server Commerce Edition 3.0 i386 MDAC RDS Vulnerability (2)
16293| [19424] Microsoft Data Access Components (MDAC) <= 2.1,Microsoft IIS 3.0/4.0,Microsoft Index Server 2.0,Microsoft Site Server Commerce Edition 3.0 i386 MDAC RDS Vulnerability (1)
16294| [19376] Microsoft IIS 2.0/3.0/4.0 ISAPI GetExtensionVersion() Vulnerability
16295| [19143] "Microsoft Windows ""April Fools 2001"" Vulnerability"
16296| [19118] Microsoft IIS 3.0/4.0,Microsoft Personal Web Server 2.0/3.0/4.0 ASP Alternate Data Streams Vulnerability
16297| [18334] Microsoft Office 2003 Home/Pro 0day
16298| [18087] MS11-021 Microsoft Office 2007 Excel .xlb Buffer Overflow
16299| [18078] Microsoft Excel 2003 11.8335.8333 Use After Free
16300| [18067] Microsoft Excel 2007 SP2 Buffer Overwrite Exploit
16301| [17305] "Microsoft Windows Vista/Server 2008 ""nsiproxy.sys"" Local Kernel DoS Exploit"
16302| [14971] MOAUB #11 - Microsoft Office Word 2007 sprmCMajority Buffer Overflow
16303| [14782] Microsoft Office PowerPoint 2007 DLL Hijacking Exploit (rpawinet.dll)
16304| [14746] Microsoft Office Groove 2007 DLL Hijacking Exploit (mso.dll)
16305| [14744] Microsoft Visio 2003 DLL Hijacking Exploit (mfc71enu.dll)
16306| [12450] Microsoft SharePoint Server 2007 XSS Vulnerability
16307| [10068] Microsoft Windows 2000-2008 Embedded OpenType Font Engine Remote Code Execution
16308| [4121] Microsoft Excel 2000/2003 Sheet Name Vulnerability PoC
16309| [3973] Microsoft Office 2000 (OUACTRL.OCX 1.0.1.9) - Remote DoS Exploit
16310| [3690] microsoft office word 2007 - Multiple Vulnerabilities
16311| [3260] Microsoft Word 2000 Unspecified Code Execution Exploit (0day)
16312| [2523] Microsoft Office 2003 PPT Local Buffer Overflow PoC
16313| [2091] Microsoft PowerPoint 2003 SP2 Local Code Execution Exploit (french)
16314| [2001] Microsoft Word 2000/2003 Unchecked Boundary Condition Vulnerability
16315| [1999] Microsoft Word 2000/2003 Hlink Local Buffer Overflow Exploit PoC
16316| [1988] Microsoft Excel 2003 Hlink Local Buffer Overflow Exploit (italian)
16317| [1986] Microsoft Excel 2000/2003 Hlink Local Buffer Overflow Exploit (french)
16318| [1958] Microsoft Excel 2003 Hlink Stack/SEH Buffer Overflow Exploit
16319| [28238] Microsoft SharePoint 2013 (Cloud) - Persistent Exception Handling Vulnerability MS13-067
16320| [23034] Microsoft URLScan 2.5/ RSA Security SecurID 5.0 Configuration Enumeration Weakness
16321| [22850] Microsoft Office OneNote 2010 Crash PoC
16322| [22679] Microsoft Visio 2010 Crash PoC
16323| [22655] Microsoft Publisher 2013 Crash PoC
16324| [22621] Microsoft Netmeeting 2.1/3.0.1 4.4.3385 CALLTO URL Buffer Overflow Vulnerability
16325| [22330] Microsoft Office Excel 2010 Crash PoC
16326| [22310] Microsoft Office Publisher 2010 Crash PoC
16327| [22237] Microsoft Office Picture Manager 2010 Crash PoC
16328| [22215] Microsoft Office Word 2010 Crash PoC
16329| [19451] Microsoft Windows 98 a/98 b/98SE,Solaris 2.6 IRDP Vulnerability
16330| [19440] Microsoft Windows NT 4.0/SP 1/SP 2/Sp 3/SP 4/SP 5 Malformed Dialer Entry Vulnerability
16331| [19372] Microsoft Windows NT 4.0/SP 1/SP 2/SP 3/SP 4/SP 5 Null Session Admin Name Vulnerability
16332| [17164] Microsoft Reader <= 2.1.1.3143 NULL Byte Write
16333| [17163] Microsoft Reader <= 2.1.1.3143 Array Overflow
16334| [17162] Microsoft Reader <= 2.1.1.3143 Integer Overflow
16335| [17161] Microsoft Reader <= 2.1.1.3143 Heap Overflow
16336| [17160] Microsoft Reader <= 2.1.1.3143 Integer Overflow
16337| [14731] Microsoft Windows Movie Maker <= 2.6.4038.0 DLL Hijacking Exploit (hhctrl.ocx)
16338| [14723] Microsoft Power Point 2010 DLL Hijacking Exploit (pptimpconv.dll)
16339|
16340| OpenVAS (Nessus) - http://www.openvas.org:
16341| [902250] Microsoft Word 2003 'MSO.dll' Null Pointer Dereference Vulnerability
16342| [900125] Microsoft SQL Server 2000 sqlvdir.dll ActiveX Buffer Overflow Vulnerability
16343| [801597] Microsoft Office Excel 2003 Invalid Object Type Remote Code Execution Vulnerability
16344| [801596] Microsoft Excel 2007 Office Drawing Layer Remote Code Execution Vulnerability
16345| [801594] Microsoft PowerPoint 2007 OfficeArt Atom Remote Code Execution Vulnerability
16346| [800687] Microsoft Windows Server 2003 OpenType Font Engine DoS Vulnerability
16347| [800577] Microsoft Windows Server 2003 win32k.sys DoS Vulnerability
16348| [800343] Microsoft Word 2007 Sensitive Information Disclosure Vulnerability
16349| [103254] Microsoft SharePoint Server 2007 '_layouts/help.aspx' Cross Site Scripting Vulnerability
16350| [11992] Vulnerability in Microsoft ISA Server 2000 H.323 Filter(816458)
16351| [902931] Microsoft Office Remote Code Execution Vulnerabilities - 2720184 (Mac OS X)
16352| [902678] Microsoft Silverlight Code Execution Vulnerabilities - 2681578 (Mac OS X)
16353| [901210] Microsoft Office Privilege Elevation Vulnerability - 2721015 (Mac OS X)
16354|
16355| SecurityTracker - https://www.securitytracker.com:
16356| [1015347] Microsoft Windows 2000 Kernel APC Queue Bug Lets Local Users Gain Elevated Privileges
16357| [1013454] Microsoft Office InfoPath 2003 May Disclose System and Authentication Information to Remote Users
16358| [1013284] Microsoft Windows 2000 and XP Group Policy Can Be Bypassed By Microsoft Office Applications and By Flash Drives
16359| [1010687] Microsoft Windows 2000/NT POSIX Subsystem Buffer Overflow Lets Local Users Gain Elevated Privileges
16360| [1010352] Microsoft Windows 2000 Domains With Eight Characters May Let Remote Users With Expired Passwords Login
16361| [1010189] Microsoft Outlook 2003 Scripting Restrictions Can Be Bypassed By Remote Users
16362| [1010125] Microsoft Outlook 2003 Lets Remote Users Send E-mail to Cause the Recipient's Client to Contact a Remote Server
16363| [1009767] Microsoft Windows 2000 Domain Controller LDAP Flaw May Let Remote Users Restart the Authentication Service
16364| [1008324] Microsoft Exchange 2003 With Outlook Web Access and Windows SharePoint Services May Grant Incorrect E-mail Account Access to Remote Authenticated Users
16365| [1007905] Microsoft Windows Server 2003 Shell Folders Can Be Referenced Using Directory Traversal Characters
16366| [1007238] Microsoft Outlook Web Access Can Be Crashed By Remote Authenticated Users With an Outlook 2003 Client
16367| [1007152] Microsoft Windows 2000 Accessibility Utility Manager Lets Local Users Gain Elevated Privileges
16368| [1007099] Microsoft Windows 2000 ShellExecute() Buffer Overflow May Let Users Execute Arbitrary Code
16369| [1007093] Microsoft Active Directory Stack Overflow in 'Lsaas.exe' Lets Remote Users Crash the Windows 2000 Server
16370| [1006959] Microsoft Windows Server 2003 Drivers May Leak Information From Memory Via Ethernet Packets Containing TCP Streams
16371| [1006580] Microsoft Windows 2003 'win2k.sys' Printing Bug Lets Users Crash the System
16372| [1006534] Microsoft Proxy Service in Proxy Server 2.0 Has Unspecified Flaw That Lets Remote Users Stop Traffic
16373| [1006286] Microsoft Windows 2000/XP PostMessage() API Flaw May Let Local Users Grab Passwords from Local Dialog Boxes
16374| [1006280] Protegrity Secure.Data for Microsoft SQL Server 2000 Contains Buffer Oveflows That Let Remote Users Execute Arbitrary Code
16375| [1005254] Microsoft NT, 2000, and XP Operating Systems May Execute a 16-bit Application Even When The File Has No Execute Permissions
16376| [1005068] Microsoft NTFS Filesystem in Windows NT and Windows 2000 Has Auditing Hole That Lets Local Users Access Files Without the File Access Being Audited
16377| [1004587] Microsoft SQL Server 2000 Buffer Overflow in OpenDataSource() Function May Let Remote Users Gain SYSTEM Privileges on the Server
16378| [1004528] Microsoft SQLXML Component of Microsoft SQL Server 2000 Contains an Input Validation Flaw in an XML SQL Tag That Allows Cross-Site Scripting Attacks
16379| [1004527] Microsoft SQLXML Component of Microsoft SQL Server 2000 Contains a Buffer Overflow That Lets Remote Users Take Full Control of the System
16380| [1004407] Microsoft Exchange 2000 Flaw in Processing a Certain Malformed SMTP Command Allows Remote Users to Deny Service to the Server
16381| [1004357] Microsoft Windows Debugging Facility for Windows NT4 and 2000 Has Authentication Hole That Lets Local Users Execute Arbitrary Code with SYSTEM Privileges
16382| [1004083] Microsoft Windows 2000 'microsoft-ds' Service Flaw Allows Remote Users to Create Denial of Service Conditions By Sending Malformed Packets
16383| [1004022] Microsoft Windows 2000 Group Policy Object Enforcement Can Be Circumvented if User License Limits are Exceeded
16384| [1003975] Microsoft Windows NT, 2000, and XP Kernel Buffer Overflow in Processing Multiple UNC Provider (MUP) Requests May Let Local Users Obtain System Level Privileges
16385| [1003949] Microsoft Windows 2000 DCOM Implementation Flaw May Disclose Memory Contents to Remote Users
16386| [1003816] Microsoft Windows 2000 Automatic Log Off Policy Fails to Expire Sessions in Progress
16387| [1003688] Microsoft Exchange Server 2000 Command Processing Bug Lets Remote Users Cause the SMTP Service to Crash
16388| [1003687] Microsoft Windows 2000 and Windows XP SMTP Service Command Processing Bug Lets Remote Users Cause the SMTP Service to Crash
16389| [1003634] Microsoft XML Core Services in SQL Server 2000 Lets Remote Scripts Access and Send Local Files
16390| [1003629] Microsoft Commerce Server 2000 AuthFilter Buffer Overflow Lets Remote Users Execute Arbitrary Code on the Server With LocalSystem Privileges to Gain Full Control of the Server
16391| [1003472] Microsoft Telnet Server for Windows 2000 and for Interix Has a Buffer Overflow That May Let Remote Users Execute Code on the Server with System Level Privileges
16392| [1003469] Microsoft Exchange 2000 Server Allows Remote Users to View and Possibly Modify Registry Settings
16393| [1003402] Microsoft Windows NT 4.0 and Windows 2000 Domain Controllers May Give Elevated Privileges to Remote Users Who Are Valid Administrators on Other Trusted Domains
16394| [1002922] Microsoft Windows 2000 Internet Key Exchange (IKE) Service Can Be Crashed By Remote Users
16395| [1002754] Terminal Services on Microsoft Windows 2000 and XP Allow Remote Users to Log Bogus IP Addresses Instead of the User's Genuine Address
16396| [1002731] Microsoft Windows 2000 RunAs Service May Disclose Authentication Credentials to Local Users
16397| [1002730] Microsoft Windows 2000 RunAs Utility May Disclose Sensitive Information to Local Users
16398| [1002729] Microsoft Windows 2000 RunAs Service Allows Local Users to Disable the Service
16399| [1002356] Microsoft Outlook 2000 Animated Assistant Prevents the Screen Saver from Activating, Allowing Physically Local Users to Access the System
16400| [1002206] Microsoft Internet Security and Acceleration (ISA) Server 2000 Can Be Disrupted By Remote Users Due to Memory Leaks and Also Allows Cross-Site Scripting Attacks
16401| [1002106] Microsoft Windows 2000 and Windows NT 4.0 RPC Input Validation Failure Lets Remote Users Destabilize the Operating System
16402| [1002099] Microsoft Windows 2000 Telnet Service Can Be Crashed By Remote Users
16403| [1002098] Windows Terminal Services in Microsoft Windows 2000 and NT 4.0 Can Be Crashed By Remote Users Due to a Memory Leak
16404| [1001993] Microsoft Windows 2000, Linux 2.4, NetBSD, FreeBSD, and OpenBSD May Let Remote Users Affect TCP Performance
16405| [1001931] Microsoft Windows 2000 SMTP Service May Allow Unauthorized Remote Users to Relay E-mail via the Service
16406| [1001832] Microsoft Windows 2000 LDAP Server Lets Remote Users Gain Administrator Access to the Domain Controller When Configured to Support LDAP over SSL
16407| [1001701] Microsoft Windows 2000 Telnet Server Allows Local Users to Gain System-Level Privileges and Lets Remote Users Crash the Server
16408| [1001605] Microsoft Windows 2000 Allows Local Users to Elevate Privileges
16409| [1001565] Microsoft IIS Web Server on Windows 2000 Allows Remote Users to Cause the Server to Consume All Available Memory Due to Memory Leak in WebDAV Lock Method
16410| [1001513] Microsoft Windows 2000 Indexing Service Allows Remote Users to View Include Programming Files
16411| [1001501] Microsoft Windows 2000 Domain Controllers Can Be Effectively Halted By Remote Users
16412| [1001464] Microsoft Internet Information Server IIS 5.0 for Windows 2000 Lets Remote Users Execute Arbitrary Code on the Server and Gain Control of the Server
16413| [1001240] Microsoft FTP Client for Windows 2000 Still Vulnerable to Executing Arbitrary Code in Limited Situations
16414| [1001088] Microsoft Internet Explorer with Services for Unix 2.0 Can Create Malicious Files on the User's Host
16415|
16416| OSVDB - http://www.osvdb.org:
16417| [90257] Microsoft Windows Server 2003 ICACLS.EXE Permission Inheritance Weakness
16418| [86790] Microsoft Virtual PC 2007 Crafted x86 Instruction Sequence Handling Local DoS
16419| [86061] Microsoft Windows Server 2008 R1 CSRSS ReadConsole / CloseHandle Local DoS
16420| [79442] Microsoft Windows Server 2008 DNS Server Service Cache Update Policy Deleted Domain Name Resolving Weakness
16421| [72670] Microsoft Windows Server 2003 ActiveDirectory BROWSER ELECTION Remote Overflow
16422| [68554] Microsoft Windows Server 2008 Shared Cluster Disks Addition Default Permission Weakness
16423| [62251] Microsoft Windows Server 2008 Hyper-V Crafted Instruction Sequence DoS
16424| [60329] Microsoft Windows 2000 NetBIOS Continuation Packet Remote DoS
16425| [59733] Microsoft Windows 2000 Terminal Services Screensaver Screen Minimization Locking Weakness
16426| [59731] Microsoft Windows 2000 DCOM Client Alter Context Request Remote Information Disclosure
16427| [59730] Microsoft Windows 2000 Terminal Services Disconnect Feature Local Privilege Escalation
16428| [59514] Microsoft Windows 2000 Task Manager Uppercase Process Name Termination Weakness
16429| [59509] Microsoft Windows 2000 Encrypted File System Cleartext Backup File Local Disclosure
16430| [59346] Microsoft Windows 2000 Crafted TCP/UDP Traffic CPU Consumption Remote DoS
16431| [55836] Microsoft ISA Server 2006 Radius OTP Security Bypass
16432| [53663] Microsoft Office Word 2000 WordPerfect 6.x Converter Document Handling Stack Corruption
16433| [50589] Microsoft SQL Server 2000 sp_replwritetovarbin() Stored Procedure Overflow
16434| [37629] Microsoft Windows 2000 RPC Authentication Unspecified Information Disclosure
16435| [37628] Microsoft Windows 2000 RPC Authentication Crafted Request Remote DoS
16436| [36034] Microsoft Office 2000 Controllo ActiveX (OUACTRL.OCX) HelpPopup Method Overflow
16437| [34489] Microsoft Office 2003 Malformed WMF File Handling DoS
16438| [34488] Microsoft Excel 2003 XLS Handling Corrupt Format DoS
16439| [31251] Microsoft Office 2003 Brazilian Portuguese Grammar Checker Arbitrary Code Execution
16440| [29529] Microsoft Windows 2000 creator.dll ActiveX COM Object Memory Corruption
16441| [29528] Microsoft Windows 2000 msdxm.ocx ActiveX COM Object Memory Corruption
16442| [29527] Microsoft Windows 2000 myinfo.dll ActiveX COM Object Memory Corruption
16443| [29526] Microsoft Windows 2000 ciodm.dll ActiveX COM Object Memory Corruption
16444| [28539] Microsoft Word 2000 Unspecified Code Execution
16445| [24121] Microsoft Commerce Server 2002 authfiles/login.asp Authentication Bypass
16446| [24081] Microsoft Outlook 2003 Unspecified Malformed Word Attachment DoS
16447| [23484] Microsoft SQLServer 2000 sp_addalias Procedure Privileged Alias Creation
16448| [23234] Microsoft SQLServer 2000 Unspecified Invalid Client Buffer DoS
16449| [23231] Microsoft SQL Server 2000 SQL Profiler Multiple Method DoS
16450| [23205] Microsoft SQLServer 2000 Crafted Sort Command User Mode Scheduler (UMS) Bypass DoS
16451| [23203] Microsoft SQL Server 2000 Database Name Transact-SQL Statement Privilege Escalation
16452| [23202] Microsoft SQLServer 2000 sysmembers Virtual Table Query Overflow
16453| [23201] Microsoft SQL Server 2000 Dynamic Transact-SQL Statement Disclosure
16454| [23200] Microsoft SQLServer 2000 Encrypted Stored Procedure Dynamic Query Disclosure
16455| [21907] Microsoft Office InfoPath 2003 Mshtml.dll Form Handling DoS
16456| [21598] Microsoft Windows 2000 NetBIOS Port Malformed TCP Packet Parsing Remote DoS
16457| [20256] Microsoft Windows 2000 NTFS Volume Macintosh Client Directory Permission Modification
16458| [20222] Microsoft Windows 2000 runas.exe Named Pipe Spoofing Information Disclosure
16459| [20221] Microsoft Windows 2000 runas.exe Named Pipe Single Thread DoS
16460| [20220] Microsoft Windows 2000 runas.exe Cleartext Authentication Information Disclosure
16461| [20002] Microsoft Windows 2000 CHKDSK Fix Mode File ACL Failure
16462| [20001] Microsoft Windows 2000 Terminal Service Client Connection IP Logging Failure
16463| [20000] Microsoft Windows 2000 Domain Administrator Computer Lock Bypass
16464| [19999] Microsoft Windows 2000 FQDN Domain Login Password Expiry Bypass
16465| [19998] Microsoft Windows 2000 UPN Credentialed Login Group Policy Failure
16466| [19997] Microsoft Windows 2000 WideCharToMultiByte Function String Termination Issue
16467| [19996] Microsoft Windows 2000 Event ID 1704 Group Policy Failure
16468| [19995] Microsoft Windows 2000 SECEDIT Long Folder ACL Set Issue
16469| [19994] Microsoft Windows 2000 audit directory service access 565 Event Logging Failure
16470| [19993] Microsoft Windows 2000 LDAPS CA Trust Issue
16471| [19264] Microsoft Exchange Server 2003 Crafted IMAP4 Folder Listing Request DoS
16472| [17031] Microsoft ISA Server 2000 SecureNAT Traffic Saturation DoS
16473| [15343] Microsoft Windows Server 2003 Malformed HTTP Cookie Header CGI DoS
16474| [15341] Microsoft Windows Server 2003 SMB Redirector Processing DoS
16475| [15340] Microsoft Windows Server 2003 Terminal Service Client Print DoS
16476| [15338] Microsoft Windows Server 2003 Terminal Session Close DoS
16477| [15337] Microsoft Windows Server 2003 CreateProcessWithLogonW() Function Process Disclosure
16478| [15336] Microsoft Windows Server 2003 Shutdown.exe Shut Down Failure
16479| [15335] Microsoft Windows Server 2003 MIT Kerberos Realm Authentication Group Policy Failure
16480| [15334] Microsoft Windows Server 2003 Shared Folder Permission Weakness
16481| [15333] Microsoft Windows Server 2003 EFS File Copy LDAP Connection DoS
16482| [15332] Microsoft Windows Server 2003 Citrix Metaframe Encryption Policy Failure
16483| [15331] Microsoft Windows Server 2003 Home Folder Path Permission Inheritance Failure
16484| [14617] Microsoft Exchange Server 2003 Folder Handling DoS
16485| [14430] Microsoft Commerce Server 2000 Profile Service Affected API Overflow
16486| [13996] Microsoft Windows 2000 IKE Malformed Packet Saturation Remote DoS
16487| [13762] Microsoft 2000 Domain Controller Directory Service Restore Mode Blank Password
16488| [13761] Microsoft Exchange 2000 Malformed URL Request DoS
16489| [13475] Microsoft Windows 2000 Telnet Service Predictable Named Pipe Arbitrary Command Execution Variant
16490| [13474] Microsoft Windows 2000 Telnet Service Predictable Named Pipe Arbitrary Command Execution
16491| [13441] Microsoft Windows 2000 Security Interface Change Password Option Account Enumeration
16492| [13437] Microsoft Windows 2000 Debug Register Local Privilege Escalation
16493| [13424] Microsoft Windows 2000 Current Password Change Policy Bypass
16494| [13423] Microsoft Windows 2000 Terminal Server SYSVOL Share Connection Saturation Restriction Bypass
16495| [13415] Microsoft Windows 2000 System Root Folder Search Path Permission Weakness
16496| [13410] Microsoft Windows 2000 Accessibility Utility Manager Arbitrary Code Execution
16497| [11958] Microsoft Outlook 2003 Image Rendering Security Policy Bypass
16498| [11945] Microsoft Outlook 2002 IFRAME Tag Embedded URL
16499| [11944] Microsoft Outlook 2002 HREF Tag Embedded JavaScript Execution
16500| [11750] Microsoft Windows 2000 Message Queue Manager Queue Registration Request Overflow DoS
16501| [11712] Microsoft ISA Server 2000 H.323 Filter Overflow
16502| [10633] Microsoft Windows 2000 Protected Store Weak Encryption Default
16503| [9386] Microsoft Windows 2000 msinfo32.exe msinfo_file Variable Overflow
16504| [8243] Microsoft SMS Port 2702 DoS
16505| [7202] Microsoft PowerPoint 2000 File Loader Overflow
16506| [7179] Microsoft Windows 2000 Event Viewer Snap-in Overflow
16507| [6971] Microsoft ISA Server 2000 ICMP Rule Bypass During Startup
16508| [6970] Microsoft ISA Server 2000 Web Publishing Unencrypted Credentials Disclosure
16509| [6969] Microsoft ISA Server 2000 Invalid DNS Request DoS
16510| [6968] Microsoft ISA Server 2000 FTP Port Scan Bounce Weakness
16511| [6967] Microsoft ISA Server 2000 UDP Packet Winsock DoS
16512| [6965] Microsoft ISA Server 2000 SSL Packet DoS
16513| [6964] Microsoft ISA Server 2000 DNS Intrusion Detection Filter DoS
16514| [6515] Microsoft Windows 2000 Domain Expired Account Authentication
16515| [5179] Microsoft Windows 2000 microsoft-ds DoS
16516| [5171] Microsoft Word 2002 Mail Merge Tool Execute Arbitrary Script
16517| [4779] Microsoft Desktop Engine (MSDE) 2000 Stored Procedure SQL Injection
16518| [4778] Microsoft SQL Server 2000 Stored Procedure SQL Injection
16519| [4777] Microsoft Desktop Engine (MSDE) 2000 Database Consistency Checkers (DBCCs) Overflow
16520| [4776] Microsoft SQL Server 2000 Database Consistency Checkers (DBCCs) 2000 Overflow
16521| [4170] Microsoft Windows 2000 Server Media Services TCP Packet Handling Remote DoS
16522| [4168] Microsoft Outlook 2002 mailto URI Script Injection
16523| [3490] Microsoft Exchange 2003 OWA Mailbox Access Information Disclosure
16524| [2705] Microsoft Windows 2000 Windows Troubleshooter ActiveX Overflow
16525| [2655] Microsoft Windows Server 2003 Shell Folders Arbitrary File Access
16526| [2540] Microsoft Windows 2003 Server Buffer Overflow Protection Mechanism Bypass
16527| [2244] Microsoft Windows 2000 ShellExecute() API Let
16528| [2237] Microsoft Windows 2000 Active Directory Lsass.exe Overflow
16529| [1949] Symantec Norton Anti-Virus for Microsoft Exchange 2000 INBOX Path Information Disclosure
16530| [1764] Microsoft Windows 2000 Domain Controller DoS
16531| [1758] Microsoft Windows 2000 Network DDE Escalated Privileges
16532| [1755] Microsoft Windows 2000 RDP Malformed Packet Handling Remote DoS
16533| [1672] Microsoft Windows 2000 Telnet Session Timeout DoS
16534| [1633] Microsoft Windows 2000 System Monitor ActiveX LogFileName Parameter Validation Overflow
16535| [1621] Microsoft Indexing Services for Windows 2000 .htw XSS
16536| [1591] Microsoft Windows 2000 OEMPreinstall Installation Permission Weakness
16537| [1578] Microsoft Windows 2000 Simplified Chinese IME Local Privilege Escalation
16538| [1500] Microsoft Word / Excel / Powerpoint 2000 Object Tag Buffer Overflow
16539| [1437] Microsoft Windows 2000 Telnet Server Binary Zero Parsing Remote DoS
16540| [1399] Microsoft Windows 2000 Windows Station Access
16541| [1328] Microsoft Office 2000 UA Control ActiveX (Ouactrl.ocx) Show Me Function Remote Code Execution
16542| [1297] Microsoft Windows 2000 Active Directory Object Attribute
16543| [1292] Microsoft Windows NT 4.0 / 2000 cmd.exe Buffer Overflow
16544| [773] Microsoft Windows 2000 Group Policy File Lock DoS
16545| [515] Microsoft Windows 2000 LDAP Server Arbitrary User Password Modification
16546| [454] Microsoft Windows 2000 NTLM Domain Account Lockout Policy Bypass
16547| [403] Microsoft Windows 2000 Still Image Service WM_USER Message Local Overflow
16548| [398] Microsoft Windows 2000 Malformed RPC Traffic Local Security Policy Corruption DoS
16549| [307] Microsoft FrontPage 2000 Server Extensions shtml.exe Path Disclosure
16550| [69085] Microsoft Office 2010 RTF File Handling pFragments Buffer Overflow Arbitrary Code Execution
16551|_
16552139/tcp closed netbios-ssn conn-refused
16553443/tcp open ssl/http syn-ack Microsoft IIS httpd 8.5
16554| vulscan: VulDB - https://vuldb.com:
16555| [68193] Microsoft IIS 8.0/8.5 IP and Domain Restriction privilege escalation
16556| [48519] Microsoft Works 8.5/9.0 memory corruption
16557| [45763] Microsoft Windows Live Messenger up to 8.5.1 unknown vulnerability
16558| [134730] Microsoft Skype 8.35 on Android Bluetooth Listening information disclosure
16559| [129845] Microsoft Skype for Business 2015 CU 8 Request cross site scripting
16560| [126799] Microsoft Dynamics 365 8 Web Request Code Execution
16561| [126798] Microsoft Dynamics 365 8 Web Request cross site scripting
16562| [126797] Microsoft Dynamics 365 8 Web Request cross site scripting
16563| [126796] Microsoft Dynamics 365 8 Web Request cross site scripting
16564| [126795] Microsoft Dynamics 365 8 Web Request cross site scripting
16565| [123872] Microsoft Windows 8.1/RT 8.1/10/Server 2012/Server 2012 R2 SMB information disclosure
16566| [121108] Microsoft Mail Client 8.1 information disclosure
16567| [115260] EMC RSA Authentication Agent for Web up to 8.0.1 on IIS/Apache cross site scripting
16568| [115259] EMC RSA Authentication Agent for Web up to 8.0.1 on IIS/Apache Cookie Stack-based memory corruption
16569| [113264] Microsoft Windows 8.1/RT 8.1/Server 2012 R2 SMBv2/SMBv3 denial of service
16570| [100989] Microsoft Internet Explorer 8/9/10/11 memory corruption
16571| [100918] Microsoft Windows 8/8.1/10/Server 2012/Server 2016 Malware Protection Service Type Confusion privilege escalation
16572| [96521] Microsoft Windows 8.1/10/Server 2012/Server 2016 SMB Response mrxsmb20.sys denial of service
16573| [93988] Microsoft Desktop Client for Mac up to 8.0.36 privilege escalation
16574| [93755] Microsoft Internet Explorer 8 Ls\xC2\xADFind\xC2\xADSpan\xC2\xADVisual\xC2\xADBoundaries memory corruption
16575| [93535] Microsoft Internet Explorer 8/9/10/11 Regex vbscript.dll RegExpComp::PnodeParse memory corruption
16576| [93386] Microsoft Windows Vista SP2/7 SP1/8.1/RT 8.1/10 Video Control memory corruption
16577| [92587] Microsoft Windows 8.1/RT 8.1/10/Server 2012/Server 2012 R2 Transaction Manager privilege escalation
16578| [92585] Microsoft Windows Vista SP2/7 SP1/8.1/RT 8.1/10 Video Control privilege escalation
16579| [91571] Microsoft Windows 8.1/RT 8.1/10/Server 2012/Server 2012 R2 PDF Library information disclosure
16580| [91570] Microsoft Windows 8.1/RT 8.1/10/Server 2012/Server 2012 R2 PDF Library information disclosure
16581| [91559] Microsoft Windows 8.1/RT 8.1/10 NTLM SSO information disclosure
16582| [90711] Microsoft Windows 8.1/RT 8.1/10/Server 2012/Server 2012 R2 PDF privilege escalation
16583| [90710] Microsoft Windows 8.1/RT 8.1/Server 2012/Server 2012 R2 Netlogon privilege escalation
16584| [87959] Microsoft Windows 8.1/10/Server 2012/Server 2012 R2 PDF information disclosure
16585| [87958] Microsoft Windows 8.1/10/Server 2012/Server 2012 R2 PDF memory corruption
16586| [87957] Microsoft Windows 8.1/10/Server 2012/Server 2012 R2 PDF information disclosure
16587| [87156] Microsoft Windows 8.1/RT 8.1/10/Server 2012 R2 Shell memory corruption
16588| [87155] Microsoft Windows Vista SP2/7/8.1/RT 8.1/10 Journal memory corruption
16589| [82223] Microsoft Windows 8.1/10/Server 2012 R2 Hyper-V Memory information disclosure
16590| [82222] Microsoft Windows 8.1/10/Server 2012/Server 2012 R2 Memory information disclosure
16591| [82221] Microsoft Windows 8.1/10/Server 2012/Server 2012 R2 Hyper-V privilege escalation
16592| [81270] Microsoft Windows 8.1/RT 8.1/10/Server 2012/Server 2012 R2 PDF Library memory corruption
16593| [80865] Microsoft Windows 8.1/RT 8.1/Server 2012/Server 2012 R2 DLL Loader memory corruption
16594| [80860] Microsoft Windows 8.1/10/Server 2012/Server 2012 R2 Reader memory corruption
16595| [80859] Microsoft Windows 8.1/10/Server 2012/Server 2012 R2 PDF Library memory corruption
16596| [80844] Microsoft Internet Explorer 8/9/10/11 MSHTML MSHTML!Method_VARIANTBOOLp_BSTR_o0oVARIANT memory corruption
16597| [80209] Microsoft Internet Explorer 8/9/10/11 VBScript/JScript memory corruption
16598| [79462] Microsoft Internet Explorer 8/9/10/11 memory corruption
16599| [79460] Microsoft Internet Explorer 8/9 memory corruption
16600| [79458] Microsoft Internet Explorer 8/9 memory corruption
16601| [79457] Microsoft Internet Explorer 8/9 memory corruption
16602| [79455] Microsoft Internet Explorer 8/9/10/11 XSS Filter privilege escalation
16603| [79449] Microsoft Internet Explorer 8/9/10/11 XSS Filter privilege escalation
16604| [79448] Microsoft Internet Explorer 8/9/10/11 Scripting Engine memory corruption
16605| [79447] Microsoft Internet Explorer 8/9/10/11 Scripting Engine information disclosure
16606| [79445] Microsoft Internet Explorer 8/9/10/11 memory corruption
16607| [79162] Microsoft Internet Explorer 8/9/10/11 Scripting Engine memory corruption
16608| [79155] Microsoft Internet Explorer 8/9/10/11 memory corruption
16609| [79143] Microsoft Internet Explorer 8/9/10/11 memory corruption
16610| [78390] Microsoft Internet Explorer 8/9/10/11 VBScript/JScript Engine information disclosure
16611| [78386] Microsoft Internet Explorer 8/9/10/11 VBScript/JScript Engine memory corruption
16612| [78384] Microsoft Internet Explorer 8/9/10/11 VBScript/JScript Engine ASLR privilege escalation
16613| [78379] Microsoft Internet Explorer 8/9/10/11 EditWith Broker privilege escalation
16614| [78377] Microsoft Internet Explorer 8 privilege escalation
16615| [78362] Microsoft Internet Explorer 8/9/10/11 VBScript/JScript Engine RegExpBase::FBadHeader memory corruption
16616| [77605] Microsoft Internet Explorer 8 VBScript/JScript Engine memory corruption
16617| [77006] Microsoft Internet Explorer 8/9/10/11 memory corruption
16618| [77004] Microsoft Internet Explorer 8/9/10/11 memory corruption
16619| [76490] Microsoft Internet Explorer 8/9/10/11 Image Caching History information disclosure
16620| [76482] Microsoft Internet Explorer 8 memory corruption
16621| [76479] Microsoft Internet Explorer 8/9/10/11 XSS Filter cross site scripting
16622| [76474] Microsoft Internet Explorer 8/9 memory corruption
16623| [76449] Microsoft Windows 8/8.1/Server 2008/Server 2012/Server 2012 R2 Hyper-V memory corruption
16624| [76448] Microsoft Windows 8.1/Server 2012 R2 Hyper-V memory corruption
16625| [76437] Microsoft Internet Explorer 8/9 memory corruption
16626| [75780] Microsoft Internet Explorer 8 memory corruption
16627| [75707] Cisco Unified MeetingPlace for Microsoft Outlook 8.6(1.2)/ 8.6(1.9) cross site scripting
16628| [75322] Microsoft Internet Explorer 8/9 memory corruption
16629| [75319] Microsoft Internet Explorer 8/9/10/11 memory corruption
16630| [75311] Microsoft Internet Explorer 8/9 memory corruption
16631| [75308] Microsoft Internet Explorer 8/9/10/11 VBscript and JScript Engine privilege escalation
16632| [75306] Microsoft Internet Explorer 8/9/10/11 VBScript Engine privilege escalation
16633| [74856] Microsoft Internet Explorer 8/9/10/11 memory corruption
16634| [74842] Microsoft Windows 8.1/Server 2012 R2 Hyper-V denial of service
16635| [73946] Microsoft Internet Explorer 8/9/10/11 memory corruption
16636| [73943] Microsoft Internet Explorer 8 memory corruption
16637| [73939] Microsoft Internet Explorer 8/9/10/11 VBScript Engine memory corruption
16638| [69137] Microsoft Internet Explorer 8 ASLR privilege escalation
16639| [69136] Microsoft Internet Explorer 8/9 MSHTML SpanQualifier memory corruption
16640| [69135] Microsoft Internet Explorer 8/10 memory corruption
16641| [69131] Microsoft Internet Explorer 8/9 memory corruption
16642| [69130] Microsoft Internet Explorer 8/9/10/11 memory corruption
16643| [68400] Microsoft Internet Explorer 8 memory corruption
16644| [68393] Microsoft Internet Explorer 8/9/10/11 XSS Filter cross site scripting
16645| [68389] Microsoft Internet Explorer 8/9/10/11 XSS Filter cross site scripting
16646| [68181] Microsoft Internet Explorer 8/9/10/11 memory corruption
16647| [68176] Microsoft Internet Explorer 8/9/10/11 information disclosure
16648| [68174] Microsoft Internet Explorer 8/9 memory corruption
16649| [68169] Microsoft Internet Explorer 8/9 ASLR privilege escalation
16650| [68211] Microsoft Internet Explorer 8/9/10/11 denial of service
16651| [67821] Microsoft Internet Explorer 8/9/10/11 CAttrArray memory corruption
16652| [67813] Microsoft Internet Explorer 8 memory corruption
16653| [67500] Microsoft Internet Explorer 8/9/10/11 memory corruption
16654| [67494] Microsoft Internet Explorer 8/9/10/11 memory corruption
16655| [67345] Microsoft Internet Explorer 8/9/10/11 memory corruption
16656| [67340] Microsoft Internet Explorer 8 memory corruption
16657| [67337] Microsoft Internet Explorer 8/9 memory corruption
16658| [67007] Microsoft Internet Explorer 8/9/10/11 memory corruption
16659| [67006] Microsoft Internet Explorer 8/9/10 memory corruption
16660| [67002] Microsoft Internet Explorer 8/9/10/11 memory corruption
16661| [67000] Microsoft Internet Explorer 8/9/10/11 memory corruption
16662| [66995] Microsoft Internet Explorer 8/9/10/11 memory corruption
16663| [13542] Microsoft Internet Explorer 8/9/10/11 privilege escalation
16664| [13536] Microsoft Internet Explorer 8 memory corruption
16665| [13518] Microsoft Internet Explorer 8 memory corruption
16666| [13515] Microsoft Internet Explorer 8/9/10/11 memory corruption
16667| [13509] Microsoft Internet Explorer 8 memory corruption
16668| [13499] Microsoft Internet Explorer 8 memory corruption
16669| [13496] Microsoft Internet Explorer 8/9/10/11 privilege escalation
16670| [13027] Microsoft Internet Explorer 8/9 information disclosure
16671| [66605] Microsoft Internet Explorer 8/9/10/11 memory corruption
16672| [12543] Microsoft Internet Explorer 8/9/10/11 memory corruption
16673| [12541] Microsoft Internet Explorer 8/9/10 memory corruption
16674| [12540] Microsoft Internet Explorer 8/9/10/11 memory corruption
16675| [12538] Microsoft Internet Explorer 8/9 memory corruption
16676| [12531] Microsoft Internet Explorer 8/9/10/11 memory corruption
16677| [66445] Microsoft Windows 8.0/8.1 XMLDOM ActiveX Control information disclosure
16678| [12252] Microsoft Internet Explorer 8 memory corruption
16679| [12245] Microsoft Internet Explorer 8/9/10/11 memory corruption
16680| [12239] Microsoft Internet Explorer 8/9/10/11 privilege escalation
16681| [12238] Microsoft Windows 8/Server 2012/RT IPv6 denial of service
16682| [11150] Microsoft Windows 8/Server 2012 Hyper-V Data Structure Value Crash privilege escalation
16683| [11141] Microsoft Internet Explorer 8/9/10/11 CCaret Object Use-After-Free memory corruption
16684| [11138] Microsoft Internet Explorer 8/9/10/11 CTreePos Object memory corruption
16685| [11127] Microsoft Internet Explorer 8/9 information disclosure
16686| [10623] Microsoft Internet Explorer 8/9 memory corruption
16687| [10215] Microsoft Internet Explorer 8/9 memory corruption
16688| [10214] Microsoft Internet Explorer 8/9/10 memory corruption
16689| [9935] Microsoft Internet Explorer 8/9 memory corruption
16690| [9934] Microsoft Internet Explorer 8/9/10 memory corruption
16691| [9933] Microsoft Internet Explorer 8/9 memory corruption
16692| [9932] Microsoft Internet Explorer 8/9 memory corruption
16693| [10246] Microsoft Internet Explorer 8 Table Tree Use-After-Free memory corruption
16694| [9419] Microsoft Internet Explorer up to 8 memory corruption
16695| [9418] Microsoft Internet Explorer 8/9/10 Use-After-Free memory corruption
16696| [9413] Microsoft Internet Explorer 8/9/10 Use-After-Free memory corruption
16697| [9406] Microsoft Internet Explorer 8/9/10 memory corruption
16698| [9099] Microsoft Internet Explorer 8/9 Use-After-Free memory corruption
16699| [9098] Microsoft Internet Explorer 8 memory corruption
16700| [9095] Microsoft Internet Explorer 8/9/10 Use-After-Free memory corruption
16701| [9084] Microsoft Internet Explorer 8/9/10 _UpdateButtonLocation memory corruption
16702| [9083] Microsoft Internet Explorer 8/9 memory corruption
16703| [8722] Microsoft Windows 8/Server 2012/RT HTTP.sys denial of service
16704| [8718] Microsoft Internet Explorer 8 memory corruption
16705| [8714] Microsoft Internet Explorer 8/9 memory corruption
16706| [8712] Microsoft Internet Explorer 8/9 memory corruption
16707| [8601] Microsoft Internet Explorer 8 'vtable' memory corruption
16708| [8423] Microsoft Internet Explorer up to 8.00.6001.18702 CSS iexplorer.exe denial of service
16709| [7962] Microsoft Internet Explorer up to 8 CTreeNode memory corruption
16710| [7958] Microsoft Internet Explorer up to 8 Celement memory corruption
16711| [7996] Microsoft Windows 8 TrueType Font denial of service
16712| [63558] Microsoft Internet Explorer 8 Use-After-Free memory corruption
16713| [63557] Microsoft Internet Explorer 8/9 Use-After-Free memory corruption
16714| [7511] Microsoft Internet Explorer 8/9 TCP Session information disclosure
16715| [7510] Microsoft Internet Explorer 8/9 HTTP/HTTPS Request spoofing
16716| [7258] Microsoft Windows up to 8/Server 2012 SSL/TLS race condition
16717| [7199] Microsoft Internet Explorer 8/9 mshtml.dll Unclosed Tags Sequence denial of service
16718| [6513] Microsoft Internet Explorer 8/9 OnMove Engine Use-After-Free memory corruption
16719| [5937] Microsoft Internet Explorer 8/9 JavaScript Parser memory corruption
16720| [5538] Microsoft Internet Explorer 8 Same ID Property Deleted Object memory corruption
16721| [5532] Microsoft Internet Explorer 8/9 HTML Sanitization toStaticHTML String information disclosure
16722| [5530] Microsoft Internet Explorer 8/9 OnRowsInserted Elements memory corruption
16723| [5516] Microsoft Internet Explorer 8/9 memory corruption
16724| [4467] Microsoft Internet Explorer 8 cross site scripting
16725| [4454] Microsoft Internet Explorer 8/9 unknown vulnerability
16726| [59618] Microsoft Internet Explorer 8 unknown vulnerability
16727| [57681] Microsoft Internet Explorer 8/9 memory corruption
16728| [57675] Microsoft Internet Explorer 8 memory corruption
16729| [4372] Microsoft Internet Explorer 8/9 information disclosure
16730| [57130] Microsoft Internet Explorer 8 on Win7 msxml.dll unknown vulnerability
16731| [4340] Microsoft Internet Explorer up to 8 unknown vulnerability
16732| [56786] Microsoft Internet Explorer 8 on Win7 unknown vulnerability
16733| [56785] Microsoft Internet Explorer 8 on Win7 memory corruption
16734| [56412] Microsoft Internet Explorer 8 IEShims.dll unknown vulnerability
16735| [55755] Microsoft Internet Explorer 8 memory corruption
16736| [54961] Microsoft Internet Explorer 8 mshtml.dll InsertIntoTimeoutList information disclosure
16737| [4172] Microsoft Internet Explorer up to 8 CSS cross site scripting
16738| [54339] Microsoft Internet Explorer 8 Uninitialized Memory memory corruption
16739| [53805] Microsoft Internet Explorer 8 unknown vulnerability
16740| [53514] Microsoft Internet Explorer 8 Uninitialized Memory memory corruption
16741| [53513] Microsoft Internet Explorer 8 memory corruption
16742| [4137] Microsoft Internet Explorer up to 8.0 memory corruption
16743| [4121] Microsoft Internet Explorer 8 XSS Filter cross site scripting
16744| [52505] Microsoft Internet Explorer 8 mstime.dll memory corruption
16745| [52373] Microsoft Internet Explorer 8 on Win7 Use-After-Free memory corruption
16746| [52372] Microsoft Internet Explorer 8 on Win7 Heap-based memory corruption
16747| [51652] Microsoft Internet Explorer 8 Uninitialized Memory memory corruption
16748| [51651] Microsoft Internet Explorer 8 Uninitialized Memory memory corruption
16749| [50914] Microsoft Internet Explorer 8 cross site scripting
16750| [50910] Microsoft Internet Explorer 8 unknown vulnerability
16751| [4048] Microsoft Internet Explorer up to 8 CSS Declaration memory corruption
16752| [4047] Microsoft Internet Explorer up to 8 DOM Object memory corruption
16753| [4046] Microsoft Internet Explorer up to 8 HTML memory corruption
16754| [3987] Microsoft Internet Explorer up to 8 Row Reference memory corruption
16755| [3982] Microsoft Internet Explorer up to 8 DHTML Call memory corruption
16756| [47244] Microsoft Internet Explorer 8 on Win 7 memory corruption
16757| [45681] Microsoft Internet Explorer 8 Beta 2 privilege escalation
16758| [45451] Microsoft Internet Explorer 8 XSS Filter cross site scripting
16759| [45450] Microsoft Internet Explorer 8 XSS Filter Protection cross site scripting
16760| [45449] Microsoft Internet Explorer 8 Beta 2 XSS Filter cross site scripting
16761| [45448] Microsoft Internet Explorer 8 Beta 2 XSS Filter cross site scripting
16762| [45447] Microsoft Internet Explorer 8 XSS Filter cross site scripting
16763| [45446] Microsoft Internet Explorer 8 Beta 2 XSS Filter cross site scripting
16764| [39012] Microsoft Windows Live Messenger up to 8.1 doc memory corruption
16765| [34991] Microsoft Visual Studio 8.0 msvcr80.dll denial of service
16766| [33589] Microsoft Windows Live Messenger up to 8.0 denial of service
16767| [31353] Microsoft Works 8.0 Spreadsheet wksss.exe memory corruption
16768| [31352] Microsoft Works 8.0 Spreadsheet wksss.exe denial of service
16769| [31024] Microsoft Windows Live Messenger 8.0 Heap-based memory corruption
16770|
16771| MITRE CVE - https://cve.mitre.org:
16772| [CVE-2013-0941] EMC RSA Authentication API before 8.1 SP1, RSA Web Agent before 5.3.5 for Apache Web Server, RSA Web Agent before 5.3.5 for IIS, RSA PAM Agent before 7.0, and RSA Agent before 6.1.4 for Microsoft Windows use an improper encryption algorithm and a weak key for maintaining the stored data of the node secret for the SecurID Authentication API, which allows local users to obtain sensitive information via cryptographic attacks on this data.
16773| [CVE-2011-1215] Stack-based buffer overflow in mw8sr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a crafted link in a Microsoft Office document attachment, aka SPR PRAD8823ND.
16774| [CVE-2010-3496] McAfee VirusScan Enterprise 8.5i and 8.7i does not properly interact with the processing of hcp:// URLs by the Microsoft Help and Support Center, which makes it easier for remote attackers to execute arbitrary code via malware that is correctly detected by this product, but with a detection approach that occurs too late to stop the code execution.
16775| [CVE-2009-3126] Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a crafted PNG image file, aka "GDI+ PNG Integer Overflow Vulnerability."
16776| [CVE-2009-3032] Integer overflow in kvolefio.dll 8.5.0.8339 and 10.5.0.0 in the Autonomy KeyView Filter SDK, as used in IBM Lotus Notes 8.5, Symantec Mail Security for Microsoft Exchange 5.0.10 through 5.0.13, and other products, allows context-dependent attackers to execute arbitrary code via a crafted OLE document that triggers a heap-based buffer overflow.
16777| [CVE-2009-2504] Multiple integer overflows in unspecified APIs in GDI+ in Microsoft .NET Framework 1.1 SP1, .NET Framework 2.0 SP1 and SP2, Windows XP SP2 and SP3, Windows Server 2003 SP2, Vista Gold and SP1, Server 2008 Gold, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allow remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "GDI+ .NET API Vulnerability."
16778| [CVE-2009-2503] GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Windows Server 2003 SP2, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 does not properly allocate an unspecified buffer, which allows remote attackers to execute arbitrary code via a crafted TIFF image file that triggers memory corruption, aka "GDI+ TIFF Memory Corruption Vulnerability."
16779| [CVE-2009-2502] Buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a crafted TIFF image file, aka "GDI+ TIFF Buffer Overflow Vulnerability."
16780| [CVE-2009-2501] Heap-based buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a crafted PNG image file, aka "GDI+ PNG Heap Overflow Vulnerability."
16781| [CVE-2009-2500] Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a crafted WMF image file, aka "GDI+ WMF Integer Overflow Vulnerability."
16782| [CVE-2009-1533] Buffer overflow in the Works for Windows document converters in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, Office 2007 SP1, and Works 8.5 and 9 allows remote attackers to execute arbitrary code via a crafted Works .wps file that triggers memory corruption, aka "File Converter Buffer Overflow Vulnerability."
16783| [CVE-2008-5828] Microsoft Windows Live Messenger Client 8.5.1 and earlier, when MSN Protocol Version 15 (MSNP15) is used over a NAT session, allows remote attackers to discover intranet IP addresses and port numbers by reading the (1) IPv4InternalAddrsAndPorts, (2) IPv4Internal-Addrs, and (3) IPv4Internal-Port header fields.
16784| [CVE-2007-0045] Multiple cross-site scripting (XSS) vulnerabilities in Adobe Acrobat Reader Plugin before 8.0.0, and possibly the plugin distributed with Adobe Reader 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2, for Mozilla Firefox, Microsoft Internet Explorer 6 SP1, Google Chrome, Opera 8.5.4 build 770, and Opera 9.10.8679 on Windows allow remote attackers to inject arbitrary JavaScript and conduct other attacks via a .pdf URL with a javascript: or res: URI with (1) FDF, (2) XML, and (3) XFDF AJAX parameters, or (4) an arbitrarily named name=URI anchor identifier, aka "Universal XSS (UXSS)."
16785| [CVE-2004-1312] A bug in the HTML parser in a certain Microsoft HTML library, as used in various third party products, may allow remote attackers to cause a denial of service via certain strings, as reported in GFI MailEssentials for Exchange 9 and 10, and GFI MailSecurity for Exchange 8, which causes emails to remain in IIS or Exchange mail queues.
16786| [CVE-2002-1117] Veritas Backup Exec 8.5 and earlier requires that the "RestrictAnonymous" registry key for Microsoft Exchange 2000 must be set to 0, which enables anonymous listing of the SAM database and shares.
16787| [CVE-2001-1088] Microsoft Outlook 8.5 and earlier, and Outlook Express 5 and earlier, with the "Automatically put people I reply to in my address book" option enabled, do not notify the user when the "Reply-To" address is different than the "From" address, which could allow an untrusted remote attacker to spoof legitimate addresses and intercept email from the client that is intended for another user.
16788| [CVE-2013-3661] The EPATHOBJ::bFlatten function in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not check whether linked-list traversal is continually accessing the same list member, which allows local users to cause a denial of service (infinite traversal) via vectors that trigger a crafted PATHRECORD chain.
16789| [CVE-2013-3660] The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, and Windows Server 2012 does not properly initialize a pointer for the next object in a certain list, which allows local users to obtain write access to the PATHRECORD chain, and consequently gain privileges, by triggering excessive consumption of paged memory and then making many FlattenPath function calls, aka "Win32k Read AV Vulnerability."
16790| [CVE-2013-3174] DirectShow in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, and Windows Server 2012 allows remote attackers to execute arbitrary code via a crafted GIF file, aka "DirectShow Arbitrary Memory Overwrite Vulnerability."
16791| [CVE-2013-3173] Buffer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages improper handling of objects in memory, aka "Win32k Buffer Overwrite Vulnerability."
16792| [CVE-2013-3164] Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
16793| [CVE-2013-3163] Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3144 and CVE-2013-3151.
16794| [CVE-2013-3151] Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3144 and CVE-2013-3163.
16795| [CVE-2013-3149] Microsoft Internet Explorer 7 and 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
16796| [CVE-2013-3144] Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3151 and CVE-2013-3163.
16797| [CVE-2013-3141] Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3110.
16798| [CVE-2013-3138] Integer overflow in the TCP/IP kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allows remote attackers to cause a denial of service (system hang) via crafted TCP packets, aka "TCP/IP Integer Overflow Vulnerability."
16799| [CVE-2013-3136] The kernel in Microsoft Windows XP SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, and Windows 8 on 32-bit platforms does not properly handle unspecified page-fault system calls, which allows local users to obtain sensitive information from kernel memory via a crafted application, aka "Kernel Information Disclosure Vulnerability."
16800| [CVE-2013-3123] Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3111.
16801| [CVE-2013-3111] Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3123.
16802| [CVE-2013-3110] Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3141.
16803| [CVE-2013-2558] Unspecified vulnerability in Microsoft Windows 8 allows remote attackers to cause a denial of service (reboot) or possibly have unknown other impact via a crafted TrueType Font (TTF) file, as demonstrated by the 120612-69701-01.dmp error report.
16804| [CVE-2013-2552] Unspecified vulnerability in Microsoft Internet Explorer 10 on Windows 8 allows remote attackers to bypass the sandbox protection mechanism by leveraging access to a Medium integrity process, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2013.
16805| [CVE-2013-1451] Microsoft Internet Explorer 8 and 9, when the Proxy Settings configuration has the same Proxy address and Port values in the HTTP and Secure rows, does not ensure that the SSL lock icon is consistent with the Address bar, which makes it easier for remote attackers to spoof web sites via a crafted HTML document that triggers many HTTPS requests to an arbitrary host, followed by an HTTPS request to a trusted host and then an HTTP request to an untrusted host, a related issue to CVE-2013-1450.
16806| [CVE-2013-1450] Microsoft Internet Explorer 8 and 9, when the Proxy Settings configuration has the same Proxy address and Port values in the HTTP and Secure rows, does not properly reuse TCP sessions to the proxy server, which allows remote attackers to obtain sensitive information intended for a specific host via a crafted HTML document that triggers many HTTPS requests and then triggers an HTTP request to that host, as demonstrated by reading a Cookie header, aka MSRC 12096gd.
16807| [CVE-2013-1347] Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly allocated or (2) is deleted, as exploited in the wild in May 2013.
16808| [CVE-2013-1345] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Win32k Vulnerability."
16809| [CVE-2013-1340] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Win32k Dereference Vulnerability."
16810| [CVE-2013-1339] The Print Spooler in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly manage memory during deletion of printer connections, which allows remote authenticated users to execute arbitrary code via a crafted request, aka "Print Spooler Vulnerability."
16811| [CVE-2013-1334] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Win32k Window Handle Vulnerability."
16812| [CVE-2013-1332] dxgkrnl.sys (aka the DirectX graphics kernel subsystem) in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "DirectX Graphics Kernel Subsystem Double Fetch Vulnerability."
16813| [CVE-2013-1311] Use-after-free vulnerability in Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer Use After Free Vulnerability."
16814| [CVE-2013-1307] Use-after-free vulnerability in Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer Use After Free Vulnerability," a different vulnerability than CVE-2013-0811.
16815| [CVE-2013-1305] HTTP.sys in Microsoft Windows 8, Windows Server 2012, and Windows RT allows remote attackers to cause a denial of service (infinite loop) via a crafted HTTP header, aka "HTTP.sys Denial of Service Vulnerability."
16816| [CVE-2013-1300] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Win32k Memory Allocation Vulnerability."
16817| [CVE-2013-1297] Microsoft Internet Explorer 6 through 8 does not properly restrict data access by VBScript, which allows remote attackers to perform cross-domain reading of JSON files via a crafted web site, aka "JSON Array Information Disclosure Vulnerability."
16818| [CVE-2013-1294] Race condition in the kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages improper handling of objects in memory, aka "Kernel Race Condition Vulnerability."
16819| [CVE-2013-1292] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages improper handling of objects in memory, aka "Win32k Race Condition Vulnerability."
16820| [CVE-2013-1291] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, Windows 7 Gold and SP1, and Windows 8 allows local users to cause a denial of service (reboot) via a crafted OpenType font, aka "OpenType Font Parsing Vulnerability" or "Win32k Font Parsing Vulnerability."
16821| [CVE-2013-1288] Use-after-free vulnerability in Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer CTreeNode Use After Free Vulnerability."
16822| [CVE-2013-1287] The USB kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 do not properly handle objects in memory, which allows physically proximate attackers to execute arbitrary code by connecting a crafted USB device, aka "Windows USB Descriptor Vulnerability," a different vulnerability than CVE-2013-1285 and CVE-2013-1286.
16823| [CVE-2013-1286] The USB kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 do not properly handle objects in memory, which allows physically proximate attackers to execute arbitrary code by connecting a crafted USB device, aka "Windows USB Descriptor Vulnerability," a different vulnerability than CVE-2013-1285 and CVE-2013-1287.
16824| [CVE-2013-1285] The USB kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 do not properly handle objects in memory, which allows physically proximate attackers to execute arbitrary code by connecting a crafted USB device, aka "Windows USB Descriptor Vulnerability," a different vulnerability than CVE-2013-1286 and CVE-2013-1287.
16825| [CVE-2013-1284] Race condition in the kernel in Microsoft Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages improper handling of objects in memory, aka "Kernel Race Condition Vulnerability."
16826| [CVE-2013-1283] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages improper handling of objects in memory, aka "Win32k Race Condition Vulnerability."
16827| [CVE-2013-1280] The kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Reference Count Vulnerability."
16828| [CVE-2013-1279] Race condition in the kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages incorrect handling of objects in memory, aka "Kernel Race Condition Vulnerability," a different vulnerability than CVE-2013-1278.
16829| [CVE-2013-1278] Race condition in the kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application that leverages incorrect handling of objects in memory, aka "Kernel Race Condition Vulnerability," a different vulnerability than CVE-2013-1279.
16830| [CVE-2013-1249] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
16831| [CVE-2013-1248] Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges, and consequently read the contents of arbitrary kernel memory locations, via a crafted application, a different vulnerability than other CVEs listed in MS13-016.
16832| [CVE-2013-0811] Use-after-free vulnerability in Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer Use After Free Vulnerability," a different vulnerability than CVE-2013-1307.
16833| [CVE-2013-0091] Use-after-free vulnerability in Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer CElement Use After Free Vulnerability."
16834| [CVE-2013-0078] The Microsoft Antimalware Client in Windows Defender on Windows 8 and Windows RT uses an incorrect pathname for MsMpEng.exe, which allows local users to gain privileges via a crafted application, aka "Microsoft Antimalware Improper Pathname Vulnerability."
16835| [CVE-2013-0075] The TCP/IP implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows remote attackers to cause a denial of service (reboot) via a crafted packet that terminates a TCP connection, aka "TCP FIN WAIT Vulnerability."
16836| [CVE-2013-0025] Use-after-free vulnerability in Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer SLayoutRun Use After Free Vulnerability."
16837| [CVE-2013-0024] Use-after-free vulnerability in Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer pasteHTML Use After Free Vulnerability."
16838| [CVE-2013-0013] The SSL provider component in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle encrypted packets, which allows man-in-the-middle attackers to conduct SSLv2 downgrade attacks against (1) SSLv3 sessions or (2) TLS sessions by intercepting handshakes and injecting content, aka "Microsoft SSL Version 3 and TLS Protocol Security Feature Bypass Vulnerability."
16839| [CVE-2013-0008] win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle window broadcast messages, which allows local users to gain privileges via a crafted application, aka "Win32k Improper Message Handling Vulnerability."
16840| [CVE-2012-4792] Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not properly allocated or (2) is deleted, as demonstrated by a CDwnBindInfo object, and exploited in the wild in December 2012.
16841| [CVE-2012-4786] The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allow remote attackers to execute arbitrary code via a crafted TrueType Font (TTF) file, aka "TrueType Font Parsing Vulnerability."
16842| [CVE-2012-2897] The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT, as used by Google Chrome before 22.0.1229.79 and other programs, do not properly handle objects in memory, which allows remote attackers to execute arbitrary code via a crafted TrueType font file, aka "Windows Font Parsing Vulnerability" or "TrueType Font Parsing Vulnerability."
16843| [CVE-2012-2557] Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "cloneNode Use After Free Vulnerability."
16844| [CVE-2012-2556] The OpenType Font (OTF) driver in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows remote attackers to execute arbitrary code via a crafted OpenType font file, aka "OpenType Font Parsing Vulnerability."
16845| [CVE-2012-2523] Integer overflow in Microsoft Internet Explorer 8 and 9, JScript 5.8, and VBScript 5.8 on 64-bit platforms allows remote attackers to execute arbitrary code by leveraging an incorrect size calculation during object copying, aka "JavaScript Integer Overflow Remote Code Execution Vulnerability."
16846| [CVE-2012-1881] Microsoft Internet Explorer 8 and 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "OnRowsInserted Event Remote Code Execution Vulnerability."
16847| [CVE-2012-1875] Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "Same ID Property Remote Code Execution Vulnerability."
16848| [CVE-2012-1874] Microsoft Internet Explorer 8 and 9 does not properly handle objects in memory, which allows user-assisted remote attackers to execute arbitrary code by accessing a deleted object, aka "Developer Toolbar Remote Code Execution Vulnerability."
16849| [CVE-2012-1858] The toStaticHTML API (aka the SafeHTML component) in Microsoft Internet Explorer 8 and 9, Communicator 2007 R2, and Lync 2010 and 2010 Attendee does not properly handle event attributes and script, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted HTML document, aka "HTML Sanitization Vulnerability."
16850| [CVE-2012-1856] The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office 2003 SP3, Office 2003 Web Components SP3, Office 2007 SP2 and SP3, Office 2010 SP1, SQL Server 2000 SP4, SQL Server 2005 SP4, SQL Server 2008 SP2, SP3, R2, R2 SP1, and R2 SP2, Commerce Server 2002 SP4, Commerce Server 2007 SP2, Commerce Server 2009 Gold and R2, Host Integration Server 2004 SP1, Visual FoxPro 8.0 SP1, Visual FoxPro 9.0 SP2, and Visual Basic 6.0 Runtime allows remote attackers to execute arbitrary code via a crafted (1) document or (2) web page that triggers system-state corruption, aka "MSCOMCTL.OCX RCE Vulnerability."
16851| [CVE-2012-1848] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview does not properly handle user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application, aka "Scrollbar Calculation Vulnerability."
16852| [CVE-2012-1537] Heap-based buffer overflow in DirectPlay in DirectX 9.0 through 11.1 in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 allows remote attackers to execute arbitrary code via a crafted Office document, aka "DirectPlay Heap Overflow Vulnerability."
16853| [CVE-2012-1529] Use-after-free vulnerability in Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not properly initialized or (2) is deleted, aka "OnMove Use After Free Vulnerability."
16854| [CVE-2012-1528] Integer overflow in Windows Shell in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 allows local users to gain privileges via a crafted briefcase, aka "Windows Briefcase Integer Overflow Vulnerability."
16855| [CVE-2012-1527] Integer underflow in Windows Shell in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 allows local users to gain privileges via a crafted briefcase, aka "Windows Briefcase Integer Underflow Vulnerability."
16856| [CVE-2012-1523] Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "Center Element Remote Code Execution Vulnerability."
16857| [CVE-2012-0181] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview does not properly manage Keyboard Layout files, which allows local users to gain privileges via a crafted application, aka "Keyboard Layout File Vulnerability."
16858| [CVE-2012-0180] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview does not properly handle user-mode input passed to kernel mode for (1) windows and (2) messages, which allows local users to gain privileges via a crafted application, aka "Windows and Messages Vulnerability."
16859| [CVE-2012-0172] Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "VML Style Remote Code Execution Vulnerability."
16860| [CVE-2012-0159] Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview
16861| [CVE-2012-0151] The Authenticode Signature Verification function in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview does not properly validate the digest of a signed portable executable (PE) file, which allows user-assisted remote attackers to execute arbitrary code via a modified file with additional content, aka "WinVerifyTrust Signature Validation Vulnerability."
16862| [CVE-2011-2382] Microsoft Internet Explorer 8 and earlier, and Internet Explorer 9 beta, does not properly restrict cross-zone drag-and-drop actions, which allows user-assisted remote attackers to read cookie files via vectors involving an IFRAME element with a SRC attribute containing a file: URL, as demonstrated by a Facebook game, related to a "cookiejacking" issue.
16863| [CVE-2011-1999] Microsoft Internet Explorer 8 does not properly allocate and access memory, which allows remote attackers to execute arbitrary code via vectors involving a "dereferenced memory address," aka "Select Element Remote Code Execution Vulnerability."
16864| [CVE-2011-1996] Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "Option Element Remote Code Execution Vulnerability."
16865| [CVE-2011-1992] The XSS Filter in Microsoft Internet Explorer 8 allows remote attackers to read content from a different (1) domain or (2) zone via a "trial and error" attack, aka "XSS Filter Information Disclosure Vulnerability."
16866| [CVE-2011-1713] Microsoft msxml.dll, as used in Internet Explorer 8 on Windows 7, allows remote attackers to obtain potentially sensitive information about heap memory addresses via an XML document containing a call to the XSLT generate-id XPath function. NOTE: this might overlap CVE-2011-1202.
16867| [CVE-2011-1347] Unspecified vulnerability in Microsoft Internet Explorer 8 on Windows 7 allows remote attackers to bypass Protected Mode and create arbitrary files by leveraging access to a Low integrity process, as demonstrated by Stephen Fewer as the third of three chained vulnerabilities during a Pwn2Own competition at CanSecWest 2011.
16868| [CVE-2011-1346] Unspecified vulnerability in Microsoft Internet Explorer 8 on Windows 7 allows remote attackers to execute arbitrary code via unknown vectors, as demonstrated by Stephen Fewer as the second of three chained vulnerabilities during a Pwn2Own competition at CanSecWest 2011.
16869| [CVE-2011-1345] Microsoft Internet Explorer 6, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, as demonstrated by Stephen Fewer as the first of three chained vulnerabilities during a Pwn2Own competition at CanSecWest 2011, aka "Object Management Memory Corruption Vulnerability."
16870| [CVE-2011-1266] The Vector Markup Language (VML) implementation in vgx.dll in Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, aka "VML Memory Corruption Vulnerability."
16871| [CVE-2011-1260] Microsoft Internet Explorer 8 and 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, aka "Layout Memory Corruption Vulnerability."
16872| [CVE-2011-1258] Microsoft Internet Explorer 6 through 8 does not properly restrict web script, which allows user-assisted remote attackers to obtain sensitive information from a different (1) domain or (2) zone via vectors involving a drag-and-drop operation, aka "Drag and Drop Information Disclosure Vulnerability."
16873| [CVE-2011-1257] Race condition in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors involving access to an object, aka "Window Open Race Condition Vulnerability."
16874| [CVE-2011-1256] Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, aka "DOM Modification Memory Corruption Vulnerability."
16875| [CVE-2011-1255] The Timed Interactive Multimedia Extensions (aka HTML+TIME) implementation in Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, aka "Time Element Memory Corruption Vulnerability."
16876| [CVE-2011-1254] Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, aka "Drag and Drop Memory Corruption Vulnerability."
16877| [CVE-2011-1252] Cross-site scripting (XSS) vulnerability in the SafeHTML function in the toStaticHTML API in Microsoft Internet Explorer 7 and 8, Office SharePoint Server 2007 SP2, Office SharePoint Server 2010 Gold and SP1, Groove Server 2010 Gold and SP1, Windows SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via unspecified strings, aka "toStaticHTML Information Disclosure Vulnerability" or "HTML Sanitization Vulnerability."
16878| [CVE-2011-1251] Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, aka "DOM Manipulation Memory Corruption Vulnerability."
16879| [CVE-2011-1246] Microsoft Internet Explorer 8 does not properly handle content settings in HTTP responses, which allows remote web servers to obtain sensitive information from a different (1) domain or (2) zone via a crafted response, aka "MIME Sniffing Information Disclosure Vulnerability."
16880| [CVE-2011-1244] Microsoft Internet Explorer 6, 7, and 8 does not enforce intended domain restrictions on content access, which allows remote attackers to obtain sensitive information or conduct clickjacking attacks via a crafted web site, aka "Frame Tag Information Disclosure Vulnerability."
16881| [CVE-2011-0346] Use-after-free vulnerability in the ReleaseInterface function in MSHTML.DLL in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to the DOM implementation and the BreakAASpecial and BreakCircularMemoryReferences functions, as demonstrated by cross_fuzz, aka "MSHTML Memory Corruption Vulnerability."
16882| [CVE-2011-0038] Untrusted search path vulnerability in Microsoft Internet Explorer 8 might allow local users to gain privileges via a Trojan horse IEShims.dll in the current working directory, as demonstrated by a Desktop directory that contains an HTML file, aka "Internet Explorer Insecure Library Loading Vulnerability."
16883| [CVE-2011-0036] Microsoft Internet Explorer 6, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, relagted to a "dangling pointer," aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2010-2556 and CVE-2011-0035.
16884| [CVE-2011-0035] Microsoft Internet Explorer 6, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2010-2556 and CVE-2011-0036.
16885| [CVE-2010-5071] The JavaScript implementation in Microsoft Internet Explorer 8.0 and earlier does not properly restrict the set of values contained in the object returned by the getComputedStyle method, which allows remote attackers to obtain sensitive information about visited web pages by calling this method.
16886| [CVE-2010-3971] Use-after-free vulnerability in the CSharedStyleSheet::Notify function in the Cascading Style Sheets (CSS) parser in mshtml.dll, as used in Microsoft Internet Explorer 6 through 8 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a self-referential @import rule in a stylesheet, aka "CSS Memory Corruption Vulnerability."
16887| [CVE-2010-3964] Unrestricted file upload vulnerability in the Document Conversions Launcher Service in Microsoft Office SharePoint Server 2007 SP2, when the Document Conversions Load Balancer Service is enabled, allows remote attackers to execute arbitrary code via a crafted SOAP request to TCP port 8082, aka "Malformed Request Code Execution Vulnerability."
16888| [CVE-2010-3962] Use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code via vectors related to Cascading Style Sheets (CSS) token sequences and the clip attribute, aka an "invalid flag reference" issue or "Uninitialized Memory Corruption Vulnerability," as exploited in the wild in November 2010.
16889| [CVE-2010-3886] The CTimeoutEventList::InsertIntoTimeoutList function in Microsoft mshtml.dll uses a certain pointer value as part of producing Timer ID values for the setTimeout and setInterval methods in VBScript and JScript, which allows remote attackers to obtain sensitive information about the heap memory addresses used by an application, as demonstrated by the Internet Explorer 8 application.
16890| [CVE-2010-3348] Microsoft Internet Explorer 6, 7, and 8 does not prevent rendering of cached content as HTML, which allows remote attackers to access content from a different (1) domain or (2) zone via unspecified script code, aka "Cross-Domain Information Disclosure Vulnerability," a different vulnerability than CVE-2010-3342.
16891| [CVE-2010-3346] Microsoft Internet Explorer 6, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "HTML Element Memory Corruption Vulnerability."
16892| [CVE-2010-3345] Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "HTML Element Memory Corruption Vulnerability."
16893| [CVE-2010-3342] Microsoft Internet Explorer 6, 7, and 8 does not prevent rendering of cached content as HTML, which allows remote attackers to access content from a different (1) domain or (2) zone via unspecified script code, aka "Cross-Domain Information Disclosure Vulnerability," a different vulnerability than CVE-2010-3348.
16894| [CVE-2010-3331] Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory in certain circumstances involving use of Microsoft Word to read Word documents, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability."
16895| [CVE-2010-3330] Microsoft Internet Explorer 6 through 8 does not properly restrict script access to content from a different (1) domain or (2) zone, which allows remote attackers to obtain sensitive information via a crafted web site, aka "Cross-Domain Information Disclosure Vulnerability."
16896| [CVE-2010-3329] mshtmled.dll in Microsoft Internet Explorer 7 and 8 allows remote attackers to execute arbitrary code via a crafted Microsoft Office document that causes the HtmlDlgHelper class destructor to access uninitialized memory, aka "Uninitialized Memory Corruption Vulnerability."
16897| [CVE-2010-3328] Use-after-free vulnerability in the CAttrArray::PrivateFind function in mshtml.dll in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code by setting an unspecified property of a stylesheet object, aka "Uninitialized Memory Corruption Vulnerability."
16898| [CVE-2010-3327] The implementation of HTML content creation in Microsoft Internet Explorer 6 through 8 does not remove the Anchor element during pasting and editing, which might allow remote attackers to obtain sensitive deleted information by visiting a web page, aka "Anchor Element Information Disclosure Vulnerability."
16899| [CVE-2010-3325] Microsoft Internet Explorer 6 through 8 does not properly handle unspecified special characters in Cascading Style Sheets (CSS) documents, which allows remote attackers to obtain sensitive information from a different (1) domain or (2) zone via a crafted web site, aka "CSS Special Character Information Disclosure Vulnerability."
16900| [CVE-2010-3324] The toStaticHTML function in Microsoft Internet Explorer 8, and the SafeHTML function in Microsoft Windows SharePoint Services 3.0 SP2, SharePoint Foundation 2010, Office SharePoint Server 2007 SP2, Groove Server 2010, and Office Web Apps, allows remote attackers to bypass the cross-site scripting (XSS) protection mechanism and conduct XSS attacks via a crafted use of the Cascading Style Sheets (CSS) @import rule, aka "HTML Sanitization Vulnerability," a different vulnerability than CVE-2010-1257.
16901| [CVE-2010-3243] Cross-site scripting (XSS) vulnerability in the toStaticHTML function in Microsoft Internet Explorer 8, and the SafeHTML function in Microsoft Windows SharePoint Services 3.0 SP2 and Office SharePoint Server 2007 SP2, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "HTML Sanitization Vulnerability."
16902| [CVE-2010-2560] Microsoft Internet Explorer 6, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "HTML Layout Memory Corruption Vulnerability."
16903| [CVE-2010-2559] Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-3671, CVE-2009-3674, CVE-2010-0245, and CVE-2010-0246.
16904| [CVE-2010-2558] Race condition in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors related to an object in memory, aka "Race Condition Memory Corruption Vulnerability."
16905| [CVE-2010-2556] Microsoft Internet Explorer 6, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability."
16906| [CVE-2010-2442] Microsoft Internet Explorer, possibly 8, does not properly restrict focus changes, which allows remote attackers to read keystrokes via "cross-domain IFRAME gadgets."
16907| [CVE-2010-2375] Package/Privilege: Plugins for Apache, Sun and IIS web servers Unspecified vulnerability in the WebLogic Server component in Oracle Fusion Middleware 7.0 SP7, 8.1 SP6, 9.0, 9.1, 9.2 MP3, 10.0 MP2, 10.3.2, and 10.3.3 allows remote attackers to affect confidentiality and integrity, related to IIS.
16908| [CVE-2010-2118] Microsoft Internet Explorer 6.0.2900.2180 and 8.0.7600.16385 allows remote attackers to cause a denial of service (resource consumption) via JavaScript code containing an infinite loop that creates IFRAME elements for invalid news:// URIs.
16909| [CVE-2010-2091] Microsoft Outlook Web Access (OWA) 8.2.254.0, when Internet Explorer 7 on Windows Server 2003 is used, does not properly handle the id parameter in a Folder IPF.Note action to the default URI, which might allow remote attackers to obtain sensitive information or conduct cross-site scripting (XSS) attacks via an invalid value.
16910| [CVE-2010-1991] Microsoft Internet Explorer 6.0.2900.2180, 7, and 8.0.7600.16385 executes a mail application in situations where an IFRAME element has a mailto: URL in its SRC attribute, which allows remote attackers to cause a denial of service (excessive application launches) via an HTML document with many IFRAME elements.
16911| [CVE-2010-1489] The XSS Filter in Microsoft Internet Explorer 8 does not properly perform neutering for the SCRIPT tag, which allows remote attackers to conduct cross-site scripting (XSS) attacks against web sites that have no inherent XSS vulnerabilities, a different issue than CVE-2009-4074.
16912| [CVE-2010-1262] Microsoft Internet Explorer 6 SP1 and SP2, 7, and 8 allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, related to the CStyleSheet object and a free of the root container, aka "Memory Corruption Vulnerability."
16913| [CVE-2010-1261] The IE8 Developer Toolbar in Microsoft Internet Explorer 8 SP1, SP2, and SP3 allows user-assisted remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability."
16914| [CVE-2010-1260] The IE8 Developer Toolbar in Microsoft Internet Explorer 8 SP1, SP2, and SP3 allows user-assisted remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "HTML Element Memory Corruption Vulnerability."
16915| [CVE-2010-1259] Microsoft Internet Explorer 6 SP1 and SP2, 7, and 8 allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability."
16916| [CVE-2010-1258] Microsoft Internet Explorer 6, 7, and 8 does not properly determine the origin of script code, which allows remote attackers to execute script in an unintended domain or security zone, and obtain sensitive information, via unspecified vectors, aka "Event Handler Cross-Domain Vulnerability."
16917| [CVE-2010-1118] Unspecified vulnerability in Internet Explorer 8 on Microsoft Windows 7 allows remote attackers to execute arbitrary code via unknown vectors, possibly related to a use-after-free issue, as demonstrated by Peter Vreugdenhil during a Pwn2Own competition at CanSecWest 2010.
16918| [CVE-2010-1117] Heap-based buffer overflow in Internet Explorer 8 on Microsoft Windows 7 allows remote attackers to discover the base address of a Windows .dll file, and possibly have unspecified other impact, via unknown vectors, as demonstrated by Peter Vreugdenhil during a Pwn2Own competition at CanSecWest 2010.
16919| [CVE-2010-0811] Multiple unspecified vulnerabilities in the Microsoft Internet Explorer 8 Developer Tools ActiveX control in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allow remote attackers to execute arbitrary code via unknown vectors that "corrupt the system state," aka "Microsoft Internet Explorer 8 Developer Tools Vulnerability."
16920| [CVE-2010-0555] Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, 7, and 8 does not prevent rendering of non-HTML local files as HTML documents, which allows remote attackers to bypass intended access restrictions and read arbitrary files via vectors involving the product's use of text/html as the default content type for files that are encountered after a redirection, aka the URLMON sniffing vulnerability, a variant of CVE-2009-1140 and related to CVE-2008-1448.
16921| [CVE-2010-0494] Cross-domain vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 allows user-assisted remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted HTML document in a situation where the client user drags one browser window across another browser window, aka "HTML Element Cross-Domain Vulnerability."
16922| [CVE-2010-0492] Use-after-free vulnerability in mstime.dll in Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code via vectors related to the TIME2 behavior, the CTimeAction object, and destruction of markup, leading to memory corruption, aka "HTML Object Memory Corruption Vulnerability."
16923| [CVE-2010-0490] Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability."
16924| [CVE-2010-0255] Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, 7, and 8 does not prevent rendering of non-HTML local files as HTML documents, which allows remote attackers to bypass intended access restrictions and read arbitrary files via vectors involving JavaScript exploit code that constructs a reference to a file://127.0.0.1 URL, aka the dynamic OBJECT tag vulnerability, as demonstrated by obtaining the data from an index.dat file, a variant of CVE-2009-1140 and related to CVE-2008-1448.
16925| [CVE-2010-0249] Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4
16926| [CVE-2010-0248] Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "HTML Object Memory Corruption Vulnerability."
16927| [CVE-2010-0246] Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-3671, CVE-2009-3674, and CVE-2010-0245.
16928| [CVE-2010-0245] Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-3671, CVE-2009-3674, and CVE-2010-0246.
16929| [CVE-2010-0244] Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-2530 and CVE-2009-2531.
16930| [CVE-2010-0112] Multiple SQL injection vulnerabilities in the Administrative Interface in the IIS extension in Symantec IM Manager before 8.4.16 allow remote attackers to execute arbitrary SQL commands via (1) the rdReport parameter to rdpageimlogic.aspx, related to the sGetDefinition function in rdServer.dll, and SQL statements contained within a certain report file
16931| [CVE-2010-0027] The URL validation functionality in Microsoft Internet Explorer 5.01, 6, 6 SP1, 7 and 8, and the ShellExecute API function in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, does not properly process input parameters, which allows remote attackers to execute arbitrary local programs via a crafted URL, aka "URL Validation Vulnerability."
16932| [CVE-2009-4074] The XSS Filter in Microsoft Internet Explorer 8 allows remote attackers to leverage the "response-changing mechanism" to conduct cross-site scripting (XSS) attacks against web sites that have no inherent XSS vulnerabilities, related to the details of output encoding and improper modification of an HTML attribute, aka "XSS Filter Script Handling Vulnerability."
16933| [CVE-2009-4073] The printing functionality in Microsoft Internet Explorer 8 allows remote attackers to discover a local pathname, and possibly a local username, by reading the dc:title element of a PDF document that was generated from a local web page.
16934| [CVE-2009-3674] Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-3671.
16935| [CVE-2009-3673] Microsoft Internet Explorer 7 and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability."
16936| [CVE-2009-3671] Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-3674.
16937| [CVE-2009-3003] Microsoft Internet Explorer 6 through 8 allows remote attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary URL on the web site visited by the victim, as demonstrated by a visit to an attacker-controlled web page, which triggers a spoofed login form for the site containing that page.
16938| [CVE-2009-2764] Microsoft Internet Explorer 8.0.7100.0 on Windows 7 RC on the x64 platform allows remote attackers to cause a denial of service (application crash) via a certain DIV element in conjunction with SCRIPT elements that have empty contents and no reference to a valid external script location.
16939| [CVE-2009-2655] mshtml.dll in Microsoft Internet Explorer 7 and 8 on Windows XP SP3 allows remote attackers to cause a denial of service (application crash) by calling the JavaScript findText method with a crafted Unicode string in the first argument, and only one additional argument, as demonstrated by a second argument of -1.
16940| [CVE-2009-2536] Microsoft Internet Explorer 5 through 8 allows remote attackers to cause a denial of service (memory consumption and application crash) via a large integer value for the length property of a Select object, a related issue to CVE-2009-1692.
16941| [CVE-2009-2531] Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-2530.
16942| [CVE-2009-2530] Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-2531.
16943| [CVE-2009-2529] Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, 7, and 8 does not properly handle argument validation for unspecified variables, which allows remote attackers to execute arbitrary code via a crafted HTML document, aka "HTML Component Handling Vulnerability."
16944| [CVE-2009-2069] Microsoft Internet Explorer before 8 displays a cached certificate for a (1) 4xx or (2) 5xx CONNECT response page returned by a proxy server, which allows man-in-the-middle attackers to spoof an arbitrary https site by letting a browser obtain a valid certificate from this site during one request, and then sending the browser a crafted 502 response page upon a subsequent request.
16945| [CVE-2009-2064] Microsoft Internet Explorer 8, and possibly other versions, detects http content in https web pages only when the top-level frame uses https, which allows man-in-the-middle attackers to execute arbitrary web script, in an https site's context, by modifying an http page to include an https iframe that references a script file on an http site, related to "HTTP-Intended-but-HTTPS-Loadable (HPIHSL) pages."
16946| [CVE-2009-2057] Microsoft Internet Explorer before 8 uses the HTTP Host header to determine the context of a document provided in a (1) 4xx or (2) 5xx CONNECT response from a proxy server, which allows man-in-the-middle attackers to execute arbitrary web script by modifying this CONNECT response, aka an "SSL tampering" attack.
16947| [CVE-2009-1532] Microsoft Internet Explorer 8 for Windows XP SP2 and SP3
16948| [CVE-2009-1335] Microsoft Internet Explorer 7 and 8 on Windows XP and Vista allows remote attackers to cause a denial of service (application hang) via a large document composed of unprintable characters, aka MSRC 9011jr.
16949| [CVE-2009-1043] Unspecified vulnerability in Microsoft Internet Explorer 8 on Windows 7 allows remote attackers to execute arbitrary code via unknown vectors triggered by clicking on a link, as demonstrated by Nils during a PWN2OWN competition at CanSecWest 2009.
16950| [CVE-2009-1016] Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, and 7.0 SP7 allows remote authenticated users to affect confidentiality, integrity, and availability, related to IIS. NOTE: the previous information was obtained from the April 2009 CPU. Oracle has not commented on claims from a reliable researcher that this is a stack-based buffer overflow involving an unspecified Server Plug-in and a crafted SSL certificate.
16951| [CVE-2009-1012] Unspecified vulnerability in the plug-ins for Apache and IIS web servers in Oracle BEA WebLogic Server 7.0 Gold through SP7, 8.1 Gold through SP6, 9.0, 9.1, 9.2 Gold through MP3, 10.0 Gold through MP1, and 10.3 allows remote attackers to affect confidentiality, integrity, and availability. NOTE: the previous information was obtained from the April 2009 CPU. Oracle has not commented on claims from a reliable researcher that this is an integer overflow in an unspecified plug-in that parses HTTP requests, which leads to a heap-based buffer overflow.
16952| [CVE-2009-1011] Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.2.2 and 8.3.0 allows local users to affect confidentiality, integrity, and availability, related to HTML. NOTE: the previous information was obtained from the April 2009 CPU. Oracle has not commented on reliable researcher claims that this issue is for multiple integer overflows in a function that parses an optional data stream within a Microsoft Office file, leading to a heap-based buffer overflow.
16953| [CVE-2009-0084] Use-after-free vulnerability in DirectShow in Microsoft DirectX 8.1 and 9.0 allows remote attackers to execute arbitrary code via an MJPEG file or video stream with a malformed Huffman table, which triggers an exception that frees heap memory that is later accessed, aka "MJPEG Decompression Vulnerability."
16954| [CVE-2009-0072] Microsoft Internet Explorer 6.0 through 8.0 beta2 allows remote attackers to cause a denial of service (application crash) via an onload=screen[""] attribute value in a BODY element.
16955| [CVE-2008-5750] Argument injection vulnerability in Microsoft Internet Explorer 8 beta 2 on Windows XP SP3 allows remote attackers to execute arbitrary commands via the --renderer-path option in a chromehtml: URI.
16956| [CVE-2008-5556] ** DISPUTED ** The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 does not recognize attack patterns designed to operate against web pages that are encoded with utf-7, which allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks by injecting crafted utf-7 content. NOTE: the vendor reportedly disputes this issue, stating "Behaviour is by design."
16957| [CVE-2008-5555] Microsoft Internet Explorer 8.0 Beta 2 relies on the XDomainRequestAllowed HTTP header to authorize data exchange between domains, which allows remote attackers to bypass the product's XSS Filter protection mechanism, and conduct XSS and cross-domain attacks, by injecting this header after a CRLF sequence, related to "XDomainRequest Allowed Injection (XAI)." NOTE: the vendor has reportedly stated that the XSS Filter intentionally does not attempt to "address every conceivable XSS attack scenario."
16958| [CVE-2008-5554] The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 does not properly handle some HTTP headers that appear after a CRLF sequence in a URI, which allows remote attackers to bypass the XSS protection mechanism and conduct XSS or redirection attacks, as demonstrated by the (1) Location and (2) Set-Cookie HTTP headers. NOTE: the vendor has reportedly stated that the XSS Filter intentionally does not attempt to "address every conceivable XSS attack scenario."
16959| [CVE-2008-5553] The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 disables itself upon encountering a certain X-XSS-Protection HTTP header, which allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks by injecting this header after a CRLF sequence. NOTE: the vendor has reportedly stated that the XSS Filter intentionally does not attempt to "address every conceivable XSS attack scenario."
16960| [CVE-2008-5552] The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks via a CRLF sequence in conjunction with a crafted Content-Type header, as demonstrated by a header with a utf-7 charset value. NOTE: the vendor has reportedly stated that the XSS Filter intentionally does not attempt to "address every conceivable XSS attack scenario."
16961| [CVE-2008-5551] The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks by injecting data at two different positions within an HTML document, related to STYLE elements and the CSS expression property, aka a "double injection."
16962| [CVE-2008-5457] Unspecified vulnerability in the Oracle BEA WebLogic Server Plugins for Apache, Sun and IIS web servers component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, and 7.0 SP7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
16963| [CVE-2008-5416] Heap-based buffer overflow in Microsoft SQL Server 2000 SP4, 8.00.2050, 8.00.2039, and earlier
16964| [CVE-2008-4295] Microsoft Windows Mobile 6.0 on HTC Wiza 200 and HTC MDA 8125 devices does not properly handle the first attempt to establish a Bluetooth connection to a peer with a long name, which allows remote attackers to cause a denial of service (device reboot) by configuring a Bluetooth device with a long hci name and (1) connecting directly to the Windows Mobile system or (2) waiting for the Windows Mobile system to scan for nearby devices.
16965| [CVE-2008-4256] The Charts ActiveX control in Microsoft Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2 does not properly handle errors during access to incorrectly initialized objects, which allows remote attackers to execute arbitrary code via a crafted HTML document, related to corruption of the "system state," aka "Charts Control Memory Corruption Vulnerability."
16966| [CVE-2008-4255] Heap-based buffer overflow in mscomct2.ocx (aka Windows Common ActiveX control or Microsoft Animation ActiveX control) in Microsoft Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2, and Office Project 2003 SP3 and 2007 Gold and SP1 allows remote attackers to execute arbitrary code via an AVI file with a crafted stream length, which triggers an "allocation error" and memory corruption, aka "Windows Common AVI Parsing Overflow Vulnerability."
16967| [CVE-2008-4254] Multiple integer overflows in the Hierarchical FlexGrid ActiveX control (mshflxgd.ocx) in Microsoft Visual Basic 6.0 and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2 allow remote attackers to execute arbitrary code via crafted (1) Rows and (2) Cols properties to the (a) ExpandAll and (b) CollapseAll methods, related to access of incorrectly initialized objects and corruption of the "system state," aka "Hierarchical FlexGrid Control Memory Corruption Vulnerability."
16968| [CVE-2008-4253] The FlexGrid ActiveX control in Microsoft Visual Basic 6.0, Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2, Office FrontPage 2002 SP3, and Office Project 2003 SP3 does not properly handle errors during access to incorrectly initialized objects, which allows remote attackers to execute arbitrary code via a crafted HTML document, related to corruption of the "system state," aka "FlexGrid Control Memory Corruption Vulnerability."
16969| [CVE-2008-4252] The DataGrid ActiveX control in Microsoft Visual Basic 6.0 and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2 does not properly handle errors during access to incorrectly initialized objects, which allows remote attackers to execute arbitrary code via a crafted HTML document, related to corruption of the "system state," aka "DataGrid Control Memory Corruption Vulnerability."
16970| [CVE-2008-4127] Mshtml.dll in Microsoft Internet Explorer 7 Gold 7.0.5730 and 8 Beta 8.0.6001 on Windows XP SP2 allows remote attackers to cause a denial of service (failure of subsequent image rendering) via a crafted PNG file, related to an infinite loop in the CDwnTaskExec::ThreadExec function.
16971| [CVE-2008-4110] Buffer overflow in the SQLVDIRLib.SQLVDirControl ActiveX control in Tools\Binn\sqlvdir.dll in Microsoft SQL Server 2000 (aka SQL Server 8.0) allows remote attackers to cause a denial of service (browser crash) or possibly execute arbitrary code via a long URL in the second argument to the Connect method. NOTE: this issue is not a vulnerability in many environments, since the control is not marked as safe for scripting and would not execute with default Internet Explorer settings.
16972| [CVE-2008-3815] Unspecified vulnerability in Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 7.0 before 7.0(8)3, 7.1 before 7.1(2)78, 7.2 before 7.2(4)16, 8.0 before 8.0(4)6, and 8.1 before 8.1(1)13, when configured as a VPN using Microsoft Windows NT Domain authentication, allows remote attackers to bypass VPN authentication via unknown vectors.
16973| [CVE-2008-3704] Heap-based buffer overflow in the MaskedEdit ActiveX control in Msmask32.ocx 6.0.81.69, and possibly other versions before 6.0.84.18, in Microsoft Visual Studio 6.0, Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2 allows remote attackers to execute arbitrary code via a long Mask parameter, related to not "validating property values with boundary checks," as exploited in the wild in August 2008, aka "Masked Edit Control Memory Corruption Vulnerability."
16974| [CVE-2008-3015] Integer overflow in gdiplus.dll in GDI+ in Microsoft Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a BMP image file with a malformed BitMapInfoHeader that triggers a buffer overflow, aka "GDI+ BMP Integer Overflow Vulnerability."
16975| [CVE-2008-3014] Buffer overflow in gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a malformed WMF image file that triggers improper memory allocation, aka "GDI+ WMF Buffer Overrun Vulnerability."
16976| [CVE-2008-3013] gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a malformed GIF image file containing many extension markers for graphic control extensions and subsequent unknown labels, aka "GDI+ GIF Parsing Vulnerability."
16977| [CVE-2008-3012] gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 does not properly perform memory allocation, which allows remote attackers to execute arbitrary code via a malformed EMF image file, aka "GDI+ EMF Memory Corruption Vulnerability."
16978| [CVE-2008-2948] Cross-domain vulnerability in Microsoft Internet Explorer 7 and 8 allows remote attackers to change the location property of a frame via the Object data type, and use a frame from a different domain to observe domain-independent events, as demonstrated by observing onkeydown events with caballero-listener. NOTE: according to Microsoft, this is a duplicate of CVE-2008-2947, possibly a different attack vector.
16979| [CVE-2008-2579] Unspecified vulnerability in the WebLogic Server Plugins for Apache, Sun and IIS web servers component in Oracle BEA Product Suite 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, 7.0 SP7, and 6.1 SP7 has unknown impact and remote attack vectors.
16980| [CVE-2008-1544] The setRequestHeader method of the XMLHttpRequest object in Microsoft Internet Explorer 5.01, 6, and 7 does not block dangerous HTTP request headers when certain 8-bit character sequences are appended to a header name, which allows remote attackers to (1) conduct HTTP request splitting and HTTP request smuggling attacks via an incorrect Content-Length header, (2) access arbitrary virtual hosts via a modified Host header, (3) bypass referrer restrictions via an incorrect Referer header, and (4) bypass the same-origin policy and obtain sensitive information via a crafted request header.
16981| [CVE-2008-1444] Stack-based buffer overflow in Microsoft DirectX 7.0 and 8.1 on Windows 2000 SP4 allows remote attackers to execute arbitrary code via a Synchronized Accessible Media Interchange (SAMI) file with crafted parameters for a Class Name variable, aka the "SAMI Format Parsing Vulnerability."
16982| [CVE-2008-0108] Stack-based buffer overflow in wkcvqd01.dll in Microsoft Works 6 File Converter, as used in Office 2003 SP2 and SP3, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted field lengths, aka "Microsoft Works File Converter Field Length Vulnerability."
16983| [CVE-2008-0105] Microsoft Works 6 File Converter, as used in Office 2003 SP2 and SP3, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted section header index table information, aka "Microsoft Works File Converter Index Table Vulnerability."
16984| [CVE-2008-0011] Microsoft DirectX 8.1 through 9.0c, and DirectX on Microsoft XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008, does not properly perform MJPEG error checking, which allows remote attackers to execute arbitrary code via a crafted MJPEG stream in a (1) AVI or (2) ASF file, aka the "MJPEG Decoder Vulnerability."
16985| [CVE-2007-5348] Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via an image file with crafted gradient sizes in gradient fill input, which triggers a heap-based buffer overflow related to GdiPlus.dll and VGX.DLL, aka "GDI+ VML Buffer Overrun Vulnerability."
16986| [CVE-2007-5277] Microsoft Internet Explorer 6 drops DNS pins based on failed connections to irrelevant TCP ports, which makes it easier for remote attackers to conduct DNS rebinding attacks, as demonstrated by a port 81 URL in an IMG SRC, when the DNS pin had been established for a session on port 80, a different issue than CVE-2006-4560.
16987| [CVE-2007-4916] Heap-based buffer overflow in the FileFind::FindFile method in (1) MFC42.dll, (2) MFC42u.dll, (3) MFC71.dll, and (4) MFC71u.dll in Microsoft Foundation Class (MFC) Library 8.0, as used by the ListFiles method in hpqutil.dll 2.0.0.138 in Hewlett-Packard (HP) All-in-One and Photo & Imaging Gallery 1.1 and probably other products, allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long first argument.
16988| [CVE-2007-4814] Buffer overflow in the SQLServer ActiveX control in the Distributed Management Objects OLE DLL (sqldmo.dll) 2000.085.2004.00 in Microsoft SQL Server Enterprise Manager 8.05.2004 allows remote attackers to execute arbitrary code via a long second argument to the Start method.
16989| [CVE-2007-2931] Heap-based buffer overflow in Microsoft MSN Messenger 6.2, 7.0, and 7.5, and Live Messenger 8.0 allows user-assisted remote attackers to execute arbitrary code via unspecified vectors involving video conversation handling in Web Cam and video chat sessions.
16990| [CVE-2007-0842] The 64-bit versions of Microsoft Visual C++ 8.0 standard library (MSVCR80.DLL) time functions, including (1) localtime, (2) localtime_s, (3) gmtime, (4) gmtime_s, (5) ctime, (6) ctime_s, (7) wctime, (8) wctime_s, and (9) fstat, trigger an assertion error instead of a NULL pointer or EINVAL when processing a time argument later than Jan 1, 3000, which might allow context-dependent attackers to cause a denial of service (application exit) via large time values. NOTE: it could be argued that this is a design limitation of the functions, and the vulnerability lies with any application that does not validate arguments to these functions. However, this behavior is inconsistent with documentation, which does not list assertions as a possible result of an error condition.
16991| [CVE-2007-0216] wkcvqd01.dll in Microsoft Works 6 File Converter, as used in Office 2003 SP2, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted section length headers, aka "Microsoft Works File Converter Input Validation Vulnerability."
16992| [CVE-2007-0047] CRLF injection vulnerability in Adobe Acrobat Reader Plugin before 8.0.0, when used with the Microsoft.XMLHTTP ActiveX object in Internet Explorer, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the javascript: URI in the (1) FDF, (2) XML, or (3) XFDF AJAX request parameters.
16993| [CVE-2006-6252] Microsoft Windows Live Messenger 8.0 and earlier, when gestual emoticons are enabled, allows remote attackers to cause a denial of service (CPU consumption) via a long string composed of ":D" sequences, which are interpreted as emoticons.
16994| [CVE-2006-3654] Buffer overflow in wksss.exe 8.4.702.0 in Microsoft Works Spreadsheet 8.0 allows remote attackers to cause a denial of service (CPU consumption or crash) via crafted Excel files.
16995| [CVE-2006-3653] wksss.exe 8.4.702.0 in Microsoft Works Spreadsheet 8.0 allows remote attackers to cause a denial of service (CPU consumption or crash) via crafted (1) Works, (2) Excel, and (3) Lotus 1-2-3 files.
16996| [CVE-2005-3568] db2fmp process in IBM DB2 Content Manager before 8.2 Fix Pack 10 allows local users to cause a denial of service (CPU consumption) by importing a corrupted Microsoft Excel file, aka "CORRUPTED EXEL FILE WILL CAUSE TEXT SEARCH PROCESS LOOPING."
16997| [CVE-2005-3182] Buffer overflow in the HTTP management interface for GFI MailSecurity 8.1 allows remote attackers to execute arbitrary code via long headers such as (1) Host and (2) Accept in HTTP requests. NOTE: the vendor suggests that this issues is "in an underlying Microsoft technology" which, if true, could mean that the overflow affects other products as well.
16998| [CVE-2005-3174] Microsoft Windows 2000 before Update Rollup 1 for SP4 allows users to log on to the domain, even when their password has expired, if the fully qualified domain name (FQDN) is 8 characters long.
16999| [CVE-2004-0540] Microsoft Windows 2000, when running in a domain whose Fully Qualified Domain Name (FQDN) is exactly 8 characters long, does not prevent users with expired passwords from logging on to the domain.
17000| [CVE-2003-0604] Windows Media Player (WMP) 7 and 8, as running on Internet Explorer and possibly other Microsoft products that process HTML, allows remote attackers to bypass zone restrictions and access or execute arbitrary files via an IFRAME tag pointing to an ASF file whose Content-location contains a File:// URL.
17001| [CVE-2002-2435] The Cascading Style Sheets (CSS) implementation in Microsoft Internet Explorer 8.0 and earlier does not properly handle the :visited pseudo-class, which allows remote attackers to obtain sensitive information about visited web pages via a crafted HTML document, a related issue to CVE-2010-2264.
17002| [CVE-2002-2380] NetDSL ADSL Modem 800 with Microsoft Network firmware 5.5.11 allows remote attackers to gain access to configuration menus by sniffing undocumented usernames and passwords from network traffic.
17003| [CVE-2002-0797] Buffer overflow in the MIB parsing component of mibiisa for Solaris 5.6 through 8 allows remote attackers to gain root privileges.
17004| [CVE-2001-0238] Microsoft Data Access Component Internet Publishing Provider 8.103.2519.0 and earlier allows remote attackers to bypass Security Zone restrictions via WebDAV requests.
17005|
17006| SecurityFocus - https://www.securityfocus.com/bid/:
17007| [582] Microsoft IIS And PWS 8.3 Directory Name Vulnerability
17008| [58847] Microsoft Windows Defender for Windows 8 and Windows RT Local Privilege Escalation Vulnerability
17009| [42467] Microsoft Internet Explorer 8 'toStaticHTML()' HTML Sanitization Bypass Weakness
17010| [40490] Microsoft Internet Explorer 8 Developer Tools Remote Code Execution Vulnerability
17011| [37135] Microsoft Internet Explorer 8 Cross-Site Scripting Filter Cross-Site Scripting Vulnerability
17012| [35941] Microsoft Internet Explorer 8 Denial of Service Vulnerability
17013|
17014| IBM X-Force - https://exchange.xforce.ibmcloud.com:
17015| [40937] Microsoft Windows Knowledge Base Article 815495 update not installed
17016| [37226] Microsoft Windows Knowledge Base Article 815495 update not installed
17017| [19102] Microsoft Knowledge Base Article 885834 is not installed
17018| [19090] Microsoft Knowledge Base Article 885250 is not installed
17019| [18392] Microsoft Windows Knowledge Base Article 885249 update is not installed
17020| [18391] Microsoft Windows Knowledge Base Article 885835 update is not installed
17021| [18390] Microsoft Windows Knowledge Base Article 885836 update is not installed
17022| [82776] Microsoft Internet Explorer 10 on Windows 8 sandbox security bypass
17023| [66402] Microsoft Windows kernel-mode driver (win32k.sys) variant 8 privilege escalation
17024| [57338] Microsoft Internet Explorer 8 Developer Tools code execution
17025| [24509] Microsoft Windows Knowledge Base Article 889167 update is not installed
17026| [22882] Microsoft Windows Knowledge Base Article 896424 update is not installed
17027| [22156] Microsoft Windows Knowledge Base Article 899589 update is not installed
17028| [22155] Microsoft Knowledge Base Article 896688 is not installed
17029| [22072] Microsoft Knowledge Base Article 899587 is not installed
17030| [22071] Microsoft Knowledge Base Article 896428 is not installed
17031| [22069] Microsoft Knowledge Base Article 890859 is not installed
17032| [22068] Microsoft Knowledge Base Article 890046 is not installed
17033| [21704] Microsoft Windows Knowledge Base Article 896727 update is not installed
17034| [21605] Microsoft Windows Knowledge Base Article 896423 update is not installed
17035| [21603] Microsoft Windows Knowledge Base Article 899588 update is not installed
17036| [21601] Microsoft Windows Knowledge Base Article 899591 update is not installed
17037| [21600] Microsoft Windows Knowledge Base Article 893756 update is not installed
17038| [20826] Microsoft Windows Knowledge Base Article 896422 update is not installed
17039| [20825] Microsoft Windows Knowledge Base Article 896358 update is not installed
17040| [20823] Microsoft Windows Knowledge Base Article 890169 update is not installed
17041| [20822] Microsoft Windows Knowledge Base Article 883939 update is not installed
17042| [20820] Microsoft Windows Knowledge Base Article 896426 update is not installed
17043| [20382] Microsoft Windows Knowledge Base Article 894320 update is not installed
17044| [20318] Microsoft Windows Knowledge Base Article 893086 update is not installed
17045| [20317] Microsoft Windows Knowledge Base Article 890923 update is not installed
17046| [20000] Microsoft Windows Knowledge Base Article 892944 update is not installed
17047| [19875] Microsoft Knowledge Base Article 893066 is not installed
17048| [19843] Microsoft Windows Knowledge Base Article 894549 update is not installed
17049| [19252] Microsoft Knowledge Base Article 890261 is not installed
17050| [19141] Microsoft Knowledge Base Article 867282 is not installed
17051| [19118] Microsoft Knowledge Base Article 890047 is not installed
17052| [19116] Microsoft Knowledge Base Article 891781 is not installed
17053| [19112] Microsoft Knowledge Base Article 873352 is not installed
17054| [19111] Microsoft Knowledge Base Article 888113 is not installed
17055| [19106] Microsoft Knowledge Base Article 873333 is not installed
17056| [19095] Microsoft Knowledge Base Article 888302 is not installed
17057| [19092] Microsoft Knowledge Base Article 887981 is not installed
17058| [18944] Microsoft Knowledge Base Article 886185 is not installed
17059| [18770] Microsoft Knowledge Base Article 890175 is not installed
17060| [18769] Microsoft Knowledge Base Article 887219 is not installed
17061| [18768] Microsoft Windows Knowledge Base Article 891711 update is not installed
17062| [18766] Microsoft Windows Knowledge Base Article 871250 update is not installed
17063| [18394] Microsoft Windows Knowledge Base Article 870763 update is not installed
17064| [18393] Microsoft Windows Knowledge Base Article 873339 update is not installed
17065| [18314] Microsoft Windows Knowledge Base Article 889293 update is not installed
17066|
17067| Exploit-DB - https://www.exploit-db.com:
17068| [17159] Microsoft Host Integration Server <= 8.5.4224.0 DoS Vulnerabilities
17069| [31118] Microsoft Works 8.0 File Converter Field Length Remote Code Execution Vulnerability
17070| [30537] Microsoft MSN Messenger <= 8.0 - Video Conversation Buffer Overflow Vulnerability
17071| [28222] microsoft works 8.0 spreadsheet Multiple Vulnerabilities
17072| [12728] Microsoft Outlook Web Access (OWA) 8.2.254.0 - Information Disclosure vulnerability
17073|
17074| OpenVAS (Nessus) - http://www.openvas.org:
17075| [902914] Microsoft IIS GET Request Denial of Service Vulnerability
17076| [902796] Microsoft IIS IP Address/Internal Network Name Disclosure Vulnerability
17077| [902694] Microsoft Windows IIS FTP Service Information Disclosure Vulnerability (2761226)
17078| [901120] Microsoft IIS Authentication Remote Code Execution Vulnerability (982666)
17079| [900944] Microsoft IIS FTP Server 'ls' Command DOS Vulnerability
17080| [900874] Microsoft IIS FTP Service Remote Code Execution Vulnerabilities (975254)
17081| [900711] Microsoft IIS WebDAV Remote Authentication Bypass Vulnerability
17082| [900567] Microsoft IIS Security Bypass Vulnerability (970483)
17083| [802806] Microsoft IIS Default Welcome Page Information Disclosure Vulnerability
17084| [801669] Microsoft Windows IIS FTP Server DOS Vulnerability
17085| [801520] Microsoft IIS ASP Stack Based Buffer Overflow Vulnerability
17086| [100952] Microsoft IIS FTPd NLST stack overflow
17087| [11443] Microsoft IIS UNC Mapped Virtual Host Vulnerability
17088| [10680] Test Microsoft IIS Source Fragment Disclosure
17089| [903041] Microsoft Windows Kernel Privilege Elevation Vulnerability (2724197)
17090| [903037] Microsoft JScript and VBScript Engines Remote Code Execution Vulnerability (2706045)
17091| [903036] Microsoft Windows Networking Components Remote Code Execution Vulnerabilities (2733594)
17092| [903035] Microsoft Windows Kernel-Mode Drivers Privilege Elevation Vulnerability (2731847)
17093| [903033] Microsoft Windows Kernel-Mode Drivers Privilege Elevation Vulnerabilities (2718523)
17094| [903026] Microsoft Office Remote Code Execution Vulnerabilities (2663830)
17095| [903017] Microsoft Office Remote Code Execution Vulnerability (2639185)
17096| [903000] Microsoft Expression Design Remote Code Execution Vulnerability (2651018)
17097| [902936] Microsoft Windows Kernel-Mode Drivers Remote Code Execution Vulnerabilities (2783534)
17098| [902934] Microsoft .NET Framework Remote Code Execution Vulnerability (2745030)
17099| [902933] Microsoft Windows Shell Remote Code Execution Vulnerabilities (2727528)
17100| [902932] Microsoft Internet Explorer Multiple Use-After-Free Vulnerabilities (2761451)
17101| [902931] Microsoft Office Remote Code Execution Vulnerabilities - 2720184 (Mac OS X)
17102| [902930] Microsoft Office Remote Code Execution Vulnerabilities (2720184)
17103| [902923] Microsoft Internet Explorer Multiple Vulnerabilities (2722913)
17104| [902922] Microsoft Remote Desktop Protocol Remote Code Execution Vulnerability (2723135)
17105| [902921] Microsoft Office Visio/Viewer Remote Code Execution Vulnerability (2733918)
17106| [902920] Microsoft Office Remote Code Execution Vulnerability (2731879)
17107| [902919] Microsoft SharePoint Privilege Elevation Vulnerabilities (2663841)
17108| [902916] Microsoft Windows Kernel Privilege Elevation Vulnerabilities (2711167)
17109| [902913] Microsoft Office Remote Code Execution Vulnerabilities-2663830 (Mac OS X)
17110| [902912] Microsoft Office Word Remote Code Execution Vulnerability-2680352 (Mac OS X)
17111| [902911] Microsoft Office Word Remote Code Execution Vulnerability (2680352)
17112| [902910] Microsoft Office Visio Viewer Remote Code Execution Vulnerability (2597981)
17113| [902909] Microsoft Windows Service Pack Missing Multiple Vulnerabilities
17114| [902908] Microsoft Windows DirectWrite Denial of Service Vulnerability (2665364)
17115| [902906] Microsoft Windows DNS Server Denial of Service Vulnerability (2647170)
17116| [902900] Microsoft Windows SSL/TLS Information Disclosure Vulnerability (2643584)
17117| [902846] Microsoft Windows TLS Protocol Information Disclosure Vulnerability (2655992)
17118| [902845] Microsoft Windows Shell Remote Code Execution Vulnerability (2691442)
17119| [902842] Microsoft Lync Remote Code Execution Vulnerabilities (2707956)
17120| [902841] Microsoft .NET Framework Remote Code Execution Vulnerability (2706726)
17121| [902839] Microsoft FrontPage Server Extensions MS-DOS Device Name DoS Vulnerability
17122| [902833] Microsoft .NET Framework Remote Code Execution Vulnerability (2693777)
17123| [902832] MS Security Update For Microsoft Office, .NET Framework, and Silverlight (2681578)
17124| [902829] Microsoft Windows Common Controls Remote Code Execution Vulnerability (2664258)
17125| [902828] Microsoft .NET Framework Remote Code Execution Vulnerability (2671605)
17126| [902818] Microsoft Remote Desktop Protocol Remote Code Execution Vulnerabilities (2671387)
17127| [902817] Microsoft Visual Studio Privilege Elevation Vulnerability (2651019)
17128| [902811] Microsoft .NET Framework and Microsoft Silverlight Remote Code Execution Vulnerabilities (2651026)
17129| [902807] Microsoft Windows Media Could Allow Remote Code Execution Vulnerabilities (2636391)
17130| [902798] Microsoft SMB Signing Enabled and Not Required At Server
17131| [902797] Microsoft SMB Signing Information Disclosure Vulnerability
17132| [902785] Microsoft AntiXSS Library Information Disclosure Vulnerability (2607664)
17133| [902784] Microsoft Windows Object Packager Remote Code Execution Vulnerability (2603381)
17134| [902783] Microsoft Windows Kernel Security Feature Bypass Vulnerability (2644615)
17135| [902782] MicroSoft Windows Server Service Remote Code Execution Vulnerability (921883)
17136| [902766] Microsoft Windows Kernel Privilege Elevation Vulnerability (2633171)
17137| [902746] Microsoft Active Accessibility Remote Code Execution Vulnerability (2623699)
17138| [902727] Microsoft Office Excel Remote Code Execution Vulnerabilities (2587505)
17139| [902708] Microsoft Remote Desktop Protocol Denial of Service Vulnerability (2570222)
17140| [902696] Microsoft Internet Explorer Multiple Vulnerabilities (2761465)
17141| [902693] Microsoft Windows Kernel-Mode Drivers Remote Code Execution Vulnerabilities (2761226)
17142| [902692] Microsoft Office Excel ReadAV Arbitrary Code Execution Vulnerability
17143| [902689] Microsoft SQL Server Report Manager Cross Site Scripting Vulnerability (2754849)
17144| [902688] Microsoft System Center Configuration Manager XSS Vulnerability (2741528)
17145| [902687] Microsoft Windows Data Access Components Remote Code Execution Vulnerability (2698365)
17146| [902686] Microsoft Internet Explorer Multiple Vulnerabilities (2719177)
17147| [902683] Microsoft Remote Desktop Protocol Remote Code Execution Vulnerability (2685939)
17148| [902682] Microsoft Internet Explorer Multiple Vulnerabilities (2699988)
17149| [902678] Microsoft Silverlight Code Execution Vulnerabilities - 2681578 (Mac OS X)
17150| [902677] Microsoft Windows Prtition Manager Privilege Elevation Vulnerability (2690533)
17151| [902676] Microsoft Windows TCP/IP Privilege Elevation Vulnerabilities (2688338)
17152| [902670] Microsoft Internet Explorer Multiple Vulnerabilities (2675157)
17153| [902663] Microsoft Remote Desktop Protocol Remote Code Execution Vulnerabilities (2671387)
17154| [902662] MicroSoft SMB Server Trans2 Request Remote Code Execution Vulnerability
17155| [902660] Microsoft SMB Transaction Parsing Remote Code Execution Vulnerability
17156| [902658] Microsoft RDP Server Private Key Information Disclosure Vulnerability
17157| [902649] Microsoft Internet Explorer Multiple Vulnerabilities (2647516)
17158| [902642] Microsoft Internet Explorer Multiple Vulnerabilities (2618444)
17159| [902626] Microsoft SharePoint SafeHTML Information Disclosure Vulnerabilities (2412048)
17160| [902625] Microsoft SharePoint Multiple Privilege Escalation Vulnerabilities (2451858)
17161| [902613] Microsoft Internet Explorer Multiple Vulnerabilities (2559049)
17162| [902609] Microsoft Windows CSRSS Privilege Escalation Vulnerabilities (2507938)
17163| [902598] Microsoft Windows Time Component Remote Code Execution Vulnerability (2618451)
17164| [902597] Microsoft Windows Media Remote Code Execution Vulnerability (2648048)
17165| [902596] Microsoft Windows OLE Remote Code Execution Vulnerability (2624667)
17166| [902588] Microsoft Windows Internet Protocol Validation Remote Code Execution Vulnerability
17167| [902581] Microsoft .NET Framework and Silverlight Remote Code Execution Vulnerability (2604930)
17168| [902580] Microsoft Host Integration Server Denial of Service Vulnerabilities (2607670)
17169| [902567] Microsoft Office Remote Code Execution Vulnerabilites (2587634)
17170| [902566] Microsoft Windows WINS Local Privilege Escalation Vulnerability (2571621)
17171| [902552] Microsoft .NET Framework Chart Control Information Disclosure Vulnerability (2567943)
17172| [902551] Microsoft .NET Framework Information Disclosure Vulnerability (2567951)
17173| [902523] Microsoft .NET Framework and Silverlight Remote Code Execution Vulnerability (2514842)
17174| [902522] Microsoft .NET Framework Remote Code Execution Vulnerability (2538814)
17175| [902518] Microsoft .NET Framework Security Bypass Vulnerability
17176| [902516] Microsoft Windows WINS Remote Code Execution Vulnerability (2524426)
17177| [902502] Microsoft .NET Framework Remote Code Execution Vulnerability (2484015)
17178| [902501] Microsoft JScript and VBScript Scripting Engines Remote Code Execution Vulnerability (2514666)
17179| [902496] Microsoft Office IME (Chinese) Privilege Elevation Vulnerability (2652016)
17180| [902495] Microsoft Office Remote Code Execution Vulnerability (2590602)
17181| [902494] Microsoft Office Excel Remote Code Execution Vulnerability (2640241)
17182| [902493] Microsoft Publisher Remote Code Execution Vulnerabilities (2607702)
17183| [902492] Microsoft Office PowerPoint Remote Code Execution Vulnerabilities (2639142)
17184| [902487] Microsoft Windows Active Directory LDAPS Authentication Bypass Vulnerability (2630837)
17185| [902484] Microsoft Windows TCP/IP Remote Code Execution Vulnerability (2588516)
17186| [902464] Microsoft Visio Remote Code Execution Vulnerabilities (2560978)
17187| [902463] Microsoft Windows Client/Server Run-time Subsystem Privilege Escalation Vulnerability (2567680)
17188| [902455] Microsoft Visio Remote Code Execution Vulnerability (2560847)
17189| [902445] Microsoft XML Editor Information Disclosure Vulnerability (2543893)
17190| [902443] Microsoft Internet Explorer Multiple Vulnerabilities (2530548)
17191| [902440] Microsoft Windows SMB Server Remote Code Execution Vulnerability (2536275)
17192| [902430] Microsoft Office PowerPoint Remote Code Execution Vulnerabilities (2545814)
17193| [902425] Microsoft Windows SMB Accessible Shares
17194| [902423] Microsoft Office Visio Viewer Remote Code Execution Vulnerabilities (2663510)
17195| [902411] Microsoft Office PowerPoint Remote Code Execution Vulnerabilities (2489283)
17196| [902410] Microsoft Office Excel Remote Code Execution Vulnerabilities (2489279)
17197| [902403] Microsoft Windows Fraudulent Digital Certificates Spoofing Vulnerability
17198| [902395] Microsoft Bluetooth Stack Remote Code Execution Vulnerability (2566220)
17199| [902378] Microsoft Office Excel Remote Code Execution Vulnerabilities (2537146)
17200| [902377] Microsoft Windows OLE Automation Remote Code Execution Vulnerability (2476490)
17201| [902365] Microsoft GDI+ Remote Code Execution Vulnerability (2489979)
17202| [902364] Microsoft Office Remote Code Execution Vulnerabilites (2489293)
17203| [902351] Microsoft Groove Remote Code Execution Vulnerability (2494047)
17204| [902337] Microsoft Windows Kernel Elevation of Privilege Vulnerability (2393802)
17205| [902336] Microsoft JScript and VBScript Scripting Engines Information Disclosure Vulnerability (2475792)
17206| [902325] Microsoft Internet Explorer 'CSS Import Rule' Use-after-free Vulnerability
17207| [902324] Microsoft SharePoint Could Allow Remote Code Execution Vulnerability (2455005)
17208| [902319] Microsoft Foundation Classes Could Allow Remote Code Execution Vulnerability (2387149)
17209| [902290] Microsoft Windows Active Directory SPN Denial of Service (2478953)
17210| [902289] Microsoft Windows LSASS Privilege Escalation Vulnerability (2478960)
17211| [902288] Microsoft Kerberos Privilege Escalation Vulnerabilities (2496930)
17212| [902287] Microsoft Visio Remote Code Execution Vulnerabilities (2451879)
17213| [902285] Microsoft Internet Explorer Information Disclosure Vulnerability (2501696)
17214| [902281] Microsoft Windows Data Access Components Remote Code Execution Vulnerabilities (2451910)
17215| [902280] Microsoft Windows BranchCache Remote Code Execution Vulnerability (2385678)
17216| [902277] Microsoft Windows Netlogon Service Denial of Service Vulnerability (2207559)
17217| [902276] Microsoft Windows Task Scheduler Elevation of Privilege Vulnerability (2305420)
17218| [902274] Microsoft Publisher Remote Code Execution Vulnerability (2292970)
17219| [902269] Microsoft Windows SMB Server NTLM Multiple Vulnerabilities (971468)
17220| [902265] Microsoft Office Word Remote Code Execution Vulnerabilities (2293194)
17221| [902264] Microsoft Office Excel Remote Code Execution Vulnerabilities (2293211)
17222| [902263] Microsoft Windows Media Player Network Sharing Remote Code Execution Vulnerability (2281679)
17223| [902262] Microsoft Windows Shell and WordPad COM Validation Vulnerability (2405882)
17224| [902256] Microsoft Windows win32k.sys Driver 'CreateDIBPalette()' BOF Vulnerability
17225| [902255] Microsoft Visual Studio Insecure Library Loading Vulnerability
17226| [902254] Microsoft Office Products Insecure Library Loading Vulnerability
17227| [902250] Microsoft Word 2003 'MSO.dll' Null Pointer Dereference Vulnerability
17228| [902246] Microsoft Internet Explorer 'toStaticHTML()' Cross Site Scripting Vulnerability
17229| [902243] Microsoft Outlook TNEF Remote Code Execution Vulnerability (2315011)
17230| [902232] Microsoft Windows TCP/IP Privilege Elevation Vulnerabilities (978886)
17231| [902231] Microsoft Windows Tracing Feature Privilege Elevation Vulnerabilities (982799)
17232| [902230] Microsoft .NET Common Language Runtime Remote Code Execution Vulnerability (2265906)
17233| [902229] Microsoft Window MPEG Layer-3 Remote Code Execution Vulnerability (2115168)
17234| [902228] Microsoft Office Word Remote Code Execution Vulnerabilities (2269638)
17235| [902227] Microsoft Windows LSASS Denial of Service Vulnerability (975467)
17236| [902226] Microsoft Windows Shell Remote Code Execution Vulnerability (2286198)
17237| [902217] Microsoft Outlook SMB Attachment Remote Code Execution Vulnerability (978212)
17238| [902210] Microsoft IE cross-domain IFRAME gadgets keystrokes steal Vulnerability
17239| [902193] Microsoft .NET Framework XML HMAC Truncation Vulnerability (981343)
17240| [902192] Microsoft Office COM Validation Remote Code Execution Vulnerability (983235)
17241| [902191] Microsoft Internet Explorer Multiple Vulnerabilities (982381)
17242| [902183] Microsoft Internet Explorer 'IFRAME' Denial Of Service Vulnerability
17243| [902178] Microsoft Visual Basic Remote Code Execution Vulnerability (978213)
17244| [902176] Microsoft SharePoint '_layouts/help.aspx' Cross Site Scripting Vulnerability
17245| [902166] Microsoft Internet Explorer 'neutering' Mechanism XSS Vulnerability
17246| [902159] Microsoft VBScript Scripting Engine Remote Code Execution Vulnerability (980232)
17247| [902158] Microsoft Office Publisher Remote Code Execution Vulnerability (981160)
17248| [902157] Microsoft 'ISATAP' Component Spoofing Vulnerability (978338)
17249| [902156] Microsoft SMB Client Remote Code Execution Vulnerabilities (980232)
17250| [902155] Microsoft Internet Explorer Multiple Vulnerabilities (980182)
17251| [902151] Microsoft Internet Explorer Denial of Service Vulnerability - Mar10
17252| [902133] Microsoft Office Excel Multiple Vulnerabilities (980150)
17253| [902117] Microsoft DirectShow Remote Code Execution Vulnerability (977935)
17254| [902116] Microsoft Client/Server Run-time Subsystem Privilege Elevation Vulnerability (978037)
17255| [902115] Microsoft Kerberos Denial of Service Vulnerability (977290)
17256| [902114] Microsoft Office PowerPoint Remote Code Execution Vulnerabilities (975416)
17257| [902112] Microsoft SMB Client Remote Code Execution Vulnerabilities (978251)
17258| [902095] Microsoft Office Excel Remote Code Execution Vulnerability (2269707)
17259| [902094] Microsoft Windows Kernel Mode Drivers Privilege Elevation Vulnerabilities (2160329)
17260| [902093] Microsoft Windows Kernel Privilege Elevation Vulnerabilities (981852)
17261| [902080] Microsoft Help and Support Center Remote Code Execution Vulnerability (2229593)
17262| [902069] Microsoft SharePoint Privilege Elevation Vulnerabilities (2028554)
17263| [902068] Microsoft Office Excel Remote Code Execution Vulnerabilities (2027452)
17264| [902067] Microsoft Windows Kernel Mode Drivers Privilege Escalation Vulnerabilities (979559)
17265| [902039] Microsoft Visio Remote Code Execution Vulnerabilities (980094)
17266| [902038] Microsoft MPEG Layer-3 Codecs Remote Code Execution Vulnerability (977816)
17267| [902033] Microsoft Windows '.ani' file Denial of Service vulnerability
17268| [902015] Microsoft Paint Remote Code Execution Vulnerability (978706)
17269| [901305] Microsoft Windows IP-HTTPS Component Security Feature Bypass Vulnerability (2765809)
17270| [901304] Microsoft Windows File Handling Component Remote Code Execution Vulnerability (2758857)
17271| [901301] Microsoft Windows Kerberos Denial of Service Vulnerability (2743555)
17272| [901212] Microsoft Windows DirectPlay Remote Code Execution Vulnerability (2770660)
17273| [901211] Microsoft Windows Common Controls Remote Code Execution Vulnerability (2720573)
17274| [901210] Microsoft Office Privilege Elevation Vulnerability - 2721015 (Mac OS X)
17275| [901209] Microsoft Windows Media Center Remote Code Execution Vulnerabilities (2604926)
17276| [901208] Microsoft Internet Explorer Multiple Vulnerabilities (2586448)
17277| [901205] Microsoft Windows Components Remote Code Execution Vulnerabilities (2570947)
17278| [901193] Microsoft Windows Media Remote Code Execution Vulnerabilities (2510030)
17279| [901183] Internet Information Services (IIS) FTP Service Remote Code Execution Vulnerability (2489256)
17280| [901180] Microsoft Internet Explorer Multiple Vulnerabilities (2482017)
17281| [901169] Microsoft Windows Address Book Remote Code Execution Vulnerability (2423089)
17282| [901166] Microsoft Office Remote Code Execution Vulnerabilites (2423930)
17283| [901164] Microsoft Windows SChannel Denial of Service Vulnerability (2207566)
17284| [901163] Microsoft Windows Media Player Remote Code Execution Vulnerability (2378111))
17285| [901162] Microsoft Internet Explorer Multiple Vulnerabilities (2360131)
17286| [901161] Microsoft ASP.NET Information Disclosure Vulnerability (2418042)
17287| [901151] Microsoft Internet Information Services Remote Code Execution Vulnerabilities (2267960)
17288| [901150] Microsoft Windows Print Spooler Service Remote Code Execution Vulnerability(2347290)
17289| [901140] Microsoft Windows SMB Code Execution and DoS Vulnerabilities (982214)
17290| [901139] Microsoft Internet Explorer Multiple Vulnerabilities (2183461)
17291| [901119] Microsoft Windows OpenType Compact Font Format Driver Privilege Escalation Vulnerability (980218)
17292| [901102] Microsoft Windows Media Services Remote Code Execution Vulnerability (980858)
17293| [901097] Microsoft Internet Explorer Multiple Vulnerabilities (978207)
17294| [901095] Microsoft Embedded OpenType Font Engine Remote Code Execution Vulnerabilities (972270)
17295| [901069] Microsoft Office Project Remote Code Execution Vulnerability (967183)
17296| [901065] Microsoft Windows IAS Remote Code Execution Vulnerability (974318)
17297| [901064] Microsoft Windows ADFS Remote Code Execution Vulnerability (971726)
17298| [901063] Microsoft Windows LSASS Denial of Service Vulnerability (975467)
17299| [901048] Microsoft Windows Active Directory Denial of Service Vulnerability (973309)
17300| [901041] Microsoft Internet Explorer Multiple Code Execution Vulnerabilities (974455)
17301| [901012] Microsoft Windows Media Format Remote Code Execution Vulnerability (973812)
17302| [900973] Microsoft Office Word Remote Code Execution Vulnerability (976307)
17303| [900965] Microsoft Windows SMB2 Negotiation Protocol Remote Code Execution Vulnerability
17304| [900964] Microsoft .NET Common Language Runtime Code Execution Vulnerability (974378)
17305| [900963] Microsoft Windows Kernel Privilege Escalation Vulnerability (971486)
17306| [900957] Microsoft Windows Patterns & Practices EntLib DOS Vulnerability
17307| [900956] Microsoft Windows Patterns & Practices EntLib Version Detection
17308| [900929] Microsoft JScript Scripting Engine Remote Code Execution Vulnerability (971961)
17309| [900908] Microsoft Windows Message Queuing Privilege Escalation Vulnerability (971032)
17310| [900907] Microsoft Windows AVI Media File Parsing Vulnerabilities (971557)
17311| [900898] Microsoft Internet Explorer 'XSS Filter' XSS Vulnerabilities - Nov09
17312| [900897] Microsoft Internet Explorer PDF Information Disclosure Vulnerability - Nov09
17313| [900891] Microsoft Internet Denial Of Service Vulnerability - Nov09
17314| [900887] Microsoft Office Excel Multiple Vulnerabilities (972652)
17315| [900886] Microsoft Windows Kernel-Mode Drivers Multiple Vulnerabilities (969947)
17316| [900881] Microsoft Windows Indexing Service ActiveX Vulnerability (969059)
17317| [900880] Microsoft Windows ATL COM Initialization Code Execution Vulnerability (973525)
17318| [900879] Microsoft Windows Media Player ASF Heap Overflow Vulnerability (974112)
17319| [900878] Microsoft Products GDI Plus Code Execution Vulnerabilities (957488)
17320| [900877] Microsoft Windows LSASS Denial of Service Vulnerability (975467)
17321| [900876] Microsoft Windows CryptoAPI X.509 Spoofing Vulnerabilities (974571)
17322| [900873] Microsoft Windows DNS Devolution Third-Level Domain Name Resolving Weakness (971888)
17323| [900863] Microsoft Internet Explorer 'window.print()' DOS Vulnerability
17324| [900838] Microsoft Windows TCP/IP Remote Code Execution Vulnerability (967723)
17325| [900837] Microsoft DHTML Editing Component ActiveX Remote Code Execution Vulnerability (956844)
17326| [900836] Microsoft Internet Explorer Address Bar Spoofing Vulnerability
17327| [900826] Microsoft Internet Explorer 'location.hash' DOS Vulnerability
17328| [900814] Microsoft Windows WINS Remote Code Execution Vulnerability (969883)
17329| [900813] Microsoft Remote Desktop Connection Remote Code Execution Vulnerability (969706)
17330| [900809] Microsoft Visual Studio ATL Remote Code Execution Vulnerability (969706)
17331| [900808] Microsoft Visual Products Version Detection
17332| [900757] Microsoft Windows Media Player '.AVI' File DOS Vulnerability
17333| [900741] Microsoft Internet Explorer Information Disclosure Vulnerability Feb10
17334| [900740] Microsoft Windows Kernel Could Allow Elevation of Privilege (977165)
17335| [900690] Microsoft Virtual PC/Server Privilege Escalation Vulnerability (969856)
17336| [900689] Microsoft Embedded OpenType Font Engine Remote Code Execution Vulnerabilities (961371))
17337| [900670] Microsoft Office Excel Remote Code Execution Vulnerabilities (969462)
17338| [900589] Microsoft ISA Server Privilege Escalation Vulnerability (970953)
17339| [900588] Microsoft DirectShow Remote Code Execution Vulnerability (961373)
17340| [900568] Microsoft Windows Search Script Execution Vulnerability (963093)
17341| [900566] Microsoft Active Directory LDAP Remote Code Execution Vulnerability (969805)
17342| [900476] Microsoft Excel Remote Code Execution Vulnerabilities (968557)
17343| [900465] Microsoft Windows DNS Memory Corruption Vulnerability - Mar09
17344| [900461] Microsoft MSN Live Messneger Denial of Service Vulnerability
17345| [900445] Microsoft Autorun Arbitrary Code Execution Vulnerability (08-038)
17346| [900404] Microsoft Windows RTCP Unspecified Remote DoS Vulnerability
17347| [900400] Microsoft Internet Explorer Unicode String DoS Vulnerability
17348| [900391] Microsoft Office Publisher Remote Code Execution Vulnerability (969516)
17349| [900366] Microsoft Internet Explorer Web Script Execution Vulnerabilites
17350| [900365] Microsoft Office Word Remote Code Execution Vulnerabilities (969514)
17351| [900337] Microsoft Internet Explorer Denial of Service Vulnerability - Apr09
17352| [900336] Microsoft Windows Media Player MID File Integer Overflow Vulnerability
17353| [900328] Microsoft Internet Explorer Remote Code Execution Vulnerability (963027)
17354| [900314] Microsoft XML Core Service Information Disclosure Vulnerability
17355| [900303] Microsoft Internet Explorer HTML Form Value DoS Vulnerability
17356| [900299] Microsoft Report Viewer Information Disclosure Vulnerability (2578230)
17357| [900297] Microsoft Windows Kernel Denial of Service Vulnerability (2556532)
17358| [900296] Microsoft Windows TCP/IP Stack Denial of Service Vulnerability (2563894)
17359| [900295] Microsoft Windows DNS Server Remote Code Execution Vulnerability (2562485)
17360| [900294] Microsoft Data Access Components Remote Code Execution Vulnerabilities (2560656)
17361| [900288] Microsoft Distributed File System Remote Code Execution Vulnerabilities (2535512)
17362| [900287] Microsoft SMB Client Remote Code Execution Vulnerabilities (2536276)
17363| [900285] Microsoft Foundation Class (MFC) Library Remote Code Execution Vulnerability (2500212)
17364| [900282] Microsoft DNS Resolution Remote Code Execution Vulnerability (2509553)
17365| [900281] Microsoft IE Developer Tools WMITools and Windows Messenger ActiveX Control Vulnerability (2508272)
17366| [900280] Microsoft Windows SMB Server Remote Code Execution Vulnerability (2508429)
17367| [900279] Microsoft SMB Client Remote Code Execution Vulnerabilities (2511455)
17368| [900278] Microsoft Internet Explorer Multiple Vulnerabilities (2497640)
17369| [900273] Microsoft Remote Desktop Client Remote Code Execution Vulnerability (2508062)
17370| [900267] Microsoft Media Decompression Remote Code Execution Vulnerability (2447961)
17371| [900266] Microsoft Windows Movie Maker Could Allow Remote Code Execution Vulnerability (2424434)
17372| [900263] Microsoft Windows OpenType Compact Font Format Driver Privilege Escalation Vulnerability (2296199)
17373| [900262] Microsoft Internet Explorer Multiple Vulnerabilities (2416400)
17374| [900261] Microsoft Office PowerPoint Remote Code Execution Vulnerabilities (2293386)
17375| [900248] Microsoft Windows Movie Maker Could Allow Remote Code Execution Vulnerability (981997)
17376| [900246] Microsoft Media Decompression Remote Code Execution Vulnerability (979902)
17377| [900245] Microsoft Data Analyzer and IE Developer Tools ActiveX Control Vulnerability (980195)
17378| [900241] Microsoft Outlook Express and Windows Mail Remote Code Execution Vulnerability (978542)
17379| [900240] Microsoft Exchange and Windows SMTP Service Denial of Service Vulnerability (981832)
17380| [900237] Microsoft Windows Authentication Verification Remote Code Execution Vulnerability (981210)
17381| [900236] Microsoft Windows Kernel Could Allow Elevation of Privilege (979683)
17382| [900235] Microsoft Windows Media Player Could Allow Remote Code Execution (979402)
17383| [900232] Microsoft Windows Movie Maker Could Allow Remote Code Execution Vulnerability (975561)
17384| [900230] Microsoft Windows SMB Server Multiple Vulnerabilities (971468)
17385| [900229] Microsoft Data Analyzer ActiveX Control Vulnerability (978262)
17386| [900228] Microsoft Office (MSO) Remote Code Execution Vulnerability (978214)
17387| [900227] Microsoft Windows Shell Handler Could Allow Remote Code Execution Vulnerability (975713)
17388| [900223] Microsoft Ancillary Function Driver Elevation of Privilege Vulnerability (956803)
17389| [900192] Microsoft Internet Explorer Information Disclosure Vulnerability
17390| [900187] Microsoft Internet Explorer Argument Injection Vulnerability
17391| [900178] Microsoft Windows 'UnhookWindowsHookEx' Local DoS Vulnerability
17392| [900173] Microsoft Windows Media Player Version Detection
17393| [900172] Microsoft Windows Media Player 'MIDI' or 'DAT' File DoS Vulnerability
17394| [900170] Microsoft iExplorer '&NBSP
17395| [900131] Microsoft Internet Explorer Denial of Service Vulnerability
17396| [900125] Microsoft SQL Server 2000 sqlvdir.dll ActiveX Buffer Overflow Vulnerability
17397| [900120] Microsoft Organization Chart Remote Code Execution Vulnerability
17398| [900108] Microsoft Windows NSlookup.exe Remote Code Execution Vulnerability
17399| [900097] Vulnerability in Microsoft DirectShow Could Allow Remote Code Execution
17400| [900095] Microsoft ISA Server and Forefront Threat Management Gateway DoS Vulnerability (961759)
17401| [900093] Microsoft DirectShow Remote Code Execution Vulnerability (961373)
17402| [900080] Vulnerabilities in Microsoft Office Visio Could Allow Remote Code Execution (957634)
17403| [900079] Vulnerabilities in Microsoft Exchange Could Allow Remote Code Execution (959239)
17404| [900064] Vulnerability in Microsoft Office SharePoint Server Could Cause Elevation of Privilege (957175)
17405| [900063] Vulnerabilities in Microsoft Office Word Could Allow Remote Code Execution (957173)
17406| [900061] Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (959070)
17407| [900058] Microsoft XML Core Services Remote Code Execution Vulnerability (955218)
17408| [900048] Microsoft Excel Remote Code Execution Vulnerability (956416)
17409| [900047] Microsoft Office nformation Disclosure Vulnerability (957699)
17410| [900046] Microsoft Office Remote Code Execution Vulnerabilities (955047)
17411| [900033] Microsoft PowerPoint Could Allow Remote Code Execution Vulnerabilities (949785)
17412| [900029] Microsoft Office Filters Could Allow Remote Code Execution Vulnerabilities (924090)
17413| [900028] Microsoft Excel Could Allow Remote Code Execution Vulnerabilities (954066)
17414| [900025] Microsoft Office Version Detection
17415| [900006] Microsoft Word Could Allow Remote Code Execution Vulnerability
17416| [900004] Microsoft Access Snapshot Viewer ActiveX Control Vulnerability
17417| [855384] Solaris Update for snmp/mibiisa 108870-36
17418| [855273] Solaris Update for snmp/mibiisa 108869-36
17419| [803028] Microsoft Internet Explorer Remote Code Execution Vulnerability (2757760)
17420| [803007] Microsoft Windows Minimum Certificate Key Length Spoofing Vulnerability (2661254)
17421| [802912] Microsoft Unauthorized Digital Certificates Spoofing Vulnerability (2728973)
17422| [802888] Microsoft Windows Media Service Handshake Sequence DoS Vulnerability
17423| [802886] Microsoft Sidebar and Gadgets Remote Code Execution Vulnerability (2719662)
17424| [802864] Microsoft XML Core Services Remote Code Execution Vulnerability (2719615)
17425| [802774] Microsoft VPN ActiveX Control Remote Code Execution Vulnerability (2695962)
17426| [802726] Microsoft SMB Signing Disabled
17427| [802708] Microsoft Internet Explorer Code Execution and DoS Vulnerabilities
17428| [802634] Microsoft Windows Unauthorized Digital Certificates Spoofing Vulnerability (2718704)
17429| [802500] Microsoft Windows TrueType Font Parsing Privilege Elevation Vulnerability
17430| [802468] Compatibility Issues Affecting Signed Microsoft Binaries (2749655)
17431| [802462] Microsoft ActiveSync Null Pointer Dereference Denial Of Service Vulnerability
17432| [802426] Microsoft Windows ActiveX Control Multiple Vulnerabilities (2647518)
17433| [802383] Microsoft Windows Color Control Panel Privilege Escalation Vulnerability
17434| [802379] Microsoft Windows Kernel 'win32k.sys' Memory Corruption Vulnerability
17435| [802287] Microsoft Internet Explorer Cache Objects History Information Disclosure Vulnerability
17436| [802286] Microsoft Internet Explorer Multiple Information Disclosure Vulnerabilities
17437| [802260] Microsoft Windows WINS Remote Code Execution Vulnerability (2524426)
17438| [802203] Microsoft Internet Explorer Cookie Hijacking Vulnerability
17439| [802202] Microsoft Internet Explorer Cookie Hijacking Vulnerability
17440| [802140] Microsoft Explorer HTTPS Sessions Multiple Vulnerabilities (Windows)
17441| [802136] Microsoft Windows Insecure Library Loading Vulnerability (2269637)
17442| [801991] Microsoft Windows SMB/NETBIOS NULL Session Authentication Bypass Vulnerability
17443| [801966] Microsoft Windows ActiveX Control Multiple Vulnerabilities (2562937)
17444| [801935] Microsoft Silverlight Multiple Memory Leak Vulnerabilities
17445| [801934] Microsoft Silverlight Version Detection
17446| [801914] Microsoft Windows IPv4 Default Configuration Security Bypass Vulnerability
17447| [801876] Microsoft Internet Explorer 'msxml.dll' Information Disclosure Vulnerability
17448| [801831] Microsoft Internet Explorer Incorrect GUI Display Vulnerability
17449| [801830] Microsoft Internet Explorer 'ReleaseInterface()' Remote Code Execution Vulnerability
17450| [801725] Microsoft Products GDI Plus Remote Code Execution Vulnerabilities (954593)
17451| [801721] Microsoft Active Directory Denial of Service Vulnerability (953235)
17452| [801719] Microsoft Windows CSRSS CSRFinalizeContext Local Privilege Escalation Vulnerability (930178)
17453| [801718] Microsoft Windows Vista Information Disclosure Vulnerability (931213)
17454| [801717] Microsoft Windows Vista Teredo Interface Firewall Bypass Vulnerability
17455| [801716] Microsoft Outlook Express/Windows Mail MHTML URI Handler Information Disclosure Vulnerability (929123)
17456| [801715] Microsoft XML Core Services Remote Code Execution Vulnerability (936227)
17457| [801713] Microsoft Outlook Express And Windows Mail NNTP Protocol Heap Buffer Overflow Vulnerability (941202)
17458| [801707] Microsoft Internet Explorer mshtml.dll Remote Memory Corruption Vulnerability (942615)
17459| [801706] Microsoft Windows TCP/IP Remote Code Execution Vulnerabilities (941644)
17460| [801705] Microsoft Windows TCP/IP Denial of Service Vulnerability (946456)
17461| [801704] Microsoft Internet Information Services Privilege Elevation Vulnerability (942831)
17462| [801702] Microsoft Internet Explorer HTML Rendering Remote Memory Corruption Vulnerability (944533)
17463| [801701] Microsoft Windows DNS Client Service Response Spoofing Vulnerability (945553)
17464| [801677] Microsoft WMI Administrative Tools ActiveX Control Remote Code Execution Vulnerabilities
17465| [801606] Microsoft Internet Explorer 'mshtml.dll' Information Disclosure Vulnerability
17466| [801598] Microsoft Windows2k3 Active Directory 'BROWSER ELECTION' Buffer Overflow Vulnerability
17467| [801597] Microsoft Office Excel 2003 Invalid Object Type Remote Code Execution Vulnerability
17468| [801596] Microsoft Excel 2007 Office Drawing Layer Remote Code Execution Vulnerability
17469| [801595] Microsoft Office Excel Axis and Art Object Parsing Remote Code Execution Vulnerabilities
17470| [801594] Microsoft PowerPoint 2007 OfficeArt Atom Remote Code Execution Vulnerability
17471| [801580] Microsoft Windows Fax Cover Page Editor BOF Vulnerabilities
17472| [801527] Microsoft Windows 32-bit Platforms Unspecified vulnerabilities
17473| [801491] Microsoft 'hxvz.dll' ActiveX Control Memory Corruption Vulnerability (948881)
17474| [801489] Microsoft Office Graphics Filters Remote Code Execution Vulnerabilities (968095)
17475| [801488] Microsoft Internet Explorer Data Stream Handling Remote Code Execution Vulnerability (947864)
17476| [801487] Microsoft Windows Kernel Usermode Callback Local Privilege Elevation Vulnerability (941693)
17477| [801486] Microsoft Windows Speech Components Voice Recognition Command Execution Vulnerability (950760)
17478| [801485] Microsoft Pragmatic General Multicast (PGM) Denial of Service Vulnerability (950762)
17479| [801484] Microsoft Windows IPsec Policy Processing Information Disclosure Vulnerability (953733)
17480| [801483] Microsoft Windows Search Remote Code Execution Vulnerability (959349)
17481| [801482] Microsoft Windows ASP.NET Denial of Service Vulnerability(970957)
17482| [801481] Microsoft Wireless LAN AutoConfig Service Remote Code Execution Vulnerability (970710)
17483| [801480] Microsoft Web Services on Devices API Remote Code Execution Vulnerability (973565)
17484| [801479] Microsoft Windows TCP/IP Could Allow Remote Code Execution (974145)
17485| [801457] Microsoft Windows Address Book Insecure Library Loading Vulnerability
17486| [801456] Microsoft Windows Progman Group Converter Insecure Library Loading Vulnerability
17487| [801349] Microsoft Internet Explorer 'IFRAME' Denial Of Service Vulnerability (June-10)
17488| [801348] Microsoft Internet Explorer 'IFRAME' Denial Of Service Vulnerability -june 10
17489| [801345] Microsoft .NET 'ASP.NET' Cross-Site Scripting vulnerability
17490| [801344] Microsoft .NET '__VIEWSTATE' Cross-Site Scripting vulnerability
17491| [801342] Microsoft ASP.NET Cross-Site Scripting vulnerability
17492| [801333] Microsoft Windows Kernel 'win32k.sys' Multiple DOS Vulnerabilities
17493| [801330] Microsoft Internet Explorer Cross Site Data Leakage Vulnerability
17494| [801109] Microsoft IE CA SSL Certificate Security Bypass Vulnerability - Oct09
17495| [801090] Microsoft Windows Indeo Codec Multiple Vulnerabilities
17496| [800968] Microsoft SharePoint Team Services Information Disclosure Vulnerability
17497| [800910] Microsoft Internet Explorer Buffer Overflow Vulnerability - Jul09
17498| [800902] Microsoft Internet Explorer XSS Vulnerability - July09
17499| [800872] Microsoft Internet Explorer 'li' Element DoS Vulnerability - Sep09
17500| [800863] Microsoft Internet Explorer XML Document DoS Vulnerability - Aug09
17501| [800862] Microsoft Windows Kernel win32k.sys Privilege Escalation Vulnerability
17502| [800861] Microsoft Internet Explorer 'findText()' Unicode Parsing DoS Vulnerability
17503| [800845] Microsoft Office Web Components ActiveX Control Code Execution Vulnerability
17504| [800829] Microsoft Video ActiveX Control 'msvidctl.dll' BOF Vulnerability
17505| [800742] Microsoft Internet Explorer Unspecified vulnerability
17506| [800700] Microsoft GDIPlus PNG Infinite Loop Vulnerability
17507| [800687] Microsoft Windows Server 2003 OpenType Font Engine DoS Vulnerability
17508| [800669] Microsoft Internet Explorer Denial Of Service Vulnerability - July09
17509| [800577] Microsoft Windows Server 2003 win32k.sys DoS Vulnerability
17510| [800505] Microsoft HTML Help Workshop buffer overflow vulnerability
17511| [800504] Microsoft Windows XP SP3 denial of service vulnerability
17512| [800481] Microsoft SharePoint Cross Site Scripting Vulnerability
17513| [800480] Microsoft Windows Media Player '.mpg' Buffer Overflow Vulnerability
17514| [800466] Microsoft Windows TLS/SSL Spoofing Vulnerability (977377)
17515| [800461] Microsoft Internet Explorer Information Disclosure Vulnerability (980088)
17516| [800442] Microsoft Windows GP Trap Handler Privilege Escalation Vulnerability
17517| [800429] Microsoft Internet Explorer Remote Code Execution Vulnerability (979352)
17518| [800382] Microsoft PowerPoint File Parsing Remote Code Execution Vulnerability (967340)
17519| [800347] Microsoft Internet Explorer Clickjacking Vulnerability
17520| [800343] Microsoft Word 2007 Sensitive Information Disclosure Vulnerability
17521| [800337] Microsoft Internet Explorer NULL Pointer DoS Vulnerability
17522| [800332] Microsoft Windows Live Messenger Information Disclosure Vulnerability
17523| [800331] Microsoft Windows Live Messenger Client Version Detection
17524| [800328] Integer Overflow vulnerability in Microsoft Windows Media Player
17525| [800310] Microsoft Windows Media Services nskey.dll ActiveX BOF Vulnerability
17526| [800267] Microsoft GDIPlus Library File Integer Overflow Vulnerability
17527| [800218] Microsoft Money 'prtstb06.dll' Denial of Service vulnerability
17528| [800217] Microsoft Money Version Detection
17529| [800209] Microsoft Internet Explorer Version Detection (Win)
17530| [800208] Microsoft Internet Explorer Anti-XSS Filter Vulnerabilities
17531| [800083] Microsoft Outlook Express Malformed MIME Message DoS Vulnerability
17532| [800082] Microsoft SQL Server sp_replwritetovarbin() BOF Vulnerability
17533| [800023] Microsoft Windows Image Color Management System Code Execution Vulnerability (952954)
17534| [103254] Microsoft SharePoint Server 2007 '_layouts/help.aspx' Cross Site Scripting Vulnerability
17535| [102059] Microsoft Windows Vector Markup Language Buffer Overflow (938127)
17536| [102055] Microsoft Windows GDI Multiple Vulnerabilities (925902)
17537| [102053] Microsoft Windows Vector Markup Language Vulnerabilities (929969)
17538| [102015] Microsoft RPC Interface Buffer Overrun (KB824146)
17539| [101100] Vulnerabilities in Microsoft ATL Could Allow Remote Code Execution (973908)
17540| [101017] Microsoft MS03-018 security check
17541| [101016] Microsoft MS03-022 security check
17542| [101015] Microsoft MS03-034 security check
17543| [101014] Microsoft MS00-078 security check
17544| [101012] Microsoft MS03-051 security check
17545| [101010] Microsoft Security Bulletin MS05-004
17546| [101009] Microsoft Security Bulletin MS06-033
17547| [101007] Microsoft dotNET version grabber
17548| [101006] Microsoft Security Bulletin MS06-056
17549| [101005] Microsoft Security Bulletin MS07-040
17550| [101004] Microsoft MS04-017 security check
17551| [101003] Microsoft MS00-058 security check
17552| [101000] Microsoft MS00-060 security check
17553| [100950] Microsoft DNS server internal hostname disclosure detection
17554| [100624] Microsoft Windows SMTP Server DNS spoofing vulnerability
17555| [100607] Microsoft SMTP Service and Exchange Routing Engine Buffer Overflow Vulnerability
17556| [100596] Microsoft Windows SMTP Server MX Record Denial of Service Vulnerability
17557| [100283] Microsoft Windows SMB2 '_Smb2ValidateProviderCallback()' Remote Code Execution Vulnerability
17558| [100062] Microsoft Remote Desktop Protocol Detection
17559| [90024] Windows Vulnerability in Microsoft Jet Database Engine
17560| [80007] Microsoft MS00-06 security check
17561| [13752] Denial of Service (DoS) in Microsoft SMS Client
17562| [11992] Vulnerability in Microsoft ISA Server 2000 H.323 Filter(816458)
17563| [11874] IIS Service Pack - 404
17564| [11808] Microsoft RPC Interface Buffer Overrun (823980)
17565| [11433] Microsoft ISA Server DNS - Denial Of Service (MS03-009)
17566| [11217] Microsoft's SQL Version Query
17567| [11177] Flaw in Microsoft VM Could Allow Code Execution (810030)
17568| [11146] Microsoft RDP flaws could allow sniffing and DOS(Q324380)
17569| [11142] IIS XSS via IDC error
17570| [11067] Microsoft's SQL Hello Overflow
17571| [11003] IIS Possible Compromise
17572| [10993] IIS ASP.NET Application Trace Enabled
17573| [10991] IIS Global.asa Retrieval
17574| [10936] IIS XSS via 404 error
17575| [10862] Microsoft's SQL Server Brute Force
17576| [10755] Microsoft Exchange Public Folders Information Leak
17577| [10732] IIS 5.0 WebDav Memory Leakage
17578| [10699] IIS FrontPage DoS II
17579| [10695] IIS .IDA ISAPI filter applied
17580| [10674] Microsoft's SQL UDP Info Query
17581| [10673] Microsoft's SQL Blank Password
17582| [10671] IIS Remote Command Execution
17583| [10667] IIS 5.0 PROPFIND Vulnerability
17584| [10661] IIS 5 .printer ISAPI filter applied
17585| [10657] NT IIS 5.0 Malformed HTTP Printer Request Header Buffer Overflow Vulnerability
17586| [10585] IIS FrontPage DoS
17587| [10576] Check for dangerous IIS default files
17588| [10575] Check for IIS .cnf file leakage
17589| [10573] IIS 5.0 Sample App reveals physical path of web root
17590| [10572] IIS 5.0 Sample App vulnerable to cross-site scripting attack
17591| [10537] IIS directory traversal
17592| [10492] IIS IDA/IDQ Path Disclosure
17593| [10491] ASP/ASA source using Microsoft Translate f: bug
17594| [10144] Microsoft SQL TCP/IP listener is running
17595|
17596| SecurityTracker - https://www.securitytracker.com:
17597| [1024070] Microsoft Internet Explorer 8 Developer Tools ActiveX Control Memory Corruption Error Lets Remote Users Execute Arbitrary Code
17598| [1027751] Microsoft Internet Information Server (IIS) FTP Server Lets Remote Users Obtain Files and Local Users Obtain Passwords
17599| [1027223] Microsoft IIS Web Server Discloses Potentially Sensitive Information to Remote Users
17600| [1024921] Microsoft IIS FTP Server Lets Remote Users Deny Service
17601| [1024496] Microsoft Internet Information Server (IIS) Web Server Stack Overflow in Reading POST Data Lets Remote Users Deny Service
17602| [1023387] Microsoft Internet Information Services (IIS) Filename Extension Parsing Configuration Error May Let Users Bypass Security Controls
17603| [1022792] Microsoft Internet Information Server (IIS) FTP Server Buffer Overflows Let Remote Authenticated Users Execute Arbitrary Code and Deny Service
17604| [1016466] Microsoft Internet Information Server (IIS) Buffer Overflow in Processing ASP Pages Lets Remote Authenticated Users Execute Arbitrary Code
17605| [1015376] Microsoft IIS Lets Remote Users Deny Service or Execute Arbitrary Code With Malformed HTTP GET Requests
17606| [1015049] Microsoft Internet Explorer Drag-and-Drop Timing May Let Remote Users Install Arbitrary Files
17607| [1014777] Microsoft IIS ASP Error Page May Disclose System Information in Certain Cases
17608| [1011633] Microsoft IIS WebDAV XML Message Handler Error Lets Remote Users Deny Service
17609| [1010692] Microsoft IIS 4.0 Buffer Overflow in Redirect Function Lets Remote Users Execute Arbitrary Code
17610| [1010610] Microsoft IIS Web Server May Disclose Private IP Addresses in Certain Cases
17611| [1010079] Microsoft IIS ASP Script Cookie Processing Flaw May Disclose Application Information to Remote Users
17612| [1008563] Microsoft IIS Fails to Log HTTP TRACK Requests
17613| [1007262] Microsoft IIS 6.0 Vulnerabilities Permit Cross-Site Scripting and Password Changing Attacks Against Administrators
17614| [1007059] Microsoft Windows Media Services (nsiislog.dll) Extension to Internet Information Server (IIS) Has Another Buffer Overflow That Lets Remote Execute Arbitrary Code
17615| [1006867] Microsoft IIS Buffer Overflow Lets Remote Users With Upload Privileges Execute Code - Remote Users Can Also Crash the Service
17616| [1006866] Microsoft Windows Media Services (nsiislog.dll) Extension to Internet Information Server (IIS) Lets Remote Execute Arbitrary Code
17617| [1006704] Microsoft IIS Authentication Manager Discloses Validity of User Names to Remote Users
17618| [1006305] Microsoft IIS Web Server WebDAV Buffer Overflow Lets Remote Users Execute Arbitrary Code
17619| [1005505] Microsoft Internet Information Server (IIS) Script Access Control Bug May Let Remote Authenticated Users Upload Unauthorized Executable Files
17620| [1005504] Microsoft Internet Information Server (IIS) WebDAV Memory Allocation Flaw Lets Remote Users Crash the Server
17621| [1005503] Microsoft Internet Information Server (IIS) Administrative Pages Allow Cross-Site Scripting Attacks
17622| [1005502] Microsoft Internet Information Server (IIS) Out-of-Process Access Control Bug Lets Certain Authenticated Users Gain Full Control of the Server
17623| [1005083] Microsoft Internet Information Server (IIS) Web Server Fails to Properly Validate Client-side Certificates, Allowing Remote Users to Impersonate Other Users or Certificate Issuers
17624| [1004757] Microsoft IIS SMTP Service Encapsulation Bug Lets Remote Users Relay Mail and Send SPAM Via the Service
17625| [1004646] ColdFusion MX Buffer Overflow When Used With Microsoft Internet Information Server (IIS) Lets Remote Users Crash the IIS Web Server or Execute Arbitrary Code
17626| [1004526] Microsoft Internet Information Server (IIS) Heap Overflow in HTR ISAPI Extension While Processing Chunked Encoded Data Lets Remote Users Execute Arbitrary Code
17627| [1004044] Cisco CallManager Affected by Microsoft Internet Information Server (IIS) Bugs
17628| [1004032] Microsoft Internet Information Server (IIS) FTP STAT Command Bug Lets Remote Users Crash Both the FTP and the Web Services
17629| [1004031] Microsoft Internet Information Server (IIS) URL Length Bug Lets Remote Users Crash the Web Service
17630| [1004011] Microsoft Internet Information Server (IIS) Buffer Overflow in ASP Server-Side Include Function May Let Remote Users Execute Arbitrary Code on the Web Server
17631| [1004006] Microsoft Internet Information Server (IIS) Off-By-One Heap Overflow in .HTR Processing May Let Remote Users Execute Arbitrary Code on the Server
17632| [1003224] Microsoft Internet Information Server (IIS) Version 4 Lets Local Users Modify the Log File Undetected
17633| [1002778] Microsoft Internet Information Server (IIS) Lets Remote Users Create Bogus Web Log Entries
17634| [1002733] Microsoft IIS 4.0 Configuration Error May Allow Remote Users to Obtain Physical Directory Path Information
17635| [1002651] Microsoft Internet Information Server (IIS) May Disclose PHP Scripting Source Code
17636| [1002212] Microsoft IIS Web Server Contains Multiple Vulnerabilities That Allow Local Users to Gain System Privileges and Allow Remote Users to Cause the Web Server to Crash
17637| [1002161] Microsoft Internet Information Server (IIS) Web Server Discloses Internal IP Addresses or NetBIOS Host Names to Remote Users
17638| [1001818] Microsoft Internet Information Server (IIS) Web Server Discloses ASP Source Code When Installed on FAT-based Filesystem
17639| [1001576] eEye Digital Security's SecureIIS Application Firewall for Microsoft Web Servers Fails to Filter Certain Web URL Characters, Allowing Remote Users to Bypass the SecureIIS Firewall
17640| [1001565] Microsoft IIS Web Server on Windows 2000 Allows Remote Users to Cause the Server to Consume All Available Memory Due to Memory Leak in WebDAV Lock Method
17641| [1001530] Microsoft IIS Web Server Allows Remote Users to Execute Commands on the Server Due to CGI Decoding Error
17642| [1001483] Microsoft IIS Web Server Lets Remote Users Restart the Web Server with Another Specially Crafted PROPFIND XML Command
17643| [1001464] Microsoft Internet Information Server IIS 5.0 for Windows 2000 Lets Remote Users Execute Arbitrary Code on the Server and Gain Control of the Server
17644| [1001402] Microsoft IIS Web Server Can Be Effectively Shutdown By Certain Internal-Network Attacks When The Underlying OS Supports User Account Lockouts
17645| [1001116] Microsoft Personal Web Server Contains An Old Internet Information Server (IIS) Vulnerability Allowing Unauthorized Directory Listings and Possible Code Execution For Remote Users
17646| [1001050] Microsoft IIS 5.0 Web Server Can Be Restarted Remotely By Any User
17647|
17648| OSVDB - http://www.osvdb.org:
17649| [91269] Microsoft Windows 8 TrueType Font (TTF) Handling Unspecified DoS
17650| [65218] Microsoft IE 8 Developer Tools ActiveX Remote Code Execution
17651| [87555] Adobe ColdFusion for Microsoft IIS Unspecified DoS
17652| [87262] Microsoft IIS FTP Command Injection Information Disclosure
17653| [87261] Microsoft IIS Log File Permission Weakness Local Password Disclosure
17654| [86899] Microsoft IIS 302 Redirect Message Internal IP Address Remote Disclosure
17655| [83771] Microsoft IIS Tilde Character Request Parsing File / Folder Name Information Disclosure
17656| [83454] Microsoft IIS ODBC Tool ctguestb.idc Unauthenticated Remote DSN Initialization
17657| [83386] Microsoft IIS Non-existent IDC File Request Web Root Path Disclosure
17658| [82848] Microsoft IIS $INDEX_ALLOCATION Data Stream Request Authentication Bypass
17659| [76237] Microsoft Forefront Unified Access Gateway IIS NULL Session Cookie Parsing Remote DoS
17660| [71856] Microsoft IIS Status Header Handling Remote Overflow
17661| [70167] Microsoft IIS FTP Server Telnet IAC Character Handling Overflow
17662| [67980] Microsoft IIS Unspecified Remote Directory Authentication Bypass
17663| [67979] Microsoft IIS FastCGI Request Header Handling Remote Overflow
17664| [67978] Microsoft IIS Repeated Parameter Request Unspecified Remote DoS
17665| [66160] Microsoft IIS Basic Authentication NTFS Stream Name Permissions Bypass
17666| [65216] Microsoft IIS Extended Protection for Authentication Memory Corruption
17667| [62229] Microsoft IIS Crafted DNS Response Inverse Lookup Log Corruption XSS
17668| [61432] Microsoft IIS Colon Safe Extension NTFS ADS Filename Syntax Arbitrary Remote File Creation
17669| [61294] Microsoft IIS ASP Crafted semicolon Extension Security Bypass
17670| [61249] Microsoft IIS ctss.idc table Parameter SQL Injection
17671| [59892] Microsoft IIS Malformed Host Header Remote DoS
17672| [59621] Microsoft IIS CodeBrws.asp Off-By-One File Check Bypass Source Disclosure
17673| [59561] Microsoft IIS CodeBrws.asp Encoded Traversal Arbitrary File Source Disclosure
17674| [59360] Microsoft IIS ASP Page Visual Basic Script Malformed Regex Parsing DoS
17675| [57753] Microsoft IIS FTP Server Crafted Recursive Listing Remote DoS
17676| [57589] Microsoft IIS FTP Server NLST Command Remote Overflow
17677| [56474] Microsoft IIS WebDAV Extension URL Decode Crafted HTTP Request Authentication Bypass
17678| [55269] Microsoft IIS Traversal GET Request Remote DoS
17679| [54555] Microsoft IIS WebDAV Unicode URI Request Authentication Bypass
17680| [52924] Microsoft IIS WebDAV PROPFIND Method Forced Directory Listing
17681| [52680] Microsoft IIS httpext.dll WebDav LOCK Method Nonexistent File Request Parsing Memory Exhaustion Remote DoS
17682| [52238] Microsoft IIS IDC Extension XSS
17683| [49899] Microsoft IIS iissext.dll Unspecified ActiveX SetPassword Method Remote Password Manipulation
17684| [49730] Microsoft IIS ActiveX (adsiis.dll) GetObject Method Remote DoS
17685| [49059] Microsoft IIS IPP Service Unspecified Remote Overflow
17686| [45583] Microsoft IIS w/ Visual Interdev Unspecified Authentication Bypass
17687| [43451] Microsoft IIS HTTP Request Smuggling
17688| [41456] Microsoft IIS File Change Handling Local Privilege Escalation
17689| [41445] Microsoft IIS ASP Web Page Input Unspecified Arbitrary Code Execution
17690| [41091] Microsoft IIS webhits.dll Hit-Highlighting Authentication Bypass
17691| [41063] Microsoft IIS ODBC Tool newdsn.exe Remote DSN Creation
17692| [41057] Microsoft IIS w/ .NET MS-DOS Device Request Blacklist Bypass
17693| [35950] Microsoft IIS IUSR_Machine Account Arbitrary Non-EXE Command Execution
17694| [33457] Microsoft IIS Crafted TCP Connection Range Header DoS
17695| [28260] Microsoft IIS FrontPage Server Extensions (FPSE) shtml.exe Path Disclosure
17696| [27152] Microsoft Windows IIS ASP Page Processing Overflow
17697| [27087] Microsoft IIS SMTP Encapsulated SMTP Address Open Relay
17698| [23590] Microsoft IIS Traversal Arbitrary FPSE File Access
17699| [21805] Microsoft IIS Crafted URL Remote DoS
17700| [21537] Microsoft IIS Log File Permission Weakness Remote Modification
17701| [18926] Microsoft IIS SERVER_NAME Variable Spoofing Filter Bypass
17702| [17124] Microsoft IIS Malformed WebDAV Request DoS
17703| [17123] Microsoft IIS Multiple Unspecified Admin Pages XSS
17704| [17122] Microsoft IIS Permission Weakness .COM File Upload
17705| [15749] Microsoft IIS / Site Server code.asp Arbitrary File Access
17706| [15342] Microsoft IIS Persistent FTP Banner Information Disclosure
17707| [14229] Microsoft IIS asp.dll Scripting.FileSystemObject Malformed Program DoS
17708| [13985] Microsoft IIS Malformed HTTP Request Log Entry Spoofing
17709| [13760] Microsoft IIS Malformed URL Request DoS
17710| [13759] Microsoft IIS ISAPI .ASP Parser Script Tag LANGUAGE Argument Overflow
17711| [13634] Microsoft IIS Inetinfo.exe Malformed Long Mail File Name DoS
17712| [13558] Microsoft IIS SSL Request Resource Exhaustion DoS
17713| [13507] Microsoft IIS showfile.asp FileSystemObject Arbitrary File Access
17714| [13479] Microsoft IIS for Far East Parsed Page Source Disclosure
17715| [13473] Microsoft IIS on FAT Partition Local ASP Source Disclosure
17716| [13439] Microsoft IIS HTTP Request Malformed Content-Length Parsing Remote DoS
17717| [13433] Microsoft IIS WebDAV MKCOL Method Location Server Header Internal IP Disclosure
17718| [13432] Microsoft IIS WebDAV WRITE Location Server Header Internal IP Disclosure
17719| [13431] Microsoft IIS WebDAV Malformed PROPFIND Request Internal IP Disclosure
17720| [13430] Microsoft IIS aexp4.htr Password Policy Bypass
17721| [13429] Microsoft IIS aexp3.htr Password Policy Bypass
17722| [13428] Microsoft IIS aexp2b.htr Password Policy Bypass
17723| [13427] Microsoft IIS aexp2.htr Password Policy Bypass
17724| [13426] Microsoft IIS NTLM Authentication Request Parsing Remote Information Disclosure
17725| [13385] Microsoft IIS WebDAV Long PROPFIND/SEARCH Request DoS
17726| [11455] Microsoft IIS / PWS DOS Filename Request Access Bypass
17727| [11452] Microsoft IIS Double Byte Code Arbitrary Source Disclosure
17728| [11277] Microsoft IIS SSL ISAPI Filter Cleartext Information Disclosure
17729| [11257] Microsoft IIS Malformed GET Request DoS
17730| [11157] Microsoft IIS FTP Service PASV Connection Saturation DoS
17731| [11101] Microsoft IIS Multiple Slash ASP Page Request DoS
17732| [9315] Microsoft IIS getdrvs.exe ODBC Sample Information Disclosure
17733| [9314] Microsoft IIS mkilog.exe ODBC Sample Arbitrary Command Execution
17734| [9200] Microsoft IIS Unspecified XSS Variant
17735| [9199] Microsoft IIS shtml.dll XSS
17736| [8098] Microsoft IIS Virtual Directory ASP Source Disclosure
17737| [7807] Microsoft IIS ISAPI Virtual Directory UNC Mapping ASP Source Disclosure
17738| [7737] Microsoft IIS ASP Redirection Function XSS
17739| [7265] Microsoft IIS .ASP Session ID Disclosure and Hijacking
17740| [5851] Microsoft IIS Single Dot Source Code Disclosure
17741| [5736] Microsoft IIS Relative Path System Privilege Escalation
17742| [5693] Microsoft MS00-060 Patch IIS Malformed Request DoS
17743| [5633] Microsoft IIS Invalid WebDAV Request DoS
17744| [5606] Microsoft IIS WebDAV PROPFIND Request DoS
17745| [5584] Microsoft IIS URL Redirection Malformed Length DoS
17746| [5566] Microsoft IIS Form_VBScript.asp XSS
17747| [5316] Microsoft IIS ISAPI HTR Chunked Encoding Overflow
17748| [4864] Microsoft IIS TRACK Logging Failure
17749| [4863] Microsoft IIS Active Server Page Header DoS
17750| [4791] Microsoft IIS Response Object DoS
17751| [4655] Microsoft IIS ssinc.dll Long Filename Overflow
17752| [4535] Microsoft Media Services ISAPI nsiislog.dll POST Overflow
17753| [3512] Microsoft IIS ODBC Tool getdrvrs.exe Remote DSN Creation
17754| [3500] Microsoft IIS fpcount.exe Remote Overflow
17755| [3341] Microsoft IIS Redirect Response XSS
17756| [3339] Microsoft IIS HTTP Error Page XSS
17757| [3338] Microsoft IIS Help File XSS
17758| [3328] Microsoft IIS FTP Status Request DoS
17759| [3326] Microsoft IIS w3svc.dll ISAPI Filter URL Handling Remote DoS
17760| [3325] Microsoft IIS HTR ISAPI Overflow
17761| [3323] Microsoft IIS ISAPI .printer Extension Host Header Overflow
17762| [3320] Microsoft IIS ASP Server-Side Include Buffer Overflow
17763| [3316] Microsoft IIS HTTP Header Field Delimiter Overflow
17764| [3301] Microsoft IIS ASP Chunked Encoding Variant Heap Overflow
17765| [3284] Microsoft IIS Winmsdp.exe Arbitrary File Retrieval
17766| [3231] Microsoft IIS Log Bypass
17767| [2106] Microsoft Media Services ISAPI nsiislog.dll Overflow
17768| [1931] Microsoft IIS MIME Content-Type Header DoS
17769| [1930] Microsoft IIS SSI ssinc.dll Filename Handling Overflow
17770| [1826] Microsoft IIS Domain Guest Account Disclosure
17771| [1824] Microsoft IIS FTP DoS
17772| [1804] Microsoft IIS Long Request Parsing Remote DoS
17773| [1770] Microsoft IIS WebDAV Malformed PROPFIND Request Remote DoS
17774| [1750] Microsoft IIS File Fragment Disclosure
17775| [1543] Microsoft NT/IIS Invalid URL Request DoS
17776| [1504] Microsoft IIS File Permission Canonicalization Bypass
17777| [1465] Microsoft IIS .htr Missing Variable DoS
17778| [1325] Microsoft IIS Malformed Filename Request File Fragment Disclosure
17779| [1322] Microsoft IIS Malformed .htr Request DoS
17780| [1281] Microsoft IIS Escaped Character Saturation Remote DoS
17781| [1261] Microsoft IIS Chunked Transfer Encoding Remote Overflow DoS
17782| [1210] Microsoft IIS WebHits.dll ISAPI Filter Traversal Arbitrary File Access
17783| [1170] Microsoft IIS Escape Character URL Access Bypass
17784| [1083] Microsoft IIS FTP NO ACCESS Read/Delete File
17785| [1082] Microsoft IIS Domain Resolution Access Bypass
17786| [1041] Microsoft IIS Malformed HTTP Request Header DoS
17787| [1020] Microsoft IIS ISAPI GetExtensionVersion() Privilege Escalation
17788| [930] Microsoft IIS Shared ASP Cache Information Disclosure
17789| [929] Microsoft IIS FTP Server NLST Command Overflow
17790| [928] Microsoft IIS Long Request Log Evasion
17791| [815] Microsoft IIS ASP.NET trace.axd Application Tracing Information Disclosure
17792| [814] Microsoft IIS global.asa Remote Information Disclosure
17793| [782] Microsoft IIS / Site Server codebrws.asp Arbitrary File Access
17794| [771] Microsoft IIS Hosting Process (dllhost.exe) Out of Process Application Unspecified Privilege Escalation
17795| [768] Microsoft IIS ASP Chunked Encoding Heap Overflow
17796| [636] Microsoft IIS sqlqhit.asp Sample Script CiScope Parameter Information Disclosure
17797| [630] Microsoft IIS Multiple Malformed Header Field Internal IP Address Disclosure
17798| [568] Microsoft IIS idq.dll IDA/IDQ ISAPI Remote Overflow
17799| [564] Microsoft IIS ISM.dll Fragmented Source Disclosure
17800| [556] Microsoft IIS/PWS Encoded Filename Arbitrary Command Execution
17801| [525] Microsoft IIS Webserver Invalid Filename Request Arbitrary Command Execution
17802| [482] Microsoft IIS FrontPage Server Extensions (FPSE) Malformed Form DoS
17803| [475] Microsoft IIS bdir.htr Arbitrary Directory Listing
17804| [474] Microsoft IIS / Site Server viewcode.asp Arbitrary File Access
17805| [473] Microsoft IIS Multiple .cnf File Information Disclosure
17806| [471] Microsoft IIS ServerVariables_Jscript.asp Path Disclosure
17807| [470] Microsoft IIS Form_JScript.asp XSS
17808| [463] Microsoft IIS Phone Book Service /pbserver/pbserver.dll Remote Overflow
17809| [436] Microsoft IIS Unicode Remote Command Execution
17810| [425] Microsoft IIS WebDAV SEARCH Method Arbitrary Directory Forced Listing
17811| [391] Microsoft IIS IDA/IDQ Document Root Path Disclosure
17812| [390] Microsoft IIS Translate f: Request ASP Source Disclosure
17813| [308] Microsoft IIS Malformed File Extension URL DoS
17814| [285] Microsoft IIS repost.asp File Upload
17815| [284] Microsoft IIS IISADMPWD Virtual Directory Information Enumeration
17816| [283] Microsoft IIS /iissamples Multiple Sample Scripts Installed
17817| [277] Microsoft IIS / PWS %2e Request ASP Source Disclosure
17818| [276] Microsoft IIS ASP::$DATA Stream Request ASP Source Disclosure
17819| [275] Microsoft IIS newdsn.exe Remote Arbitrary File Creation
17820| [274] Microsoft IIS ctss.idc ODBC Sample Arbitrary Command Execution
17821| [273] Microsoft IIS Upgrade ism.dll Local Privilege Escalation
17822| [272] Microsoft IIS MDAC RDS Arbitrary Remote Command Execution
17823| [271] Microsoft IIS WebHits null.htw .asp Source Disclosure
17824| [98] Microsoft IIS perl.exe HTTP Path Disclosure
17825| [97] Microsoft IIS ISM.DLL HTR Request Overflow
17826| [96] Microsoft IIS idq.dll Traversal Arbitrary File Access
17827| [7] Microsoft IIS / Site Server showcode.asp source Parameter Traversal Arbitrary File Access
17828| [4] Microsoft IIS ExAir advsearch.asp Direct Request Remote DoS
17829| [3] Microsoft IIS ExAir query.asp Direct Request Remote DoS
17830| [2] Microsoft IIS ExAir search.asp Direct Request DoS
17831|_
17832445/tcp closed microsoft-ds conn-refused
178333389/tcp open ms-wbt-server syn-ack Microsoft Terminal Service
17834| vulscan: VulDB - https://vuldb.com:
17835| [133212] Microsoft Windows up to Server 2019 Terminal Services Memory information disclosure
17836| [31855] Microsoft Internet Explorer 6.0 SP1 Terminal Service tsuserex.dll memory corruption
17837| [134750] Microsoft ASP.NET Core 2.1/2.2 denial of service
17838| [134749] Microsoft .NET Framework/.NET Core denial of service
17839| [134748] Microsoft .NET Framework/.NET Core denial of service
17840| [134729] Microsoft Windows up to Server 2019 Storage Service privilege escalation
17841| [134705] Microsoft .NET Framework/.NET Core Regex denial of service
17842| [134704] Microsoft SQL Server 2017 Analysis Services information disclosure
17843| [134681] Microsoft Windows Remote Desktop Service memory corruption
17844| [133222] Microsoft Windows up to Server 2019 Remote Registry Service memory corruption
17845| [133214] Microsoft Windows up to Server 2019 AppX Deployment Service privilege escalation
17846| [133197] Microsoft ASP.NET Core 2.2 Request denial of service
17847| [132088] PuTTY up to 0.70 Terminal denial of service
17848| [131657] Microsoft Windows up to Server 2019 denial of service
17849| [131650] Microsoft Windows 10 1803/10 1809/Server 2019/Server 1803 Hyper-V denial of service
17850| [131648] Microsoft Windows up to Server 2019 Hyper-V denial of service
17851| [131644] Microsoft Windows up to Server 2019 Hyper-V denial of service
17852| [131629] Microsoft Windows up to Server 2019 Deployment Services TFTP Server memory corruption
17853| [131210] Jamf Self Service 10.9.0 Terminal privilege escalation
17854| [130817] Microsoft Windows up to Server 2019 Storage Service privilege escalation
17855| [128751] Microsoft Windows up to Server 2019 Data Sharing Service privilege escalation
17856| [128747] Microsoft ASP.NET Core 2.1 Web Request denial of service
17857| [128735] Microsoft ASP.NET Core 2.1/2.2 Web Request denial of service
17858| [128727] Microsoft Windows up to Server 2019 Data Sharing Service privilege escalation
17859| [128726] Microsoft Windows up to Server 2019 Data Sharing Service privilege escalation
17860| [128725] Microsoft Windows up to Server 2019 Data Sharing Service privilege escalation
17861| [127881] Microsoft Windows 10 1809/Server 2019 Object denial of service
17862| [127821] Microsoft Windows up to Server 2019 Connected User Experiences and Telemetry Service denial of service
17863| [127813] Microsoft .NET Framework up to 4.7.2 denial of service
17864| [126793] Microsoft Azure App Service on Azure Stack cross site scripting
17865| [126754] Microsoft Skype for Business/Lync Server 2013 SP1/2016 Emoji denial of service
17866| [126730] Microsoft Windows up to Server 2019 Active Directory Federation Services cross site scripting
17867| [126711] Microsoft Windows up to Server 2019 Deployment Services TFTP Server memory corruption
17868| [124217] Microsoft Windows Server 2012/Server 2016 Active Directory Federation Services /adfs/ls Server-Side Request Forgery
17869| [123992] Microsoft Data.OData Web Request denial of service
17870| [123868] Microsoft Windows up to Server 2016 Hyper-V denial of service
17871| [123867] Microsoft Windows 10 1803/Server 1803 Hyper-V denial of service
17872| [123866] Microsoft Windows 10 1803/Server 1803 Hyper-V denial of service
17873| [123856] Microsoft ASP.NET Core/.NET Core System.IO.Pipelines denial of service
17874| [123849] Microsoft Windows up to Server 2016 SMB denial of service
17875| [121120] Microsoft Active Directory Federation Services Web Customizations cross site scripting
17876| [121107] Microsoft Windows up to Server 2016 DNSAPI DNSAPI.dll denial of service
17877| [121092] Microsoft Windows up to Server 2016 FTP Server denial of service
17878| [121086] Microsoft PowerShell Editor Services privilege escalation
17879| [119470] Microsoft Windows up to Server 2016 HTTP HTTP.sys denial of service
17880| [119466] Microsoft Windows 10 1709/Server 1709 Hyper-V denial of service
17881| [119455] Microsoft Windows up to Server 2016 denial of service
17882| [119453] Microsoft Windows 10 1709/10 1803/Server 1709/Server 1803 WebDAV denial of service
17883| [119448] Microsoft Windows up to Server 2016 Code Integrity Module denial of service
17884| [117479] Microsoft .NET Framework up to 4.7.1 XML Data denial of service
17885| [117331] Microsoft Windows Host Compute Host Compute Service Shim Code Execution memory corruption
17886| [116039] Microsoft Windows up to Server 2016 Remote Desktop Protocol denial of service
17887| [116030] Microsoft Windows up to Server 2016 SNMP Service denial of service
17888| [116024] Microsoft Windows up to Server 2016 HTTP.sys denial of service
17889| [114535] Microsoft Windows up to Server 2016 Hyper-V denial of service
17890| [114524] Microsoft ASP.NET Core 2.0 denial of service
17891| [113264] Microsoft Windows 8.1/RT 8.1/Server 2012 R2 SMBv2/SMBv3 denial of service
17892| [113262] Microsoft Windows 10/Server 1709 Storage Services memory corruption
17893| [113124] LibreOffice up to 6.0.1 COM.MICROSOFT.WEBSERVICE information disclosure
17894| [111557] Microsoft .NET Framework up to 5.7 XML denial of service
17895| [111358] Microsoft Windows up to Server 2016 IPsec denial of service
17896| [109360] Microsoft Windows up to Server 2016 Windows Search denial of service
17897| [109359] Microsoft ASP.NET 1.0/1.1/2.0 denial of service
17898| [109358] Microsoft .NET Framework 1.0/1.1/2.0 denial of service
17899| [107759] Microsoft Windows up to Server 2016 SMB denial of service
17900| [107724] Microsoft Windows up to Server 2016 Text Services Framework memory corruption
17901| [106492] Microsoft Windows Server 2012/Server 2012 R2/Server 2016 DHCP Service memory corruption
17902| [106454] Microsoft Windows up to Server 2016 Windows NetBT Session Services race condition memory corruption
17903| [105049] Microsoft Windows 10 1703 Remote Desktop Protocol denial of service
17904| [105013] Microsoft Windows 10 1607/10 1703/Server 2016 Hyper-V denial of service
17905| [105008] Microsoft SQL Server 2012/2014/2016 Analysis Services information disclosure
17906| [104989] Microsoft Windows up to Server 2016 NetBIOS denial of service
17907| [104982] Microsoft Windows up to XP SMBv1 Smbloris denial of service
17908| [103444] Microsoft Windows up to Server 2016 Explorer denial of service
17909| [103443] Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7 denial of service
17910| [101820] Microsoft Windows Vista/7/8.1 NtfsCommonCreate denial of service
17911| [101151] Microsoft ASP.NET Core/.NET Core Web Request denial of service
17912| [101817] Microsoft Windows up to Server 2016 Malware Protection Engine denial of service
17913| [101814] Microsoft Windows up to Server 2016 Malware Protection Engine denial of service
17914| [101812] Microsoft Windows up to Server 2016 Malware Protection Engine denial of service
17915| [101811] Microsoft Windows up to Server 2016 Malware Protection Engine denial of service
17916| [101810] Microsoft Windows up to Server 2016 Malware Protection Engine denial of service
17917| [101043] Microsoft Windows up to XP SP3 SMB denial of service
17918| [101039] Microsoft Windows up to XP SP3 SMB denial of service
17919| [101036] Microsoft Windows up to XP SP3 SMBv1 Server denial of service
17920| [101026] Microsoft Windows DNS Server denial of service
17921| [100918] Microsoft Windows 8/8.1/10/Server 2012/Server 2016 Malware Protection Service Type Confusion privilege escalation
17922| [100807] Rxvt 2.7.10 Terminal Escape Code Integer denial of service
17923| [99697] Microsoft SharePoint Server 2010 SP1/2010 SP2 Excel Services cross site scripting
17924| [99695] Microsoft Hyper-V Network Switch denial of service
17925| [99694] Microsoft Hyper-V denial of service
17926| [99693] Microsoft Hyper-V Network Switch denial of service
17927| [99692] Microsoft Hyper-V Network Switch denial of service
17928| [99691] Microsoft Hyper-V denial of service
17929| [99690] Microsoft Hyper-V denial of service
17930| [99680] Microsoft Windows up to Vista SP2 Win32k denial of service
17931| [99667] Microsoft Windows 10/Server 2016 Active Directory Service Unresponsive denial of service
17932| [98319] Palo Alto Terminal Services Agent 6.0/7.0/8.0 information disclosure
17933| [98113] Microsoft Windows up to Vista SP2 XML Core Services information disclosure
17934| [98110] Microsoft Windows Active Directory Federation Services XXE information disclosure
17935| [98082] Microsoft Office 2010 SP2/2013 SP1/2013 RT SP1/2016 denial of service
17936| [98015] Microsoft Windows 10/Server 2016 Hyper-V denial of service
17937| [98012] Microsoft Windows up to Vista SP2 Hyper-V denial of service
17938| [98011] Microsoft Windows up to Vista SP2 Hyper-V denial of service
17939| [98010] Microsoft Windows up to Vista SP2 Hyper-V denial of service
17940| [98007] Microsoft Windows 10/Server 2016 Hyper-V Network Switch denial of service
17941| [96521] Microsoft Windows 8.1/10/Server 2012/Server 2016 SMB Response mrxsmb20.sys denial of service
17942| [96743] Microsoft ASP.NET Core MVC denial of service
17943| [96234] Palo Alto Terminal Services Agent up to 7.0.6 User spoofing
17944| [95126] Microsoft Windows Local Security Authority Subsystem Service denial of service
17945| [93541] Microsoft Office 2007 SP3 denial of service
17946| [93418] Microsoft Windows up to Vista SP2 Local Security Authority Subsystem Service denial of service
17947| [93235] Microsoft Internet Explorer 11 CalculateImageImmunity denial of service
17948| [91703] Symantec Mail Security for Microsoft Exchange up to 6.5.8/7.0.4/7.5.4 RAR Decompression Memory Consumption denial of service
17949| [91702] Symantec Mail Security for Microsoft Exchange up to 6.5.8/7.0.4/7.5.4 RAR Decompression Out-of-Bounds denial of service
17950| [91560] Microsoft Windows 10 Object denial of service
17951| [90934] Microsoft Windows 7/8.1 FON Font File win32k.sys denial of service
17952| [87961] Microsoft Windows up to Server 2012 R2 Search denial of service
17953| [87960] Microsoft Windows Server 2008 R2/Server 2012/Server 2012 R2 Active Directory denial of service
17954| [82234] Microsoft Windows 10 HTTP.sys HTTP Request denial of service
17955| [82232] Microsoft XML Core Services 3.0 MSXML memory corruption
17956| [81266] Microsoft Windows up to Vista SP2 OpenType Font denial of service
17957| [80879] Microsoft Windows Network Policy Server RADIUS denial of service
17958| [80878] Microsoft Windows Server 2012 R2 Active Directory Federation Service denial of service
17959| [80223] Microsoft Windows 10/1511 RDP Service weak authentication
17960| [79183] Microsoft Windows up to Server 2012 R2 IPsec denial of service
17961| [78371] Microsoft SharePoint Server 2007 SP3/2010 SP2 InfoPath Forms Services XXE information disclosure
17962| [77640] Microsoft Windows Active Directory denial of service
17963| [77632] Microsoft .NET Framework up to 4.6 MVC denial of service
17964| [77622] Microsoft Windows up to Vista SP2 Journal File denial of service
17965| [77613] Microsoft Windows up to Vista SP2 Adobe Type Manager Library atmfd.dll OpenType Font denial of service
17966| [77597] Microsoft Internet Explorer 10/11 File denial of service
17967| [77038] Microsoft Windows Server 2008 SP2 UDDI Services cross site scripting
17968| [77032] Microsoft Windows up to Vista XML Core Services information disclosure
17969| [77031] Microsoft Windows up to Vista XML Core Services information disclosure
17970| [77030] Microsoft Windows up to Vista XML Core Services information disclosure
17971| [76460] Microsoft Windows 7 SP1/8/Server 2012 RDP Server Service memory corruption
17972| [75783] Microsoft Windows Server 2008/Server 2012 Active Directory Federation Services cross site scripting
17973| [75499] Microsoft Internet Explorer 11 denial of service
17974| [75339] Microsoft .NET Framework up to 4.5.2 XML Memory Consumption denial of service
17975| [75335] Microsoft Windows up to Vista SP2 Service Control Manager privilege escalation
17976| [75328] Microsoft Windows up to Vista Management Console denial of service
17977| [66976] Microsoft Access 2010 VBA Datatype denial of service
17978| [74842] Microsoft Windows 8.1/Server 2012 R2 Hyper-V denial of service
17979| [74841] Microsoft XML Core Services 3.0 privilege escalation
17980| [74834] Microsoft Windows Server 2012 R2 Active Directory Federation Services 3.0 privilege escalation
17981| [73961] Microsoft Windows 7 SP1/8/8.1/Server 2012/Server 2012 R2 Remote Desktop Protocol Object Management denial of service
17982| [73960] Microsoft Windows Netlogon Service User spoofing
17983| [73958] Microsoft Windows up to Vista SP2 Text Services memory corruption
17984| [73950] Microsoft Windows up to Vista Adobe Font Driver denial of service
17985| [69153] Microsoft Windows up to Vista Font Mapper win32k.sys denial of service
17986| [68596] Microsoft Windows Internet Authentication Service denial of service
17987| [68593] Microsoft Windows up to Server 2012 Network Location Awareness Service privilege escalation
17988| [68196] Microsoft Windows up to Vista TrueType Array Index denial of service
17989| [68190] Microsoft Windows up to Vista Audio Service privilege escalation
17990| [68211] Microsoft Internet Explorer 8/9/10/11 denial of service
17991| [67518] Microsoft Lync 2013 denial of service
17992| [67516] Microsoft Lync 2010/2013 denial of service
17993| [67514] Microsoft .NET Framework up to 4.5.2 Hash Collision Form denial of service
17994| [67354] Microsoft SQL Server 2008 SP3/2008 R2 SP2/2012 SP1/2014 SQL Master Data Services cross site scripting
17995| [67018] Microsoft Windows Server 2008/Server 2012/Server 2012 R2 Service Bus AMQP Message denial of service
17996| [29831] Microsoft Malware Protection Engine up to 1.1.10600.0 denial of service
17997| [13548] Microsoft Windows up to Vista TCP/IP Packet TCP Options denial of service
17998| [13546] Microsoft Windows up to Vista XML Core Services information disclosure
17999| [13450] Microsoft Internet Explorer 11 WeakMap Integer denial of service
18000| [69756] Novell openSUSE 11.4/12.1 Terminal caps.c denial of service
18001| [13234] Microsoft Windows iSCSI Packets denial of service
18002| [13233] Microsoft Windows iSCSI Packets denial of service
18003| [12843] Microsoft Office 2007/2010/2011/2013 XML Parser Nested Entities Memory Consumption denial of service
18004| [12271] Microsoft .NET Framework up to 4.5.1 HTTP POST denial of service
18005| [12264] Microsoft Windows up to XP XML Core Services Bypass information disclosure
18006| [12238] Microsoft Windows 8/Server 2012/RT IPv6 denial of service
18007| [66083] Microsoft Dynamics AX 4.0 denial of service
18008| [12183] Microsoft .NET Framework 2/4 DTD denial of service
18009| [11673] Microsoft Windows Live Movie Maker 2011 WAV File denial of service
18010| [11457] Microsoft SharePoint Server/Office Web Apps 2010 SP1/2010 SP2/2013 W3WP Service Account privilege escalation
18011| [11147] Microsoft Windows up to XP X.509 Certificate Processor Crypt32.dll/Wcrypt32.dll denial of service
18012| [11230] Microsoft Word 2003 DOC Document Embedded Image denial of service
18013| [10641] Microsoft Windows up to XP Comctl32.dll DSA_InsertItem denial of service
18014| [10640] Microsoft .NET Framework up to 4.5 JSON Data Crash denial of service
18015| [10639] Microsoft .NET Framework up to 4.5 XML External Entity Crash denial of service
18016| [10250] Microsoft SharePoint Server up to 2013 W3WP Process denial of service
18017| [10190] Microsoft Windows Vista/7/8/Server 2008 Active Directory denial of service
18018| [9944] Microsoft Windows up to XP TCP/IP Stack ICMPv6 Packet Stack-Based denial of service
18019| [9943] Microsoft Windows Server 2012 NAT Driver ICMP Packet denial of service
18020| [9929] Microsoft Windows Server 2008/Server 2012 Active Directory Federation Services Unspecified Account information disclosure
18021| [9715] Microsoft PowerPoint 2007 DirectShow Runtime quartz.dll GetMaxSampleSize denial of service
18022| [9259] Microsoft Internet Explorer 7.00.5730.13/8.00.6001.18702 Javascript denial of service
18023| [9101] Microsoft Internet Explorer 9/10 denial of service
18024| [8722] Microsoft Windows 8/Server 2012/RT HTTP.sys denial of service
18025| [12619] Microsoft Internet Explorer XMLDOM ActiveX Control denial of service
18026| [8423] Microsoft Internet Explorer up to 8.00.6001.18702 CSS iexplorer.exe denial of service
18027| [8208] Microsoft Windows win32k.sys denial of service
18028| [8203] Microsoft Windows up to 2012 AD LDAP Query denial of service
18029| [7968] Microsoft SharePoint Server 2010 SP1 Input Validator Eingabe Crash denial of service
18030| [7996] Microsoft Windows 8 TrueType Font denial of service
18031| [7981] FFmpeg up to 1.1.3 Microsoft RLE Data msrledec.c msrle_decode_8_16_24_32 denial of service
18032| [8432] Microsoft Internet Explorer 10 HTML5 Engine localStorage denial of service
18033| [7941] Google Chrome 15.0.874.121/16.0.912.63/26.0.1410.27 Frame Plugin for Microsoft IE protocol_sink_wrap.cc Hook_Terminate denial of service
18034| [7678] Microsoft Windows up to XP TCP FIN WAIT TCP/IP denial of service
18035| [7643] Microsoft Windows Server 2008 R2/Server 2012 NFS Server NULL Pointer Dereference denial of service
18036| [63336] Microsoft XML Core Services 3.0/5.0/6.0 memory corruption
18037| [7259] Microsoft .NET Framework 3.5/3.5 SP1/3.5.1/4 Replace() denial of service
18038| [7255] Microsoft .NET Framework up to 4.5 System.DirectoryServices.Protocolsb Method memory corruption
18039| [7249] Microsoft XML Core Services 1.x XSLT memory corruption
18040| [7199] Microsoft Internet Explorer 8/9 mshtml.dll Unclosed Tags Sequence denial of service
18041| [7121] Microsoft Exchange 2007/2010 RSS Feed denial of service
18042| [7092] Microsoft Internet Explorer 7 Redirect denial of service
18043| [7058] Microsoft Windows 7/Server 2008 R2 DHCPv6 Message denial of service
18044| [7230] Microsoft Excel 2010 SP1 on 32-bit XLS File Formatting Information Crash denial of service
18045| [6627] Microsoft Windows 7/Server 2008 R2 Kerberos denial of service
18046| [5939] Microsoft Windows XP/Vista/7/Server 2003/Server 2008 R2 Print Spooler Service memory corruption
18047| [5938] Microsoft Windows XP/Vista/7/Server 2003/Server 2008 R2 Remote Administration Protocol netapi32.dll RAP Request denial of service
18048| [61375] Nalin Dahyabhai Vte up to 0.19.0 Terminal denial of service
18049| [61230] Synel SY-780/A Time & Attendance terminal 3735 Terminal denial of service
18050| [61153] Keith Winstein mosh up to 1.2-2 Terminal denial of service
18051| [5553] Microsoft Windows XP/Vista/7/Server 2003/Server 2008 OpenType Font atmfd.dll denial of service
18052| [5526] Microsoft XML Core Services up to 6.0 memory corruption
18053| [5474] Microsoft WordPad 5.1 DOC Document denial of service
18054| [60711] Microsoft .NET Framework 4.0 denial of service
18055| [4803] Microsoft Windows Server 2003/Server 2008 DNS Server Domain Resource Record Query Parser denial of service
18056| [4802] Microsoft Windows XP/Vista/7/Server 2003/Server 2008 Remote Desktop Protocol denial of service
18057| [4798] Microsoft Windows XP/Vista/7/Server 2003/Server 2008 Remote Desktop Service memory corruption
18058| [4848] Microsoft Internet Explorer 6/7/8/9/10 Integrity Process denial of service
18059| [4509] Microsoft .NET Framework 1.1 SP1/2.0 SP2/3.5 SP1/3.5.1/4.0 Forms Authentication Ticket Caching denial of service
18060| [4506] Microsoft .NET Framework 1.1 SP1/2.0 SP2/3.5 SP1/3.5.1/4.0 ASP.NET Hash denial of service
18061| [4484] Microsoft Windows Phone 7.5 SMS Service denial of service
18062| [4455] Microsoft Windows XP Keyboard Layout win32k.sys denial of service
18063| [4439] Microsoft Windows True Type Fonts denial of service
18064| [4438] Microsoft Windows Vista/7/Server 2008 TCP/IP Reference Counter denial of service
18065| [59008] Microsoft Forefront Unified Access Gateway 2010 Crash denial of service
18066| [59005] Microsoft Host Integration Server 2004 denial of service
18067| [4424] Microsoft Host Integration Server up to 2010 denial of service
18068| [58236] Microsoft Windows TCP/IP Stack Stack-Based denial of service
18069| [4396] Microsoft Windows Vista/7/Server 2008 TCP/IP Stack denial of service
18070| [4394] Microsoft Windows DNS Service Domain Lookup denial of service
18071| [4393] Microsoft Windows Server 2008 DNS Service memory corruption
18072| [4392] Microsoft Windows Remote Access Service memory corruption
18073| [4389] Microsoft Windows Remote Desktop Protocol denial of service
18074| [4388] Microsoft Windows Vista/7/Server 2008 File Metadata Parser denial of service
18075| [4386] Microsoft Windows XP denial of service
18076| [91971] Microsoft Skype 2.2.x/5.2.x/5.3.x denial of service
18077| [57812] Microsoft Windows XP lots-of-polys-example.html denial of service
18078| [57693] Microsoft Forefront Threat Management Gateway 2010 NSPLookupServiceNext memory corruption
18079| [57692] Microsoft Windows XP denial of service
18080| [57691] Microsoft SQL Server 2008 Web Service information disclosure
18081| [4367] Microsoft Windows Server 2008 Hyper-V VMBus denial of service
18082| [4362] Microsoft Windows Vista/7/Server 2008 denial of service
18083| [4347] Microsoft Windows WINS Service Stack-based Designfehler
18084| [57299] Microsoft Silverlight up to 4.0.60129.0 Grid Control Memory Leak denial of service
18085| [57298] Microsoft Silverlight up to 4.0.60129.0 Memory Leak denial of service
18086| [4337] Microsoft Windows OpenType Font Stack-based denial of service
18087| [4301] Microsoft Windows Server 2003 SMB Browser Heap-based denial of service
18088| [56383] Microsoft Windows denial of service
18089| [55937] Microsoft Windows XP denial of service
18090| [4234] Microsoft IIS 7.5 FTP Server Telnet IAC Character Heap-based denial of service
18091| [4230] Microsoft Exchange 2007 on 64-bit RPC store.exe MAPI Request denial of service
18092| [4229] Microsoft SharePoint 2007 Document Conversion Launcher Service Eingabeung\xC3\xBCltigkeit
18093| [4228] Microsoft Windows Server 2008 Hyper-V VMBus denial of service
18094| [4227] Microsoft Windows Netlogon RPC Service denial of service
18095| [4231] Microsoft Windows XP/Vista/7/Server 2003/Server 2008 Driver win32k.sys GreEnableEUDC denial of service
18096| [4194] Microsoft Windows Vista/7/Server 2008 SChannel Client Certificate Request denial of service
18097| [54774] Microsoft Word 2003 word_crash_11.8326.8324_poc.doc denial of service
18098| [4180] Microsoft IIS 5.1/6.0/7.0/7.5 Repeated Parameter Request denial of service
18099| [4187] Microsoft Windows Vista/7/Server 2008 TCP/IP Stack Ipv4SetEchoRequestCreate() denial of service
18100| [54333] Microsoft Windows denial of service
18101| [54332] Microsoft Windows denial of service
18102| [4165] Microsoft Windows Vista/7/Server 2008 TCP/IP Stack denial of service
18103| [4163] Microsoft XML Core Services 3.x HTTP HTTP Response memory corruption
18104| [53508] Microsoft SharePoint Services 3.0 denial of service
18105| [4134] Microsoft Windows OpenType Compact Font Format Driver denial of service
18106| [53422] Microsoft Internet Explorer 6.0.2900.2180 denial of service
18107| [53421] Microsoft Internet Explorer 6/7/8 denial of service
18108| [53284] Microsoft Internet Explorer 6/7/8 denial of service
18109| [4107] Microsoft Windows 7/Server 2008 Kernel denial of service
18110| [4104] Microsoft Windows SMTP Service denial of service
18111| [4103] Microsoft Windows Server 2003 Media Services Stack-based memory corruption
18112| [52400] Microsoft Internet Explorer 6.00.2800.1106 NULL Pointer Dereference denial of service
18113| [52336] Microsoft Windows denial of service
18114| [51809] Microsoft Windows denial of service
18115| [51803] Microsoft Windows NULL Pointer Dereference denial of service
18116| [51796] Microsoft Windows denial of service
18117| [51497] Microsoft Windows Live Messenger 2009 ActiveX Control msnmsgr.exe denial of service
18118| [4067] Microsoft Windows Active Directory Federation Service memory corruption
18119| [4066] Microsoft Windows Local Security Authority Subsystem denial of service
18120| [50823] Microsoft Internet Explorer 6/7 denial of service
18121| [50811] Microsoft Windows denial of service
18122| [4058] Microsoft Windows Active Directory denial of service
18123| [50445] Microsoft Windows EducatedScholar denial of service
18124| [50444] Microsoft Windows Local Security Authority Subsystem Service Integer denial of service
18125| [50139] Microsoft Enterprise Library 4.0 denial of service
18126| [50128] Microsoft Internet Explorer 7.00.5730.1100 window.print denial of service
18127| [50125] Microsoft Internet Explorer 6/7 denial of service
18128| [4030] Microsoft Windows Vista/Server 2008 Wireless LAN AutoConfig Service Heap-based memory corruption
18129| [4029] Microsoft Windows 2000/XP TCP/IP Window Size denial of service
18130| [4024] Microsoft IIS 5.0/6.0/7.0 FTP Server denial of service
18131| [49745] Microsoft Windows Server 2003 denial of service
18132| [49744] Microsoft Internet Explorer 7 Crash denial of service
18133| [49699] Sophos PureMessage for Microsoft Exchange Installation denial of service
18134| [49698] Sophos PureMessage for Microsoft Exchange EdgeTransport.exe denial of service
18135| [49697] Sophos PureMessage for Microsoft Exchange Message Queue PMScanner.exe denial of service
18136| [49620] Microsoft Internet Explorer up to 6.0.2900.2180 JavaScript denial of service
18137| [49434] Microsoft Windows 7 Crash denial of service
18138| [4014] Microsoft Windows Workstation Service memory corruption
18139| [4013] Microsoft Windows Message Queuing Service Designfehler
18140| [4012] Microsoft Windows WINS Service memory corruption
18141| [4011] Microsoft Windows WINS Service Heap-based memory corruption
18142| [4009] Microsoft NET Framework 2.x/3.x denial of service
18143| [49262] Microsoft Internet Explorer 6/7 denial of service
18144| [49242] Microsoft Internet Explorer 7/8 on Win XP mshtml.dll denial of service
18145| [49122] Microsoft Internet Explorer 5/6/7 Unicode Character Memory Consumption denial of service
18146| [49074] Microsoft Internet Explorer 5/6/7/8 Memory Consumption denial of service
18147| [48518] Microsoft ADAM XP Active Directory Memory Leak denial of service
18148| [48033] Microsoft Windows XP denial of service
18149| [47808] Microsoft Internet Explorer 7/8 on Win XP/Vista Document denial of service
18150| [47804] Microsoft Windows Media Player 11.0.5721.5260 Integer denial of service
18151| [86702] Microsoft ISA Server / denial of service
18152| [3952] Microsoft ISA Server 2004/2006 denial of service
18153| [3950] Microsoft Windows HTTP Service memory corruption
18154| [47465] Microsoft Windows GDI+ gdiplus.dll GpFont::SetData denial of service
18155| [46637] Microsoft Windows DNS Server Memory Leak denial of service
18156| [46620] Microsoft Windows Live Messenger 2009 msnmsgr.exe denial of service
18157| [46455] Microsoft Exchange Server 2007 denial of service
18158| [46294] Microsoft XML Core Services information disclosure
18159| [46007] Microsoft Windows Mobile 6.0 FTP Service Stack-Based directory traversal
18160| [45911] Microsoft Windows Domain Controller denial of service
18161| [45826] Microsoft Internet Explorer 6/7/8 Crash denial of service
18162| [45758] Microsoft Money 2006 ActiveX Control prtstb06.dll denial of service
18163| [45676] Microsoft Windows Media Player 9 quartz.dll denial of service
18164| [45392] Microsoft Outlook Express 6.00.2900.5512 InetComm.dll MimeOleClearDirtyTree denial of service
18165| [45379] Microsoft Office SharePoint Server 2007 denial of service
18166| [45131] Microsoft Office Communicator denial of service
18167| [45130] Microsoft Office Communicator Memory Consumption denial of service
18168| [45129] Microsoft Windows Live Messenger Crash denial of service
18169| [44976] Microsoft XML Core Services up to 6.0 information disclosure
18170| [44975] Microsoft XML Core Services 3.0/4.0 information disclosure
18171| [44860] Microsoft Windows Media Player up to 9 Crash denial of service
18172| [44780] Microsoft Debug Diagnostic Tool 1.0 ActiveX Control CrashHangExt.dll denial of service
18173| [3851] Microsoft Windows IIS IPP Service memory corruption
18174| [44306] Microsoft Internet Explorer 7 alert denial of service
18175| [44249] Microsoft Windows XP SP3 gdiplus.dll denial of service
18176| [44246] Microsoft Windows XP SP3 denial of service
18177| [44237] Microsoft iis ActiveX Control adsiis.dll denial of service
18178| [44236] Microsoft Authentication Service iashlpr.dll denial of service
18179| [44227] Microsoft Windows Mobile 6.0 Bluetooth denial of service
18180| [44092] Microsoft Internet Explorer 7/8 Beta PNG Image Mshtml.dll CDwnTaskExec::ThreadExec denial of service
18181| [44069] Microsoft Windows denial of service
18182| [42732] Microsoft Windows XP/Vista/Server 2003 denial of service
18183| [42731] Microsoft Windows Server 2003 denial of service
18184| [3733] Microsoft Windows Active Directory LDAP Request denial of service
18185| [42328] Microsoft Windows Live Onecare 1.1.3520.0 Malware Protection Engine mpengine.dll denial of service
18186| [42327] Microsoft Windows Live Onecare 1.1.3520.0 Malware Protection Engine mpengine.dll denial of service
18187| [40987] Microsoft Windows 2000 denial of service
18188| [40986] Microsoft Windows Vista denial of service
18189| [40353] Microsoft Internet Explorer 7 ActiveX Control npupload.dll SetPassword denial of service
18190| [40242] Microsoft Publisher 2000/2002/2003/2007 Crash denial of service
18191| [3510] Microsoft Media Services 9.x ASF File Heap-based memory corruption
18192| [39937] Microsoft Windows Media Player 11 Crash denial of service
18193| [36994] Microsoft Visual Database Tools Database Designer 7.0 ActiveX Control vdt70.dll notsafe denial of service
18194| [3372] Microsoft Windows SharePoint Services cross site scripting
18195| [3370] Microsoft Windows RPC Authentication denial of service
18196| [38999] Microsoft Windows Server 2003 explorer.exe denial of service
18197| [3302] Microsoft Windows Services for UNIX memory corruption
18198| [3252] Microsoft XML Core Services substringData() cross site scripting
18199| [38272] Microsoft Windows Media Player 11 wmplayer.exe denial of service
18200| [38227] Microsoft Internet Explorer 6 JPG Image explorer.exe denial of service
18201| [38246] Microsoft Windows Crash denial of service
18202| [37962] Microsoft Internet Explorer GIF File explorer.exe denial of service
18203| [3179] Microsoft Windows Active Directory LDAP ASN denial of service
18204| [37724] Microsoft Register Server denial of service
18205| [37627] Microsoft Internet Explorer 6.0/7.0 Zone denial of service
18206| [37526] Microsoft Windows 2000/Server 2003 denial of service
18207| [37405] Microsoft Internet Explorer 6 on Win XP SysFreeString denial of service
18208| [37508] Microsoft MSN Messenger 4.7 Flooding denial of service
18209| [37157] Microsoft Windows XP Graphics Device Interface gdiplus.dll denial of service
18210| [86350] Microsoft Windows denial of service
18211| [36936] Microsoft Internet Information Services 5.0 Authentication Mechanism webhits.dll unknown vulnerability
18212| [36711] Microsoft Terminal Server 6.0 Remote Desktop Protocol unknown vulnerability
18213| [36621] Microsoft Exchange Server 2000 Integer denial of service
18214| [36618] Microsoft Exchange Server 2000 NULL Pointer Dereference denial of service
18215| [36305] Microsoft Internet Explorer 7.0 denial of service
18216| [3012] Microsoft Windows 2000/Server 2003 DNS Service Stack-based memory corruption
18217| [36002] Microsoft Windows XP/2000 denial of service
18218| [2991] Microsoft Windows Vista ATI Radeon Kernel Mode Driver Crash denial of service
18219| [35822] Microsoft Windows Proxy Server denial of service
18220| [35704] Microsoft Windows XP/Vista ARP denial of service
18221| [35703] Microsoft Windows Vista LLTD Mapper denial of service
18222| [35654] Microsoft Windows XP winmm.dll mmioread denial of service
18223| [35373] Microsoft Excel 2003 denial of service
18224| [35372] Microsoft Office 2003 denial of service
18225| [35254] Microsoft Internet Explorer 6 mshtml.dll denial of service
18226| [35206] Microsoft Windows XP/Server 2003 Crash denial of service
18227| [35209] Microsoft Internet Explorer 7.0 LOAD Crash denial of service
18228| [35165] Microsoft Internet Explorer up to 6.0.2900 mshtml.dll denial of service
18229| [35164] Microsoft Internet Explorer up to 6.0 mshtml.dll denial of service
18230| [35163] Microsoft Internet Explorer denial of service
18231| [34991] Microsoft Visual Studio 8.0 msvcr80.dll denial of service
18232| [34967] Microsoft Windows Mobile 5.0 denial of service
18233| [34875] Microsoft Internet Explorer 6.0 SP1/6.0 SP2 NULL Pointer Dereference denial of service
18234| [34793] Microsoft Windows Mobile 5.0 denial of service
18235| [34655] Microsoft Internet Explorer Crash denial of service
18236| [34737] Microsoft Internet Explorer 7 ActiveX Control mshtml.dll denial of service
18237| [34690] Microsoft Windows Explorer 6.0.2900.2180 explorer.exe denial of service
18238| [2809] Microsoft Outlook 2000/2002/2003 Header denial of service
18239| [34253] Microsoft IIS denial of service
18240| [85073] Microsoft Internet Explorer denial of service
18241| [34124] Microsoft Dynamics GP up to 9.0 Crash denial of service
18242| [2789] Microsoft Windows 2000/XP RPC Request NetrWkstaUserEnum() denial of service
18243| [33949] Microsoft Internet Explorer 7.0 ActiveX Control ole32.dll denial of service
18244| [33890] Microsoft Windows XP SP2 Explorer explorer.exe denial of service
18245| [33889] Microsoft Windows Media Player 10.00.00.4036 denial of service
18246| [2739] Microsoft Windows 2000 Remote Installation Service Fehlende Authentifizierung
18247| [2737] Microsoft Windows XP/Server 2003 Manifest denial of service
18248| [33643] Microsoft Internet Explorer 6.0.2900.2180 denial of service
18249| [33642] Microsoft Internet Explorer up to 6.0 Crash denial of service
18250| [33589] Microsoft Windows Live Messenger up to 8.0 denial of service
18251| [2717] Microsoft Windows 2000 Print Spooler Memory Consumption denial of service
18252| [2689] Microsoft Windows up to 2000 SP4 Active Directory denial of service
18253| [2688] Microsoft Windows 2000/XP/Server 2003 Client Service for Netware denial of service
18254| [2686] Microsoft Windows 2000/XP/Server 2003 Client Service for Netware memory corruption
18255| [2684] Microsoft Windows 2000/XP Workstation Service Stack-based memory corruption
18256| [2655] Microsoft Windows 2000/XP/Server 2003 XML Core Services Designfehler
18257| [2640] Microsoft Windows XP Windows NAT Helper Component ipnathlp.dll DNS Query denial of service
18258| [2610] Microsoft PowerPoint 2003 PPT Document NULL Pointer Dereference denial of service
18259| [32692] Microsoft XML Core Services up to 2.6 memory corruption
18260| [32691] Microsoft XML Core Services up to 2.6 memory corruption
18261| [2601] Microsoft Windows XP/Server 2003 IPv6 Stack denial of service
18262| [2600] Microsoft Windows XP/Server 2003 IPv6 Stack TCP denial of service
18263| [2599] Microsoft Windows XP/Server 2003 IPv6 Stack ICMP denial of service
18264| [2522] Microsoft Windows 2000/XP/Server 2003 Indexing Service cross site scripting
18265| [32026] Microsoft Terminal Server Client Connection Manager memory corruption
18266| [84706] Microsoft Internet Explorer dxtmsft3.dll denial of service
18267| [31920] Microsoft Internet Explorer 6.0 SP1 dximagetransform.microsoft.chroma.1 denial of service
18268| [31736] Microsoft Windows XP gdiplus.dll denial of service
18269| [2426] Microsoft Windows 2000/XP/Server 2003 WMF File gdi32.dll denial of service
18270| [2415] Microsoft Windows 2000/XP/Server 2003 SMB File srv.sys denial of service
18271| [35255] Microsoft Internet Explorer up to 7.0.6000.16473 NULL Pointer Dereference denial of service
18272| [31521] Microsoft Windows NT 4.0/2000/XP IP Stack Stack-Based denial of service
18273| [31551] Microsoft Internet Explorer 6 window.alert denial of service
18274| [31582] Microsoft Internet Explorer 6 Integer denial of service
18275| [31527] Microsoft Internet Explorer 6.0 on Win 2000 ActiveX Object Stack-Based denial of service
18276| [32623] Microsoft Internet Explorer up to 6.0 wininet.dll denial of service
18277| [31528] Microsoft Internet Explorer 6.0 ActiveX Object Click denial of service
18278| [31529] Microsoft Internet Explorer 6.0 ActiveX Object cenroll.cenroll.2 stringtobinary denial of service
18279| [31546] Microsoft Internet Explorer 6 ActiveX Object newdefaultitem denial of service
18280| [31431] Microsoft Internet Explorer 6 DataSourceControl Integer denial of service
18281| [31358] Microsoft PowerPoint 2003 powerpnt.exe denial of service
18282| [31352] Microsoft Works 8.0 Spreadsheet wksss.exe denial of service
18283| [31355] Microsoft Internet Explorer 6 ActiveX Object Stack-Based denial of service
18284| [31357] Microsoft Internet Explorer 6 ActiveX Object Crash denial of service
18285| [31356] Microsoft Internet Explorer 6 Security Check Crash denial of service
18286| [32375] Microsoft Internet Explorer up to 6 denial of service
18287| [31331] Microsoft Internet Explorer 6.0 ActiveX Object Crash denial of service
18288| [31272] Microsoft Internet Explorer 7.0 Crash denial of service
18289| [31319] Microsoft Internet Explorer NULL Pointer Dereference denial of service
18290| [2369] Microsoft Windows 2000/XP/Server 2003 Server Service Mailslot Heap-based memory corruption
18291| [31239] Microsoft Internet Explorer Crash denial of service
18292| [31240] Microsoft Internet Explorer ActiveX Object Crash denial of service
18293| [31241] Microsoft Internet Explorer danim.dll denial of service
18294| [31238] Microsoft Internet Explorer 6.0 on Win 2000 Crash denial of service
18295| [31213] Microsoft Internet Explorer 6 Crash denial of service
18296| [31204] Microsoft Internet Explorer 6.0 ActiveX Object Crash denial of service
18297| [31214] Microsoft Internet Explorer 6.0/6.0 SP1 denial of service
18298| [32150] Microsoft System Information ActiveX control ActiveX Control msinfo.dll savefile denial of service
18299| [28142] Microsoft Outlook Express Book Control Address Book Crash denial of service
18300| [31136] Microsoft Internet Explorer 6 ActiveX Object Crash denial of service
18301| [30973] Microsoft Internet Explorer 6.0.2900 Crash denial of service
18302| [2309] Microsoft Windows 2000/XP/Server 2003 Routing and Remote Access Service RPC Request memory corruption
18303| [30131] Microsoft Windows NT 4.0/XP/2000/Server 2003 Distributed Transaction Coordinator Crash denial of service
18304| [2218] Microsoft Windows 2000/XP/Server 2003 MSDTC Heap-based denial of service
18305| [29604] Microsoft Internet Explorer 6 Crash denial of service
18306|
18307| MITRE CVE - https://cve.mitre.org:
18308| [CVE-2012-0152] The Remote Desktop Protocol (RDP) service in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows remote attackers to cause a denial of service (application hang) via a series of crafted packets, aka "Terminal Server Denial of Service Vulnerability."
18309| [CVE-2011-1991] Multiple untrusted search path vulnerabilities in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allow local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .doc, .rtf, or .txt file, related to (1) deskpan.dll in the Display Panning CPL Extension, (2) EAPHost Authenticator Service, (3) Folder Redirection, (4) HyperTerminal, (5) the Japanese Input Method Editor (IME), and (6) Microsoft Management Console (MMC), aka "Windows Components Insecure Library Loading Vulnerability."
18310| [CVE-2009-1929] Heap-based buffer overflow in the Microsoft Terminal Services Client ActiveX control running RDP 6.1 on Windows XP SP2, Vista SP1 or SP2, or Server 2008 Gold or SP2
18311| [CVE-2009-1133] Heap-based buffer overflow in Microsoft Remote Desktop Connection (formerly Terminal Services Client) running RDP 5.0 through 6.1 on Windows, and Remote Desktop Connection Client for Mac 2.0, allows remote attackers to execute arbitrary code via unspecified parameters, aka "Remote Desktop Connection Heap Overflow Vulnerability."
18312| [CVE-2006-4219] The Terminal Services COM object (tsuserex.dll) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by instantiating it as an ActiveX object in Internet Explorer 6.0 SP1 on Microsoft Windows 2003 EE SP1 CN.
18313| [CVE-2005-3176] Microsoft Windows 2000 before Update Rollup 1 for SP4 does not record the IP address of a Windows Terminal Services client in a security log event if the client connects successfully, which could make it easier for attackers to escape detection.
18314| [CVE-2004-0900] The DHCP Server service for Microsoft Windows NT 4.0 Server and Terminal Server Edition does not properly validate the length of certain messages, which allows remote attackers to execute arbitrary code via a malformed DHCP message, aka the "DHCP Request Vulnerability."
18315| [CVE-2004-0899] The DHCP Server service for Microsoft Windows NT 4.0 Server and Terminal Server Edition, with DHCP logging enabled, does not properly validate the length of certain messages, which allows remote attackers to cause a denial of service (application crash) via a malformed DHCP message, aka "Logging Vulnerability."
18316| [CVE-2003-0807] Buffer overflow in the COM Internet Services and in the RPC over HTTP Proxy components for Microsoft Windows NT Server 4.0, NT 4.0 Terminal Server Edition, 2000, XP, and Server 2003 allows remote attackers to cause a denial of service via a crafted request.
18317| [CVE-2003-0003] Buffer overflow in the RPC Locator service for Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute arbitrary code via an RPC call to the service containing certain parameter information.
18318| [CVE-2002-1933] The terminal services screensaver for Microsoft Windows 2000 does not automatically lock the terminal window if the window is minimized, which could allow local users to gain access to the terminal server window.
18319| [CVE-2002-1795] Cross-site scripting (XSS) vulnerability in connect.asp in Microsoft Terminal Services Advanced Client (TSAC) ActiveX control allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
18320| [CVE-2002-0726] Buffer overflow in Microsoft Terminal Services Advanced Client (TSAC) ActiveX control allows remote attackers to execute arbitrary code via a long server name field.
18321| [CVE-2013-3661] The EPATHOBJ::bFlatten function in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not check whether linked-list traversal is continually accessing the same list member, which allows local users to cause a denial of service (infinite traversal) via vectors that trigger a crafted PATHRECORD chain.
18322| [CVE-2013-3178] Microsoft Silverlight 5 before 5.1.20513.0 does not properly initialize arrays, which allows remote attackers to execute arbitrary code or cause a denial of service (NULL pointer dereference) via a crafted Silverlight application, aka "Null Pointer Vulnerability."
18323| [CVE-2013-3172] Buffer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to cause a denial of service (system hang) via a crafted application that leverages improper handling of objects in memory, aka "Win32k Buffer Overflow Vulnerability."
18324| [CVE-2013-3164] Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
18325| [CVE-2013-3163] Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3144 and CVE-2013-3151.
18326| [CVE-2013-3162] Microsoft Internet Explorer 7 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3115.
18327| [CVE-2013-3161] Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3143.
18328| [CVE-2013-3153] Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3148.
18329| [CVE-2013-3152] Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3146.
18330| [CVE-2013-3151] Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3144 and CVE-2013-3163.
18331| [CVE-2013-3150] Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3145.
18332| [CVE-2013-3149] Microsoft Internet Explorer 7 and 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
18333| [CVE-2013-3148] Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3153.
18334| [CVE-2013-3147] Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
18335| [CVE-2013-3146] Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3152.
18336| [CVE-2013-3145] Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3150.
18337| [CVE-2013-3144] Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3151 and CVE-2013-3163.
18338| [CVE-2013-3143] Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3161.
18339| [CVE-2013-3142] Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3112, CVE-2013-3113, CVE-2013-3121, and CVE-2013-3139.
18340| [CVE-2013-3141] Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3110.
18341| [CVE-2013-3139] Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3112, CVE-2013-3113, CVE-2013-3121, and CVE-2013-3142.
18342| [CVE-2013-3138] Integer overflow in the TCP/IP kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allows remote attackers to cause a denial of service (system hang) via crafted TCP packets, aka "TCP/IP Integer Overflow Vulnerability."
18343| [CVE-2013-3125] Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3118 and CVE-2013-3120.
18344| [CVE-2013-3124] Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3117 and CVE-2013-3122.
18345| [CVE-2013-3123] Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3111.
18346| [CVE-2013-3122] Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3117 and CVE-2013-3124.
18347| [CVE-2013-3121] Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3112, CVE-2013-3113, CVE-2013-3139, and CVE-2013-3142.
18348| [CVE-2013-3120] Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3118 and CVE-2013-3125.
18349| [CVE-2013-3119] Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3114.
18350| [CVE-2013-3118] Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3120 and CVE-2013-3125.
18351| [CVE-2013-3117] Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3122 and CVE-2013-3124.
18352| [CVE-2013-3116] Microsoft Internet Explorer 7 through 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
18353| [CVE-2013-3115] Microsoft Internet Explorer 7 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3162.
18354| [CVE-2013-3114] Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3119.
18355| [CVE-2013-3113] Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3112, CVE-2013-3121, CVE-2013-3139, and CVE-2013-3142.
18356| [CVE-2013-3112] Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3113, CVE-2013-3121, CVE-2013-3139, and CVE-2013-3142.
18357| [CVE-2013-3111] Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3123.
18358| [CVE-2013-3110] Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3141.
18359| [CVE-2013-2558] Unspecified vulnerability in Microsoft Windows 8 allows remote attackers to cause a denial of service (reboot) or possibly have unknown other impact via a crafted TrueType Font (TTF) file, as demonstrated by the 120612-69701-01.dmp error report.
18360| [CVE-2013-2557] The sandbox protection mechanism in Microsoft Internet Explorer 9 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, as demonstrated against Adobe Flash Player by VUPEN during a Pwn2Own competition at CanSecWest 2013.
18361| [CVE-2013-2496] The msrle_decode_8_16_24_32 function in msrledec.c in libavcodec in FFmpeg through 1.1.3 does not properly determine certain end pointers, which allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) or possibly have unspecified other impact via crafted Microsoft RLE data.
18362| [CVE-2013-1346] mpengine.dll in Microsoft Malware Protection Engine before 1.1.9506.0 on x64 platforms allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file.
18363| [CVE-2013-1305] HTTP.sys in Microsoft Windows 8, Windows Server 2012, and Windows RT allows remote attackers to cause a denial of service (infinite loop) via a crafted HTTP header, aka "HTTP.sys Denial of Service Vulnerability."
18364| [CVE-2013-1293] The NTFS kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via a crafted application that leverages improper handling of objects in memory, aka "NTFS NULL Pointer Dereference Vulnerability."
18365| [CVE-2013-1291] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, Windows 7 Gold and SP1, and Windows 8 allows local users to cause a denial of service (reboot) via a crafted OpenType font, aka "OpenType Font Parsing Vulnerability" or "Win32k Font Parsing Vulnerability."
18366| [CVE-2013-1282] The LDAP service in Microsoft Active Directory, Active Directory Application Mode (ADAM), Active Directory Lightweight Directory Service (AD LDS), and Active Directory Services allows remote attackers to cause a denial of service (memory consumption and service outage) via a crafted query, aka "Memory Consumption Vulnerability."
18367| [CVE-2013-1281] The NFS server in Microsoft Windows Server 2008 R2 and R2 SP1 and Server 2012 allows remote attackers to cause a denial of service (NULL pointer dereference and reboot) via an attempted renaming of a file or folder located on a read-only share, aka "NULL Dereference Vulnerability."
18368| [CVE-2013-0085] Buffer overflow in Microsoft SharePoint Server 2010 SP1 and SharePoint Foundation 2010 SP1 allows remote attackers to cause a denial of service (W3WP process crash and site outage) via a crafted URL, aka "Buffer Overflow Vulnerability."
18369| [CVE-2013-0075] The TCP/IP implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows remote attackers to cause a denial of service (reboot) via a crafted packet that terminates a TCP connection, aka "TCP FIN WAIT Vulnerability."
18370| [CVE-2013-0011] The Print Spooler in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted print job, aka "Windows Print Spooler Components Vulnerability."
18371| [CVE-2013-0007] Microsoft XML Core Services (aka MSXML) 4.0, 5.0, and 6.0 does not properly parse XML content, which allows remote attackers to execute arbitrary code via a crafted web page, aka "MSXML XSLT Vulnerability."
18372| [CVE-2013-0006] Microsoft XML Core Services (aka MSXML) 3.0, 5.0, and 6.0 does not properly parse XML content, which allows remote attackers to execute arbitrary code via a crafted web page, aka "MSXML Integer Truncation Vulnerability."
18373| [CVE-2013-0005] The WCF Replace function in the Open Data (aka OData) protocol implementation in Microsoft .NET Framework 3.5, 3.5 SP1, 3.5.1, and 4, and the Management OData IIS Extension on Windows Server 2012, allows remote attackers to cause a denial of service (resource consumption and daemon restart) via crafted values in HTTP requests, aka "Replace Denial of Service Vulnerability."
18374| [CVE-2013-0003] Buffer overflow in a System.DirectoryServices.Protocols (S.DS.P) namespace method in Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, and 4.5 allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application that leverages a missing array-size check during a memory copy operation, aka "S.DS.P Buffer Overflow Vulnerability."
18375| [CVE-2012-5672] Microsoft Excel Viewer (aka Xlview.exe) and Excel in Microsoft Office 2007 (aka Office 12) allow remote attackers to cause a denial of service (read access violation and application crash) via a crafted spreadsheet file, as demonstrated by a .xls file with battery voltage data.
18376| [CVE-2012-4791] Microsoft Exchange Server 2007 SP3 and 2010 SP1 and SP2 allows remote authenticated users to cause a denial of service (Information Store service hang) by subscribing to a crafted RSS feed, aka "RSS Feed May Cause Exchange DoS Vulnerability."
18377| [CVE-2012-3456] Heap-based buffer overflow in the read function in filters/words/msword-odf/wv2/src/styles.cpp in the Microsoft import filter in Calligra 2.4.3 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted ODF style in an ODF document. NOTE: this is the same vulnerability as CVE-2012-3455, but it was SPLIT by the CNA even though Calligra and KOffice share the same codebase.
18378| [CVE-2012-3455] Heap-based buffer overflow in the read function in filters/words/msword-odf/wv2/src/styles.cpp in the Microsoft import filter in KOffice 2.3.3 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted ODF style in an ODF document. NOTE: this is the same vulnerability as CVE-2012-3456, but it was SPLIT by the CNA even though Calligra and KOffice share the same codebase.
18379| [CVE-2012-2970] The Synel SY-780/A Time & Attendance terminal allows remote attackers to cause a denial of service (device hang) via network traffic to port (1) 1641, (2) 3734, or (3) 3735.
18380| [CVE-2012-2738] The VteTerminal in gnome-terminal (vte) before 0.32.2 allows remote authenticated users to cause a denial of service (long loop and CPU consumption) via an escape sequence with a large repeat count value.
18381| [CVE-2012-2552] Cross-site scripting (XSS) vulnerability in the SQL Server Report Manager in Microsoft SQL Server 2000 Reporting Services SP2 and SQL Server 2005 SP4, 2008 SP2 and SP3, 2008 R2 SP1, and 2012 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka "Reflected XSS Vulnerability."
18382| [CVE-2012-2551] The server in Kerberos in Microsoft Windows Server 2008 R2 and R2 SP1, and Windows 7 Gold and SP1, allows remote attackers to cause a denial of service (NULL pointer dereference and reboot) via a crafted session request, aka "Kerberos NULL Dereference Vulnerability."
18383| [CVE-2012-2550] Microsoft Works 9 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted Word .doc file, aka "Works Heap Vulnerability."
18384| [CVE-2012-2532] Microsoft FTP Service 7.0 and 7.5 for Internet Information Services (IIS) processes unspecified commands before TLS is enabled for a session, which allows remote attackers to obtain sensitive information by reading the replies to these commands, aka "FTP Command Injection Vulnerability."
18385| [CVE-2012-2531] Microsoft Internet Information Services (IIS) 7.5 uses weak permissions for the Operational log, which allows local users to discover credentials by reading this file, aka "Password Disclosure Vulnerability."
18386| [CVE-2012-2524] Microsoft Office 2007 SP2 and SP3 and 2010 SP1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Computer Graphics Metafile (CGM) file, aka "CGM File Format Memory Corruption Vulnerability."
18387| [CVE-2012-2520] Cross-site scripting (XSS) vulnerability in Microsoft InfoPath 2007 SP2 and SP3 and 2010 SP1, Communicator 2007 R2, Lync 2010 and 2010 Attendee, SharePoint Server 2007 SP2 and SP3 and 2010 SP1, Groove Server 2010 SP1, Windows SharePoint Services 3.0 SP2, SharePoint Foundation 2010 SP1, and Office Web Apps 2010 SP1 allows remote attackers to inject arbitrary web script or HTML via a crafted string, aka "HTML Sanitization Vulnerability."
18388| [CVE-2012-2385] The terminal dispatcher in mosh before 1.2.1 allows remote authenticated users to cause a denial of service (long loop and CPU consumption) via an escape sequence with a large repeat count value.
18389| [CVE-2012-1889] Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.
18390| [CVE-2012-1863] Cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint Server 2007 SP2 and SP3 Windows SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via crafted JavaScript elements in a URL, aka "SharePoint Reflected List Parameter Vulnerability."
18391| [CVE-2012-1860] Microsoft Office SharePoint Server 2007 SP2 and SP3, SharePoint Server 2010 Gold and SP1, and Office Web Apps 2010 Gold and SP1 do not properly check permissions for search scopes, which allows remote authenticated users to obtain sensitive information or cause a denial of service (data modification) by changing a parameter in a search-scope URL, aka "SharePoint Search Scope Vulnerability."
18392| [CVE-2012-1853] Stack-based buffer overflow in the Remote Administration Protocol (RAP) implementation in the LanmanWorkstation service in Microsoft Windows XP SP3 allows remote attackers to execute arbitrary code via crafted RAP response packets, aka "Remote Administration Protocol Stack Overflow Vulnerability."
18393| [CVE-2012-1852] Heap-based buffer overflow in the Remote Administration Protocol (RAP) implementation in the LanmanWorkstation service in Microsoft Windows XP SP2 and SP3 allows remote attackers to execute arbitrary code via crafted RAP response packets, aka "Remote Administration Protocol Heap Overflow Vulnerability."
18394| [CVE-2012-1851] Format string vulnerability in the Print Spooler service in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted response, aka "Print Spooler Service Format String Vulnerability."
18395| [CVE-2012-1850] The Remote Administration Protocol (RAP) implementation in the LanmanWorkstation service in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle RAP responses, which allows remote attackers to cause a denial of service (service hang) via crafted RAP packets, aka "Remote Administration Protocol Denial of Service Vulnerability."
18396| [CVE-2012-1545] Microsoft Internet Explorer 6 through 9, and 10 Consumer Preview, allows remote attackers to bypass Protected Mode or cause a denial of service (memory corruption) by leveraging access to a Low integrity process, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2012.
18397| [CVE-2012-1194] The resolver in the DNS Server service in Microsoft Windows Server 2008 before R2 overwrites cached server names and TTL values in NS records during the processing of a response to an A record query, which allows remote attackers to trigger continued resolvability of revoked domain names via a "ghost domain names" attack.
18398| [CVE-2012-0183] Microsoft Word 2003 SP3 and 2007 SP2 and SP3, Office 2008 and 2011 for Mac, and Office Compatibility Pack SP2 and SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted RTF data, aka "RTF Mismatch Vulnerability."
18399| [CVE-2012-0164] Microsoft .NET Framework 4 does not properly compare index values, which allows remote attackers to cause a denial of service (application hang) via crafted requests to a Windows Presentation Foundation (WPF) application, aka ".NET Framework Index Comparison Vulnerability."
18400| [CVE-2012-0156] DirectWrite in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly render Unicode characters, which allows remote attackers to cause a denial of service (application hang) via a (1) instant message or (2) web site, aka "DirectWrite Application Denial of Service Vulnerability."
18401| [CVE-2012-0006] The DNS server in Microsoft Windows Server 2003 SP2 and Server 2008 SP2, R2, and R2 SP1 does not properly handle objects in memory during record lookup, which allows remote attackers to cause a denial of service (daemon restart) via a crafted query, aka "DNS Denial of Service Vulnerability."
18402| [CVE-2011-5046] The Graphics Device Interface (GDI) in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly validate user-mode input, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted data, as demonstrated by a large height attribute of an IFRAME element rendered by Safari, aka "GDI Access Violation Vulnerability."
18403| [CVE-2011-3414] The CaseInsensitiveHashProvider.getHashCode function in the HashTable implementation in the ASP.NET subsystem in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters, aka "Collisions in HashTable May Cause DoS Vulnerability."
18404| [CVE-2011-3406] Buffer overflow in Active Directory, Active Directory Application Mode (ADAM), and Active Directory Lightweight Directory Service (AD LDS) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote authenticated users to execute arbitrary code via a crafted query that leverages incorrect memory initialization, aka "Active Directory Buffer Overflow Vulnerability."
18405| [CVE-2011-3260] Buffer overflow in OfficeImport in Apple iOS before 5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Microsoft Word document.
18406| [CVE-2011-2014] The LDAP over SSL (aka LDAPS) implementation in Active Directory, Active Directory Application Mode (ADAM), and Active Directory Lightweight Directory Service (AD LDS) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not examine Certificate Revocation Lists (CRLs), which allows remote authenticated users to bypass intended certificate restrictions and access Active Directory resources by leveraging a revoked X.509 certificate for a domain account, aka "LDAPS Authentication Bypass Vulnerability."
18407| [CVE-2011-2012] Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 does not properly validate session cookies, which allows remote attackers to cause a denial of service (IIS outage) via unspecified network traffic, aka "Null Session Cookie Crash."
18408| [CVE-2011-2008] Microsoft Host Integration Server (HIS) 2004 SP1, 2006 SP1, 2009, and 2010 allows remote attackers to cause a denial of service (SNA Server service outage) via crafted TCP or UDP traffic, aka "Access of Unallocated Memory DoS Vulnerability."
18409| [CVE-2011-2007] Microsoft Host Integration Server (HIS) 2004 SP1, 2006 SP1, 2009, and 2010 allows remote attackers to cause a denial of service (SNA Server service outage) via crafted TCP or UDP traffic, aka "Endless Loop DoS in snabase.exe Vulnerability."
18410| [CVE-2011-2004] Array index error in win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows remote attackers to cause a denial of service (reboot) via a crafted TrueType font file, aka "TrueType Font Parsing Vulnerability," a different vulnerability than CVE-2011-3402.
18411| [CVE-2011-2002] win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle TrueType fonts, which allows local users to cause a denial of service (system hang) via a crafted font file, aka "Win32k TrueType Font Type Translation Vulnerability."
18412| [CVE-2011-1985] win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly validate user-mode input, which allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via a crafted application, aka "Win32k Null Pointer De-reference Vulnerability."
18413| [CVE-2011-1974] NDISTAPI.sys in the NDISTAPI driver in Remote Access Service (RAS) in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP2 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "NDISTAPI Elevation of Privilege Vulnerability."
18414| [CVE-2011-1971] The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly parse file metadata, which allows local users to cause a denial of service (reboot) via a crafted file, aka "Windows Kernel Metadata Parsing DOS Vulnerability."
18415| [CVE-2011-1970] The DNS server in Microsoft Windows Server 2003 SP2 and Windows Server 2008 SP2, R2, and R2 SP1 does not properly initialize memory, which allows remote attackers to cause a denial of service (service outage) via a query for a nonexistent domain, aka "DNS Uninitialized Memory Corruption Vulnerability."
18416| [CVE-2011-1968] The Remote Desktop Protocol (RDP) implementation in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP2 does not properly process packets in memory, which allows remote attackers to cause a denial of service (reboot) by sending crafted RDP packets triggering access to an object that (1) was not properly initialized or (2) is deleted, as exploited in the wild in 2011, aka "Remote Desktop Protocol Vulnerability."
18417| [CVE-2011-1965] Tcpip.sys in the TCP/IP stack in Microsoft Windows 7 Gold and SP1 and Windows Server 2008 R2 and R2 SP1 does not properly implement URL-based QoS, which allows remote attackers to cause a denial of service (reboot) via a crafted URL to a web server, aka "TCP/IP QOS Denial of Service Vulnerability."
18418| [CVE-2011-1893] Cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint Server 2010, Windows SharePoint Services 2.0 and 3.0 SP2, and SharePoint Foundation 2010 allows remote attackers to inject arbitrary web script or HTML via the URI, aka "SharePoint XSS Vulnerability."
18419| [CVE-2011-1892] Microsoft Office Groove 2007 SP2, SharePoint Workspace 2010 Gold and SP1, Office Forms Server 2007 SP2, Office SharePoint Server 2007 SP2, Office SharePoint Server 2010 Gold and SP1, Office Groove Data Bridge Server 2007 SP2, Office Groove Management Server 2007 SP2, Groove Server 2010 Gold and SP1, Windows SharePoint Services 3.0 SP2, SharePoint Foundation 2010, and Office Web Apps 2010 Gold and SP1 do not properly handle Web Parts containing XML classes referencing external entities, which allows remote authenticated users to read arbitrary files via a crafted XML and XSL file, aka "SharePoint Remote File Disclosure Vulnerability."
18420| [CVE-2011-1891] Cross-site scripting (XSS) vulnerability in Microsoft Windows SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and SP1, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters in a request to a script, aka "Contact Details Reflected XSS Vulnerability."
18421| [CVE-2011-1889] The NSPLookupServiceNext function in the client in Microsoft Forefront Threat Management Gateway (TMG) 2010 allows remote attackers to execute arbitrary code via vectors involving unspecified requests, aka "TMG Firewall Client Memory Corruption Vulnerability."
18422| [CVE-2011-1872] Hyper-V in Microsoft Windows Server 2008 Gold, SP2, R2, and R2 SP1 allows guest OS users to cause a denial of service (host OS infinite loop) via malformed machine instructions in a VMBus packet, aka "VMBus Persistent DoS Vulnerability."
18423| [CVE-2011-1871] Tcpip.sys in the TCP/IP stack in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to cause a denial of service (reboot) via a series of crafted ICMP messages, aka "ICMP Denial of Service Vulnerability."
18424| [CVE-2011-1870] Integer overflow in the Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, and Windows Server 2003 SP2, allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application that triggers an incorrect memory assignment for a user transaction, aka "CSRSS Local EOP SrvWriteConsoleOutputString Vulnerability."
18425| [CVE-2011-1869] The Distributed File System (DFS) implementation in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote DFS servers to cause a denial of service (system hang) via a crafted referral response, aka "DFS Referral Response Vulnerability."
18426| [CVE-2011-1845] Multiple memory leaks in the DataGrid control implementation in Microsoft Silverlight 4 before 4.0.60310.0 allow remote attackers to cause a denial of service (memory consumption) via an application involving (1) subscriptions to an INotifyDataErrorInfo.ErrorsChanged event or (2) a TextBlock or TextBox element.
18427| [CVE-2011-1844] Memory leak in Microsoft Silverlight 4 before 4.0.60310.0 allows remote attackers to cause a denial of service (memory consumption) via an application involving a popup control and a custom DependencyProperty property, related to lack of garbage collection.
18428| [CVE-2011-1652] ** DISPUTED ** The default configuration of Microsoft Windows 7 immediately prefers a new IPv6 and DHCPv6 service over a currently used IPv4 and DHCPv4 service upon receipt of an IPv6 Router Advertisement (RA), and does not provide an option to ignore an unexpected RA, which allows remote attackers to conduct man-in-the-middle attacks on communication with external IPv4 servers via vectors involving RAs, a DHCPv6 server, and NAT-PT on the local network, aka a "SLAAC Attack." NOTE: it can be argued that preferring IPv6 complies with RFC 3484, and that attempting to determine the legitimacy of an RA is currently outside the scope of recommended behavior of host operating systems.
18429| [CVE-2011-1417] Integer overflow in QuickLook, as used in Apple Mac OS X before 10.6.7 and MobileSafari in Apple iOS before 4.2.7 and 4.3.x before 4.3.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a Microsoft Office document with a crafted size field in the OfficeArtMetafileHeader, related to OfficeArtBlip, as demonstrated on the iPhone by Charlie Miller and Dion Blazakis during a Pwn2Own competition at CanSecWest 2011.
18430| [CVE-2011-1284] Integer overflow in the Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application that triggers an incorrect memory assignment for a user transaction, aka "CSRSS Local EOP SrvWriteConsoleOutput Vulnerability."
18431| [CVE-2011-1283] The Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, and Windows Server 2008 Gold and SP2 does not ensure that an unspecified array index has a non-negative value before performing read and write operations, which allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application that triggers an incorrect memory assignment for a user transaction, aka "CSRSS Local EOP SrvSetConsoleNumberOfCommand Vulnerability."
18432| [CVE-2011-1282] The Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly initialize memory and consequently uses a NULL pointer in an unspecified function call, which allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application that triggers an incorrect memory assignment for a user transaction, aka "CSRSS Local EOP SrvSetConsoleLocalEUDC Vulnerability."
18433| [CVE-2011-1281] The Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly restrict the number of console objects for a process, which allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application that triggers an incorrect memory assignment for a user transaction, aka "CSRSS Local EOP AllocConsole Vulnerability."
18434| [CVE-2011-1279] Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information during parsing of Excel spreadsheets, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted spreadsheet, aka "Excel Out of Bounds WriteAV Vulnerability."
18435| [CVE-2011-1278] Microsoft Excel 2002 SP3 and Office 2004 for Mac do not properly validate record information during parsing of Excel spreadsheets, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted spreadsheet, aka "Excel WriteAV Vulnerability."
18436| [CVE-2011-1277] Microsoft Excel 2002 SP3, Office 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information during parsing of Excel spreadsheets, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted spreadsheet, aka "Excel Memory Corruption Vulnerability."
18437| [CVE-2011-1267] The SMB server in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to cause a denial of service (system hang) via a crafted (1) SMBv1 or (2) SMBv2 request, aka "SMB Request Parsing Vulnerability."
18438| [CVE-2011-1264] Cross-site scripting (XSS) vulnerability in Active Directory Certificate Services Web Enrollment in Microsoft Windows Server 2003 SP2 and Server 2008 Gold, SP2, R2, and R2 SP1 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka "Active Directory Certificate Services Vulnerability."
18439| [CVE-2011-1257] Race condition in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors involving access to an object, aka "Window Open Race Condition Vulnerability."
18440| [CVE-2011-1252] Cross-site scripting (XSS) vulnerability in the SafeHTML function in the toStaticHTML API in Microsoft Internet Explorer 7 and 8, Office SharePoint Server 2007 SP2, Office SharePoint Server 2010 Gold and SP1, Groove Server 2010 Gold and SP1, Windows SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via unspecified strings, aka "toStaticHTML Information Disclosure Vulnerability" or "HTML Sanitization Vulnerability."
18441| [CVE-2011-1248] WINS in Microsoft Windows Server 2003 SP2 and Server 2008 Gold, SP2, R2, and R2 SP1 does not properly handle socket send exceptions, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted packets, related to unintended stack-frame values and buffer passing, aka "WINS Service Failed Response Vulnerability."
18442| [CVE-2011-0661] The SMB Server service in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly validate fields in SMB requests, which allows remote attackers to execute arbitrary code via a malformed request in a (1) SMBv1 or (2) SMBv2 packet, aka "SMB Transaction Parsing Vulnerability."
18443| [CVE-2011-0654] Integer underflow in the BowserWriteErrorLogEntry function in the Common Internet File System (CIFS) browser service in Mrxsmb.sys or bowser.sys in Active Directory in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code or cause a denial of service (system crash) via a malformed BROWSER ELECTION message, leading to a heap-based buffer overflow, aka "Browser Pool Corruption Vulnerability." NOTE: some of these details are obtained from third party information.
18444| [CVE-2011-0647] The irccd.exe service in EMC Replication Manager Client before 5.3 and NetWorker Module for Microsoft Applications 2.1.x and 2.2.x allows remote attackers to execute arbitrary commands via the RunProgram function to TCP port 6542.
18445| [CVE-2011-0627] Adobe Flash Player before 10.3.181.14 on Windows, Mac OS X, Linux, and Solaris and before 10.3.185.21 on Android allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content, as possibly exploited in the wild in May 2011 by a Microsoft Office document with an embedded .swf file.
18446| [CVE-2011-0346] Use-after-free vulnerability in the ReleaseInterface function in MSHTML.DLL in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to the DOM implementation and the BreakAASpecial and BreakCircularMemoryReferences functions, as demonstrated by cross_fuzz, aka "MSHTML Memory Corruption Vulnerability."
18447| [CVE-2011-0290] The BlackBerry Collaboration Service in Research In Motion (RIM) BlackBerry Enterprise Server (BES) 5.0.3 through MR4 for Microsoft Exchange and Lotus Domino allows remote authenticated users to log into arbitrary user accounts associated with the same organization, and send messages, read messages, read contact lists, or cause a denial of service (login unavailability), via unspecified vectors.
18448| [CVE-2011-0208] QuickLook in Apple Mac OS X 10.6 before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Microsoft Office document.
18449| [CVE-2011-0104] Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted HLink record in an Excel file, aka "Excel Buffer Overwrite Vulnerability."
18450| [CVE-2011-0103] Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted record information in an Excel file, aka "Excel Memory Corruption Vulnerability."
18451| [CVE-2011-0101] Microsoft Excel 2002 SP3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted RealTimeData record, related to a stTopic field, doubly-byte characters, and an incorrect pointer calculation, aka "Excel Record Parsing WriteAV Vulnerability."
18452| [CVE-2011-0043] Kerberos in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 supports weak hashing algorithms, which allows local users to gain privileges by operating a service that sends crafted service tickets, as demonstrated by the CRC32 algorithm, aka "Kerberos Unkeyed Checksum Vulnerability."
18453| [CVE-2011-0040] The server in Microsoft Active Directory on Windows Server 2003 SP2 does not properly handle an update request for a service principal name (SPN), which allows remote attackers to cause a denial of service (authentication downgrade or outage) via a crafted request that triggers name collisions, aka "Active Directory SPN Validation Vulnerability."
18454| [CVE-2011-0039] The Local Security Authority Subsystem Service (LSASS) in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly process authentication requests, which allows local users to gain privileges via a request with a crafted length, aka "LSASS Length Validation Vulnerability."
18455| [CVE-2010-4701] Heap-based buffer overflow in the CDrawPoly::Serialize function in fxscover.exe in Microsoft Windows Fax Services Cover Page Editor 5.2 r2 in Windows XP Professional SP3, Server 2003 R2 Enterprise Edition SP2, and Windows 7 Professional allows remote attackers to execute arbitrary code via a long record in a Fax Cover Page (.cov) file. NOTE: some of these details are obtained from third party information.
18456| [CVE-2010-4669] The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Microsoft Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, and Windows 7 allows remote attackers to cause a denial of service (CPU consumption and system hang) by sending many Router Advertisement (RA) messages with different source addresses, as demonstrated by the flood_router6 program in the thc-ipv6 package.
18457| [CVE-2010-4643] Heap-based buffer overflow in Impress in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Truevision TGA (TARGA) file in an ODF or Microsoft Office document.
18458| [CVE-2010-4253] Heap-based buffer overflow in Impress in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file in an ODF or Microsoft Office document, as demonstrated by a PowerPoint (aka PPT) document.
18459| [CVE-2010-3972] Heap-based buffer overflow in the TELNET_STREAM_CONTEXT::OnSendData function in ftpsvc.dll in Microsoft FTP Service 7.0 and 7.5 for Internet Information Services (IIS) 7.0, and IIS 7.5, allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a crafted FTP command, aka "IIS FTP Service Heap Buffer Overrun Vulnerability." NOTE: some of these details are obtained from third party information.
18460| [CVE-2010-3971] Use-after-free vulnerability in the CSharedStyleSheet::Notify function in the Cascading Style Sheets (CSS) parser in mshtml.dll, as used in Microsoft Internet Explorer 6 through 8 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a self-referential @import rule in a stylesheet, aka "CSS Memory Corruption Vulnerability."
18461| [CVE-2010-3964] Unrestricted file upload vulnerability in the Document Conversions Launcher Service in Microsoft Office SharePoint Server 2007 SP2, when the Document Conversions Load Balancer Service is enabled, allows remote attackers to execute arbitrary code via a crafted SOAP request to TCP port 8082, aka "Malformed Request Code Execution Vulnerability."
18462| [CVE-2010-3963] Buffer overflow in the Routing and Remote Access NDProxy component in the kernel in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a crafted application, related to the Routing and Remote Access service (RRAS) and improper copying from user mode to the kernel, aka "Kernel NDProxy Buffer Overflow Vulnerability."
18463| [CVE-2010-3960] Hyper-V in Microsoft Windows Server 2008 Gold, SP2, and R2 allows guest OS users to cause a denial of service (host OS hang) by sending a crafted encapsulated packet over the VMBus, aka "Hyper-V VMBus Vulnerability."
18464| [CVE-2010-3954] Microsoft Publisher 2002 SP3, 2003 SP3, and 2010 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Publisher file, aka "Microsoft Publisher Memory Corruption Vulnerability."
18465| [CVE-2010-3952] The FlashPix image converter in the graphics filters in Microsoft Office XP SP3 and Office Converter Pack allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted FlashPix image in an Office document, aka "FlashPix Image Converter Heap Corruption Vulnerability."
18466| [CVE-2010-3950] The TIFF image converter in the graphics filters in Microsoft Office XP SP3, Office Converter Pack, and Works 9 does not properly convert data, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted TIFF image in an Office document, aka "TIFF Image Converter Memory Corruption Vulnerability."
18467| [CVE-2010-3937] Microsoft Exchange Server 2007 SP2 on the x64 platform allows remote authenticated users to cause a denial of service (infinite loop and MSExchangeIS outage) via a crafted RPC request, aka "Exchange Server Infinite Loop Vulnerability."
18468| [CVE-2010-3785] Buffer overflow in QuickLook in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Microsoft Office document.
18469| [CVE-2010-3454] Multiple off-by-one errors in the WW8DopTypography::ReadFromMem function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted typography information in a Microsoft Word .DOC file that triggers an out-of-bounds write.
18470| [CVE-2010-3453] The WW8ListManager::WW8ListManager function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 does not properly handle an unspecified number of list levels in user-defined list styles in WW8 data in a Microsoft Word document, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted .DOC file that triggers an out-of-bounds write.
18471| [CVE-2010-3332] Microsoft .NET Framework 1.1 SP1, 2.0 SP1 and SP2, 3.5, 3.5 SP1, 3.5.1, and 4.0, as used for ASP.NET in Microsoft Internet Information Services (IIS), provides detailed error codes during decryption attempts, which allows remote attackers to decrypt and modify encrypted View State (aka __VIEWSTATE) form data, and possibly forge cookies or read application files, via a padding oracle attack, aka "ASP.NET Padding Oracle Vulnerability."
18472| [CVE-2010-3324] The toStaticHTML function in Microsoft Internet Explorer 8, and the SafeHTML function in Microsoft Windows SharePoint Services 3.0 SP2, SharePoint Foundation 2010, Office SharePoint Server 2007 SP2, Groove Server 2010, and Office Web Apps, allows remote attackers to bypass the cross-site scripting (XSS) protection mechanism and conduct XSS attacks via a crafted use of the Cascading Style Sheets (CSS) @import rule, aka "HTML Sanitization Vulnerability," a different vulnerability than CVE-2010-1257.
18473| [CVE-2010-3243] Cross-site scripting (XSS) vulnerability in the toStaticHTML function in Microsoft Internet Explorer 8, and the SafeHTML function in Microsoft Windows SharePoint Services 3.0 SP2 and Office SharePoint Server 2007 SP2, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "HTML Sanitization Vulnerability."
18474| [CVE-2010-3229] The Secure Channel (aka SChannel) security package in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, when IIS 7.x is used, does not properly process client certificates during SSL and TLS handshakes, which allows remote attackers to cause a denial of service (LSASS outage and reboot) via a crafted packet, aka "TLSv1 Denial of Service Vulnerability."
18475| [CVE-2010-3225] Use-after-free vulnerability in the Media Player Network Sharing Service in Microsoft Windows Vista SP1 and SP2 and Windows 7 allows remote attackers to execute arbitrary code via a crafted Real Time Streaming Protocol (RTSP) packet, aka "RTSP Use After Free Vulnerability."
18476| [CVE-2010-3223] The user interface in Microsoft Cluster Service (MSCS) in Microsoft Windows Server 2008 R2 does not properly set administrative-share permissions for new cluster disks that are shared as part of a failover cluster, which allows remote attackers to read or modify data on these disks via requests to the associated share, aka "Permissions on New Cluster Disks Vulnerability."
18477| [CVE-2010-3200] MSO.dll in Microsoft Word 2003 SP3 11.8326.11.8324 allows remote attackers to cause a denial of service (NULL pointer dereference and multiple-instance application crash) via a crafted buffer in a Word document, as demonstrated by word_crash_11.8326.8324_poc.doc.
18478| [CVE-2010-2742] The Netlogon RPC Service in Microsoft Windows Server 2003 SP2 and Server 2008 Gold, SP2, and R2, when the domain controller role is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and reboot) via a crafted RPC packet, aka "Netlogon RPC Null dereference DOS Vulnerability."
18479| [CVE-2010-2739] Buffer overflow in the CreateDIBPalette function in win32k.sys in Microsoft Windows XP SP3, Server 2003 R2 Enterprise SP2, Vista Business SP1, Windows 7, and Server 2008 SP2 allows local users to cause a denial of service (crash) and possibly execute arbitrary code by performing a clipboard operation (GetClipboardData API function) with a crafted bitmap with a palette that contains a large number of colors.
18480| [CVE-2010-2731] Unspecified vulnerability in Microsoft Internet Information Services (IIS) 5.1 on Windows XP SP3, when directory-based Basic Authentication is enabled, allows remote attackers to bypass intended access restrictions and execute ASP files via a crafted request, aka "Directory Authentication Bypass Vulnerability."
18481| [CVE-2010-2730] Buffer overflow in Microsoft Internet Information Services (IIS) 7.5, when FastCGI is enabled, allows remote attackers to execute arbitrary code via crafted headers in a request, aka "Request Header Buffer Overflow Vulnerability."
18482| [CVE-2010-2729] The Print Spooler service in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, when printer sharing is enabled, does not properly validate spooler access permissions, which allows remote attackers to create files in a system directory, and consequently execute arbitrary code, by sending a crafted print request over RPC, as exploited in the wild in September 2010, aka "Print Spooler Service Impersonation Vulnerability."
18483| [CVE-2010-2569] pubconv.dll (aka the Publisher Converter DLL) in Microsoft Publisher 2002 SP3, 2003 SP3, and 2007 SP2 does not properly handle an unspecified size field in certain older file formats, which allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted Publisher file, aka "Size Value Heap Corruption in pubconv.dll Vulnerability."
18484| [CVE-2010-2564] Buffer overflow in Microsoft Windows Movie Maker (WMM) 2.1, 2.6, and 6.0 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted project file, aka "Movie Maker Memory Corruption Vulnerability."
18485| [CVE-2010-2562] Microsoft Office Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Excel file, aka "Excel Memory Corruption Vulnerability."
18486| [CVE-2010-2561] Microsoft XML Core Services (aka MSXML) 3.0 does not properly handle HTTP responses, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted response, aka "Msxml2.XMLHTTP.3.0 Response Handling Memory Corruption Vulnerability."
18487| [CVE-2010-2558] Race condition in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors related to an object in memory, aka "Race Condition Memory Corruption Vulnerability."
18488| [CVE-2010-2555] The Tracing Feature for Services in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly determine the length of strings in the registry, which allows local users to gain privileges or cause a denial of service (memory corruption) via vectors involving a long string, aka "Tracing Memory Corruption Vulnerability."
18489| [CVE-2010-2554] The Tracing Feature for Services in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 has incorrect ACLs on its registry keys, which allows local users to gain privileges via vectors involving a named pipe and impersonation, aka "Tracing Registry Key ACL Vulnerability."
18490| [CVE-2010-2552] Stack consumption vulnerability in the SMB Server in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows remote attackers to cause a denial of service (system hang) via a malformed SMBv2 compounded request, aka "SMB Stack Exhaustion Vulnerability."
18491| [CVE-2010-2551] The SMB Server in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate an internal variable in an SMB packet, which allows remote attackers to cause a denial of service (system hang) via a crafted (1) SMBv1 or (2) SMBv2 packet, aka "SMB Variable Validation Vulnerability."
18492| [CVE-2010-2549] Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Vista SP1 and SP2 and Server 2008 Gold and SP2 allows local users to gain privileges or cause a denial of service (system crash) by using a large number of calls to the NtUserCheckAccessForIntegrityLevel function to trigger a failure in the LockProcessByClientId function, leading to deletion of an in-use process object, aka "Win32k Reference Count Vulnerability."
18493| [CVE-2010-2119] Microsoft Internet Explorer 6.0.2900.2180 allows remote attackers to cause a denial of service (resource consumption) via JavaScript code containing an infinite loop that creates IFRAME elements for invalid nntp:// URIs.
18494| [CVE-2010-2118] Microsoft Internet Explorer 6.0.2900.2180 and 8.0.7600.16385 allows remote attackers to cause a denial of service (resource consumption) via JavaScript code containing an infinite loop that creates IFRAME elements for invalid news:// URIs.
18495| [CVE-2010-1991] Microsoft Internet Explorer 6.0.2900.2180, 7, and 8.0.7600.16385 executes a mail application in situations where an IFRAME element has a mailto: URL in its SRC attribute, which allows remote attackers to cause a denial of service (excessive application launches) via an HTML document with many IFRAME elements.
18496| [CVE-2010-1903] Microsoft Office Word 2002 SP3 and 2003 SP3, and Office Word Viewer, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a malformed record in a Word file, aka "Word HTML Linked Objects Memory Corruption Vulnerability."
18497| [CVE-2010-1899] Stack consumption vulnerability in the ASP implementation in Microsoft Internet Information Services (IIS) 5.1, 6.0, 7.0, and 7.5 allows remote attackers to cause a denial of service (daemon outage) via a crafted request, related to asp.dll, aka "IIS Repeated Parameter Request Denial of Service Vulnerability."
18498| [CVE-2010-1892] The TCP/IP stack in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly handle malformed IPv6 packets, which allows remote attackers to cause a denial of service (system hang) via multiple crafted packets, aka "IPv6 Memory Corruption Vulnerability."
18499| [CVE-2010-1890] The kernel in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate ACLs on kernel objects, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Improper Validation Vulnerability."
18500| [CVE-2010-1887] The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 do not properly validate an unspecified system-call argument, which allows local users to cause a denial of service (system hang) via a crafted application, aka "Win32k Bounds Checking Vulnerability."
18501| [CVE-2010-1886] Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 SP2 and R2, and Windows 7 allow local users to gain privileges by leveraging access to a process with NetworkService credentials, as demonstrated by TAPI Server, SQL Server, and IIS processes, and related to the Windows Service Isolation feature. NOTE: the vendor states that privilege escalation from NetworkService to LocalSystem does not cross a "security boundary."
18502| [CVE-2010-1881] The FieldList ActiveX control in the Microsoft Access Wizard Controls in ACCWIZ.dll in Microsoft Office Access 2003 SP3 does not properly interact with the memory-access approach used by Internet Explorer and Office during instantiation, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via an HTML document that references this control along with crafted persistent storage data, aka "ACCWIZ.dll Uninitialized Variable Vulnerability."
18503| [CVE-2010-1847] The kernel in Apple Mac OS X 10.6.x before 10.6.5 does not properly perform memory management associated with terminal devices, which allows local users to cause a denial of service (system crash) via unspecified vectors.
18504| [CVE-2010-1735] The SfnLOGONNOTIFY function in win32k.sys in the kernel in Microsoft Windows 2000, XP, and Server 2003 allows local users to cause a denial of service (system crash) via a 0x4c value in the second argument (aka the Msg argument) of a PostMessage function call for the DDEMLEvent window.
18505| [CVE-2010-1734] The SfnINSTRING function in win32k.sys in the kernel in Microsoft Windows 2000, XP, and Server 2003 allows local users to cause a denial of service (system crash) via a 0x18d value in the second argument (aka the Msg argument) of a PostMessage function call for the DDEMLEvent window.
18506| [CVE-2010-1264] Unspecified vulnerability in Microsoft Windows SharePoint Services 3.0 SP1 and SP2 allows remote attackers to cause a denial of service (hang) via crafted requests to the Help page that cause repeated restarts of the application pool, aka "Sharepoint Help Page Denial of Service Vulnerability."
18507| [CVE-2010-1127] Microsoft Internet Explorer 6 and 7 does not initialize certain data structures during execution of the createElement method, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted JavaScript code, as demonstrated by setting the (1) outerHTML or (2) value property of an object returned by createElement.
18508| [CVE-2010-1098] The ANI parser in Microsoft Windows before 7 on the x86 platform, as used in Internet Explorer and other applications, allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted biClrUsed value in the BITMAPINFO header of a .ANI file.
18509| [CVE-2010-1042] Microsoft Windows Media Player 11 does not properly perform colorspace conversion, which allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted .AVI file. NOTE: the provenance of this information is unknown
18510| [CVE-2010-0820] Heap-based buffer overflow in the Local Security Authority Subsystem Service (LSASS), as used in Active Directory in Microsoft Windows Server 2003 SP2 and Windows Server 2008 Gold, SP2, and R2
18511| [CVE-2010-0817] Cross-site scripting (XSS) vulnerability in _layouts/help.aspx in Microsoft SharePoint Server 2007 12.0.0.6421 and possibly earlier, and SharePoint Services 3.0 SP1 and SP2, versions, allows remote attackers to inject arbitrary web script or HTML via the cid0 parameter.
18512| [CVE-2010-0810] The kernel in Microsoft Windows Vista Gold, SP1, and SP2, and Windows Server 2008 Gold and SP2, does not properly handle unspecified exceptions, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Exception Handler Vulnerability."
18513| [CVE-2010-0719] An unspecified API in Microsoft Windows 2000, Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, and Windows 7 does not validate arguments, which allows local users to cause a denial of service (system crash) via a crafted application.
18514| [CVE-2010-0718] Buffer overflow in Microsoft Windows Media Player 9 and 11.0.5721.5145 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted .mpg file.
18515| [CVE-2010-0482] The kernel in Microsoft Windows Server 2008 R2 and Windows 7 does not properly validate relocation sections of image files, which allows local users to cause a denial of service (reboot) via a crafted file, aka "Windows Kernel Malformed Image Vulnerability."
18516| [CVE-2010-0481] The kernel in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly translate a registry key's virtual path to its real path, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Virtual Path Parsing Vulnerability."
18517| [CVE-2010-0478] Stack-based buffer overflow in nsum.exe in the Windows Media Unicast Service in Media Services for Microsoft Windows 2000 Server SP4 allows remote attackers to execute arbitrary code via crafted packets associated with transport information, aka "Media Services Stack-based Buffer Overflow Vulnerability."
18518| [CVE-2010-0476] The SMB client in Microsoft Windows Server 2003 SP2, Vista Gold, SP1, and SP2, and Windows Server 2008 Gold and SP2 allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and reboot) via a crafted SMB transaction response that uses (1) SMBv1 or (2) SMBv2, aka "SMB Client Response Parsing Vulnerability."
18519| [CVE-2010-0278] A certain ActiveX control in msgsc.14.0.8089.726.dll in Microsoft Windows Live Messenger 2009 build 14.0.8089.726 on Windows Vista and Windows 7 allows remote attackers to cause a denial of service (msnmsgr.exe crash) by calling the ViewProfile method with a crafted argument during an MSN Messenger session.
18520| [CVE-2010-0270] The SMB client in Microsoft Windows Server 2008 R2 and Windows 7 does not properly validate fields in SMB transaction responses, which allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and reboot) via a crafted (1) SMBv1 or (2) SMBv2 response, aka "SMB Client Transaction Vulnerability."
18521| [CVE-2010-0242] The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 allows remote attackers to cause a denial of service (system hang) via crafted packets with malformed TCP selective acknowledgement (SACK) values, aka "TCP/IP Selective Acknowledgement Vulnerability."
18522| [CVE-2010-0238] Unspecified vulnerability in registry-key validation in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Vista Gold allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Registry Key Vulnerability."
18523| [CVE-2010-0235] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Vista Gold does not perform the expected validation before creating a symbolic link, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Symbolic Link Value Vulnerability."
18524| [CVE-2010-0234] The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 does not properly validate a registry-key argument to an unspecified system call, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Null Pointer Vulnerability."
18525| [CVE-2010-0231] The SMB implementation in the Server service in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not use a sufficient source of entropy, which allows remote attackers to obtain access to files and other SMB resources via a large number of authentication requests, related to server-generated challenges, certain "duplicate values," and spoofing of an authentication token, aka "SMB NTLM Authentication Lack of Entropy Vulnerability."
18526| [CVE-2010-0035] The Key Distribution Center (KDC) in Kerberos in Microsoft Windows 2000 SP4, Server 2003 SP2, and Server 2008 Gold and SP2, when a trust relationship with a non-Windows Kerberos realm exists, allows remote authenticated users to cause a denial of service (NULL pointer dereference and domain controller outage) via a crafted Ticket Granting Ticket (TGT) renewal request, aka "Kerberos Null Pointer Dereference Vulnerability."
18527| [CVE-2010-0026] The Hyper-V server implementation in Microsoft Windows Server 2008 Gold, SP2, and R2 on the x64 platform allows guest OS users to cause a denial of service (host OS hang) via a crafted application that executes a malformed series of machine instructions, aka "Hyper-V Instruction Set Validation Vulnerability."
18528| [CVE-2010-0024] The SMTP component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Server 2008 Gold, SP2, and R2, and Exchange Server 2003 SP2, does not properly parse MX records, which allows remote DNS servers to cause a denial of service (service outage) via a crafted response to a DNS MX record query, aka "SMTP Server MX Record Vulnerability."
18529| [CVE-2010-0022] The SMB implementation in the Server service in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate the share and servername fields in SMB packets, which allows remote attackers to cause a denial of service (system hang) via a crafted packet, aka "SMB Null Pointer Vulnerability."
18530| [CVE-2010-0021] Multiple race conditions in the SMB implementation in the Server service in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allow remote attackers to cause a denial of service (system hang) via a crafted (1) SMBv1 or (2) SMBv2 Negotiate packet, aka "SMB Memory Corruption Vulnerability."
18531| [CVE-2010-0020] The SMB implementation in the Server service in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate request fields, which allows remote authenticated users to execute arbitrary code via a malformed request, aka "SMB Pathname Overflow Vulnerability."
18532| [CVE-2010-0019] Microsoft Silverlight 3 before 3.0.50611.0 on Windows, and before 3.0.41130.0 on Mac OS X, does not properly handle pointers, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and framework outage) via a crafted web site, aka "Microsoft Silverlight Memory Corruption Vulnerability."
18533| [CVE-2009-4445] Microsoft Internet Information Services (IIS), when used in conjunction with unspecified third-party upload applications, allows remote attackers to create empty files with arbitrary extensions via a filename containing an initial extension followed by a : (colon) and a safe extension, as demonstrated by an upload of a .asp:.jpg file that results in creation of an empty .asp file, related to support for the NTFS Alternate Data Streams (ADS) filename syntax. NOTE: it could be argued that this is a vulnerability in the third-party product, not IIS, because the third-party product should be applying its extension restrictions to the portion of the filename before the colon.
18534| [CVE-2009-4444] Microsoft Internet Information Services (IIS) 5.x and 6.x uses only the portion of a filename before a
18535| [CVE-2009-4313] ir32_32.dll 3.24.15.3 in the Indeo32 codec in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to cause a denial of service (heap corruption) or execute arbitrary code via malformed data in a stream in a media file, as demonstrated by an AVI file.
18536| [CVE-2009-4210] The Indeo codec in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via crafted media content.
18537| [CVE-2009-3943] Microsoft Internet Explorer 6 through 6.0.2900.2180 and 7 through 7.0.6000.16711 allows remote attackers to cause a denial of service (application hang) via a JavaScript loop that configures the home page by using the setHomePage method and a DHTML behavior property.
18538| [CVE-2009-3830] The download functionality in Team Services in Microsoft Office SharePoint Server 2007 12.0.0.4518 and 12.0.0.6219 allows remote attackers to read ASP.NET source code via pathnames in the SourceUrl and Source parameters to _layouts/download.aspx.
18539| [CVE-2009-3678] Integer overflow in cdd.dll in the Canonical Display Driver (CDD) in Microsoft Windows Server 2008 R2 and Windows 7 on 64-bit platforms, when the Windows Aero theme is installed, allows context-dependent attackers to cause a denial of service (reboot) or possibly execute arbitrary code via a crafted image file that triggers incorrect data parsing after user-mode data is copied to kernel mode, as demonstrated using "Browse with Irfanview" and certain actions on a folder containing a large number of thumbnail images in Resample mode, possibly related to the ATI graphics driver or win32k.sys, aka "Canonical Display Driver Integer Overflow Vulnerability."
18540| [CVE-2009-3677] The Internet Authentication Service (IAS) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold and SP1, and Server 2008 Gold does not properly verify the credentials in an MS-CHAP v2 Protected Extensible Authentication Protocol (PEAP) authentication request, which allows remote attackers to access network resources via a malformed request, aka "MS-CHAP Authentication Bypass Vulnerability."
18541| [CVE-2009-3676] The SMB client in the kernel in Microsoft Windows Server 2008 R2 and Windows 7 allows remote SMB servers and man-in-the-middle attackers to cause a denial of service (infinite loop and system hang) via a (1) SMBv1 or (2) SMBv2 response packet that contains (a) an incorrect length value in a NetBIOS header or (b) an additional length field at the end of this response packet, aka "SMB Client Incomplete Response Vulnerability."
18542| [CVE-2009-3675] LSASS.exe in the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote authenticated users to cause a denial of service (CPU consumption) via a malformed ISAKMP request over IPsec, aka "Local Security Authority Subsystem Service Resource Exhaustion Vulnerability."
18543| [CVE-2009-3555] The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate renegotiation handshakes with an existing connection, which allows man-in-the-middle attackers to insert data into HTTPS sessions, and possibly other types of sessions protected by TLS or SSL, by sending an unauthenticated request that is processed retroactively by a server in a post-renegotiation context, related to a "plaintext injection" attack, aka the "Project Mogul" issue.
18544| [CVE-2009-3294] The popen API function in TSRM/tsrm_win32.c in PHP before 5.2.11 and 5.3.x before 5.3.1, when running on certain Windows operating systems, allows context-dependent attackers to cause a denial of service (crash) via a crafted (1) "e" or (2) "er" string in the second argument (aka mode), possibly related to the _fdopen function in the Microsoft C runtime library. NOTE: this might not cross privilege boundaries except in rare cases in which the mode argument is accessible to an attacker outside of an application that uses the popen function.
18545| [CVE-2009-3275] Blocks/Common/Src/Configuration/Manageability/Adm/AdmContentBuilder.cs in Microsoft patterns & practices Enterprise Library (aka EntLib) allows context-dependent attackers to cause a denial of service (CPU consumption) via an input string composed of many \ (backslash) characters followed by a " (double quote), related to a certain regular expression, aka a "ReDoS" vulnerability.
18546| [CVE-2009-3270] Microsoft Internet Explorer 7 through 7.0.6000.16711 allows remote attackers to cause a denial of service (unusable browser) by calling the window.print function in a loop, aka a "printing DoS attack," possibly a related issue to CVE-2009-0821.
18547| [CVE-2009-3267] Microsoft Internet Explorer 6 through 6.0.2900.2180, and 7.0.6000.16711, allows remote attackers to cause a denial of service (CPU consumption) via an automatically submitted form containing a KEYGEN element, a related issue to CVE-2009-1828.
18548| [CVE-2009-3126] Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a crafted PNG image file, aka "GDI+ PNG Integer Overflow Vulnerability."
18549| [CVE-2009-3103] Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, and Windows 7 RC allows remote attackers to execute arbitrary code or cause a denial of service (system crash) via an & (ampersand) character in a Process ID High header field in a NEGOTIATE PROTOCOL REQUEST packet, which triggers an attempted dereference of an out-of-bounds memory location, aka "SMBv2 Negotiation Vulnerability." NOTE: some of these details are obtained from third party information.
18550| [CVE-2009-3043] The tty_ldisc_hangup function in drivers/char/tty_ldisc.c in the Linux kernel 2.6.31-rc before 2.6.31-rc8 allows local users to cause a denial of service (system crash, sometimes preceded by a NULL pointer dereference) or possibly gain privileges via certain pseudo-terminal I/O activity, as demonstrated by KernelTtyTest.c.
18551| [CVE-2009-3023] Buffer overflow in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 6.0 allows remote authenticated users to execute arbitrary code via a crafted NLST (NAME LIST) command that uses wildcards, leading to memory corruption, aka "IIS FTP Service RCE and DoS Vulnerability."
18552| [CVE-2009-3020] win32k.sys in Microsoft Windows Server 2003 SP2 allows remote attackers to cause a denial of service (system crash) by referencing a crafted .eot file in the src descriptor of an @font-face Cascading Style Sheets (CSS) rule in an HTML document, possibly related to the Embedded OpenType (EOT) Font Engine, a different vulnerability than CVE-2006-0010, CVE-2009-0231, and CVE-2009-0232. NOTE: some of these details are obtained from third party information.
18553| [CVE-2009-3019] Microsoft Internet Explorer 6 on Windows XP SP2 and SP3, and Internet Explorer 7 on Vista, allows remote attackers to cause a denial of service (application crash) via JavaScript code that calls createElement to create an instance of the LI element, and then calls setAttribute to set the value attribute.
18554| [CVE-2009-2954] Microsoft Internet Explorer 6.0.2900.2180 and earlier allows remote attackers to cause a denial of service (CPU consumption and application hang) via JavaScript code with a long string value for the hash property (aka location.hash), a related issue to CVE-2008-5715.
18555| [CVE-2009-2838] Integer overflow in QuickLook in Apple Mac OS X 10.5.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Microsoft Office document that triggers a buffer overflow.
18556| [CVE-2009-2764] Microsoft Internet Explorer 8.0.7100.0 on Windows 7 RC on the x64 platform allows remote attackers to cause a denial of service (application crash) via a certain DIV element in conjunction with SCRIPT elements that have empty contents and no reference to a valid external script location.
18557| [CVE-2009-2668] Microsoft Internet Explorer 6 through 6.0.2900.2180 and 7 through 7.0.6000.16473 allows remote attackers to cause a denial of service (CPU consumption) via an XML document composed of a long series of start-tags with no corresponding end-tags, a related issue to CVE-2009-1232.
18558| [CVE-2009-2655] mshtml.dll in Microsoft Internet Explorer 7 and 8 on Windows XP SP3 allows remote attackers to cause a denial of service (application crash) by calling the JavaScript findText method with a crafted Unicode string in the first argument, and only one additional argument, as demonstrated by a second argument of -1.
18559| [CVE-2009-2576] Microsoft Internet Explorer 6.0.2900.2180 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via a long Unicode string argument to the write method, a related issue to CVE-2009-2479. NOTE: it was later reported that 7.0.6000.16473 and earlier are also affected.
18560| [CVE-2009-2536] Microsoft Internet Explorer 5 through 8 allows remote attackers to cause a denial of service (memory consumption and application crash) via a large integer value for the length property of a Select object, a related issue to CVE-2009-1692.
18561| [CVE-2009-2532] Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, and Windows 7 RC do not properly process the command value in an SMB Multi-Protocol Negotiate Request packet, which allows remote attackers to execute arbitrary code via a crafted SMBv2 packet to the Server service, aka "SMBv2 Command Value Vulnerability."
18562| [CVE-2009-2526] Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 do not properly validate fields in SMBv2 packets, which allows remote attackers to cause a denial of service (infinite loop and system hang) via a crafted packet to the Server service, aka "SMBv2 Infinite Loop Vulnerability."
18563| [CVE-2009-2524] Integer underflow in the NTLM authentication feature in the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows remote attackers to cause a denial of service (reboot) via a malformed packet, aka "Local Security Authority Subsystem Service Integer Overflow Vulnerability."
18564| [CVE-2009-2521] Stack consumption vulnerability in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 7.0 allows remote authenticated users to cause a denial of service (daemon crash) via a list (ls) -R command containing a wildcard that references a subdirectory, followed by a .. (dot dot), aka "IIS FTP Service DoS Vulnerability."
18565| [CVE-2009-2517] The kernel in Microsoft Windows Server 2003 SP2 does not properly handle unspecified exceptions when an error condition occurs, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Exception Handler Vulnerability."
18566| [CVE-2009-2509] Active Directory Federation Services (ADFS) in Microsoft Windows Server 2003 SP2 and Server 2008 Gold and SP2 does not properly validate headers in HTTP requests, which allows remote authenticated users to execute arbitrary code via a crafted request to an IIS web server, aka "Remote Code Execution in ADFS Vulnerability."
18567| [CVE-2009-2508] The single sign-on implementation in Active Directory Federation Services (ADFS) in Microsoft Windows Server 2003 SP2 and Server 2008 Gold and SP2 does not properly remove credentials at the end of a network session, which allows physically proximate attackers to obtain the credentials of a previous user of the same web browser by using data from the browser's cache, aka "Single Sign On Spoofing in ADFS Vulnerability."
18568| [CVE-2009-2507] A certain ActiveX control in the Indexing Service in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly process URLs, which allows remote attackers to execute arbitrary programs via unspecified vectors that cause a "vulnerable binary" to load and run, aka "Memory Corruption in Indexing Service Vulnerability."
18569| [CVE-2009-2505] The Internet Authentication Service (IAS) in Microsoft Windows Vista SP2 and Server 2008 SP2 does not properly validate MS-CHAP v2 Protected Extensible Authentication Protocol (PEAP) authentication requests, which allows remote attackers to execute arbitrary code via crafted structures in a malformed request, aka "Internet Authentication Service Memory Corruption Vulnerability."
18570| [CVE-2009-2504] Multiple integer overflows in unspecified APIs in GDI+ in Microsoft .NET Framework 1.1 SP1, .NET Framework 2.0 SP1 and SP2, Windows XP SP2 and SP3, Windows Server 2003 SP2, Vista Gold and SP1, Server 2008 Gold, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allow remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "GDI+ .NET API Vulnerability."
18571| [CVE-2009-2503] GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Windows Server 2003 SP2, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 does not properly allocate an unspecified buffer, which allows remote attackers to execute arbitrary code via a crafted TIFF image file that triggers memory corruption, aka "GDI+ TIFF Memory Corruption Vulnerability."
18572| [CVE-2009-2502] Buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a crafted TIFF image file, aka "GDI+ TIFF Buffer Overflow Vulnerability."
18573| [CVE-2009-2501] Heap-based buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a crafted PNG image file, aka "GDI+ PNG Heap Overflow Vulnerability."
18574| [CVE-2009-2500] Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a crafted WMF image file, aka "GDI+ WMF Integer Overflow Vulnerability."
18575| [CVE-2009-2498] Microsoft Windows Media Format Runtime 9.0, 9.5, and 11 and Windows Media Services 9.1 and 2008 do not properly parse malformed headers in Advanced Systems Format (ASF) files, which allows remote attackers to execute arbitrary code via a crafted (1) .asf, (2) .wmv, or (3) .wma file, aka "Windows Media Header Parsing Invalid Free Vulnerability."
18576| [CVE-2009-2484] Stack-based buffer overflow in the Win32AddConnection function in modules/access/smb.c in VideoLAN VLC media player 0.9.9, when running on Microsoft Windows, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long smb URI in a playlist file.
18577| [CVE-2009-2433] Stack-based buffer overflow in the AddFavorite method in Microsoft Internet Explorer allows remote attackers to cause a denial of service (application crash) and possibly have unspecified other impact via a long URL in the first argument.
18578| [CVE-2009-1930] The Telnet service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote Telnet servers to execute arbitrary code on a client machine by replaying the NTLM credentials of a client user, aka "Telnet Credential Reflection Vulnerability," a related issue to CVE-2000-0834.
18579| [CVE-2009-1928] Stack consumption vulnerability in the LDAP service in Active Directory on Microsoft Windows 2000 SP4, Server 2003 SP2, and Server 2008 Gold and SP2
18580| [CVE-2009-1926] Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allow remote attackers to cause a denial of service (TCP outage) via a series of TCP sessions that have pending data and a (1) small or (2) zero receive window size, and remain in the FIN-WAIT-1 or FIN-WAIT-2 state indefinitely, aka "TCP/IP Orphaned Connections Vulnerability."
18581| [CVE-2009-1925] The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 does not properly manage state information, which allows remote attackers to execute arbitrary code by sending packets to a listening service, and thereby triggering misinterpretation of an unspecified field as a function pointer, aka "TCP/IP Timestamps Code Execution Vulnerability."
18582| [CVE-2009-1924] Integer overflow in the Windows Internet Name Service (WINS) component for Microsoft Windows 2000 SP4 allows remote WINS replication partners to execute arbitrary code via crafted data structures in a packet, aka "WINS Integer Overflow Vulnerability."
18583| [CVE-2009-1923] Heap-based buffer overflow in the Windows Internet Name Service (WINS) component for Microsoft Windows 2000 SP4 and Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted WINS replication packet that triggers an incorrect buffer-length calculation, aka "WINS Heap Overflow Vulnerability."
18584| [CVE-2009-1922] The Message Queuing (aka MSMQ) service for Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP2, and Vista Gold does not properly validate unspecified IOCTL request data from user mode before passing this data to kernel mode, which allows local users to gain privileges via a crafted request, aka "MSMQ Null Pointer Vulnerability."
18585| [CVE-2009-1808] Microsoft Windows XP SP3 allows local users to cause a denial of service (system crash) by making an SPI_SETDESKWALLPAPER SystemParametersInfo call with an improperly terminated pvParam argument, followed by an SPI_GETDESKWALLPAPER SystemParametersInfo call.
18586| [CVE-2009-1717] Integer overflow in Terminal in Apple Mac OS X 10.5 before 10.5.7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted size value in a CSI[4 xterm resize escape sequence that triggers a heap-based buffer overflow.
18587| [CVE-2009-1546] Integer overflow in Avifil32.dll in the Windows Media file handling functionality in Microsoft Windows allows remote attackers to execute arbitrary code on a Windows 2000 SP4 system via a crafted AVI file, or cause a denial of service on a Windows XP SP2 or SP3, Server 2003 SP2, Vista Gold, SP1, or SP2, or Server 2008 Gold or SP2 system via a crafted AVI file, aka "AVI Integer Overflow Vulnerability."
18588| [CVE-2009-1544] Double free vulnerability in the Workstation service in Microsoft Windows allows remote authenticated users to gain privileges via a crafted RPC message to a Windows XP SP2 or SP3 or Server 2003 SP2 system, or cause a denial of service via a crafted RPC message to a Vista Gold, SP1, or SP2 or Server 2008 Gold or SP2 system, aka "Workstation Service Memory Corruption Vulnerability."
18589| [CVE-2009-1536] ASP.NET in Microsoft .NET Framework 2.0 SP1 and SP2 and 3.5 Gold and SP1, when ASP 2.0 is used in integrated mode on IIS 7.0, does not properly manage request scheduling, which allows remote attackers to cause a denial of service (daemon outage) via a series of crafted HTTP requests, aka "Remote Unauthenticated Denial of Service in ASP.NET Vulnerability."
18590| [CVE-2009-1535] The WebDAV extension in Microsoft Internet Information Services (IIS) 5.1 and 6.0 allows remote attackers to bypass URI-based protection mechanisms, and list folders or read, create, or modify files, via a %c0%af (Unicode / character) at an arbitrary position in the URI, as demonstrated by inserting %c0%af into a "/protected/" initial pathname component to bypass the password protection on the protected\ folder, aka "IIS 5.1 and 6.0 WebDAV Authentication Bypass Vulnerability," a different vulnerability than CVE-2009-1122.
18591| [CVE-2009-1511] GDI+ in Microsoft Windows XP SP3 allows remote attackers to cause a denial of service (infinite loop) via a PNG file that contains a certain large btChunkLen value.
18592| [CVE-2009-1335] Microsoft Internet Explorer 7 and 8 on Windows XP and Vista allows remote attackers to cause a denial of service (application hang) via a large document composed of unprintable characters, aka MSRC 9011jr.
18593| [CVE-2009-1331] Integer overflow in Microsoft Windows Media Player (WMP) 11.0.5721.5260 allows remote attackers to cause a denial of service (application crash) via a crafted .mid file, as demonstrated by crash.mid.
18594| [CVE-2009-1217] Off-by-one error in the GpFont::SetData function in gdiplus.dll in Microsoft GDI+ on Windows XP allows remote attackers to cause a denial of service (stack corruption and application termination) via a crafted EMF file that triggers an integer overflow, as demonstrated by voltage-exploit.emf, aka the "Microsoft GdiPlus EMF GpFont.SetData integer overflow."
18595| [CVE-2009-1216] Multiple unspecified vulnerabilities in (1) unlzh.c and (2) unpack.c in the gzip libraries in Microsoft Windows Server 2008, Windows Services for UNIX 3.0 and 3.5, and the Subsystem for UNIX-based Applications (SUA)
18596| [CVE-2009-1139] Memory leak in the LDAP service in Active Directory on Microsoft Windows 2000 SP4 and Server 2003 SP2, and Active Directory Application Mode (ADAM) on Windows XP SP2 and SP3 and Server 2003 SP2, allows remote attackers to cause a denial of service (memory consumption and service outage) via (1) LDAP or (2) LDAPS requests with unspecified OID filters, aka "Active Directory Memory Leak Vulnerability."
18597| [CVE-2009-1138] The LDAP service in Active Directory on Microsoft Windows 2000 SP4 does not properly free memory for LDAP and LDAPS requests, which allows remote attackers to execute arbitrary code via a request that uses hexadecimal encoding, whose associated memory is not released, related to a "DN AttributeValue," aka "Active Directory Invalid Free Vulnerability." NOTE: this issue is probably a memory leak.
18598| [CVE-2009-1132] Heap-based buffer overflow in the Wireless LAN AutoConfig Service (aka Wlansvc) in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a malformed wireless frame, aka "Wireless Frame Parsing Remote Code Execution Vulnerability."
18599| [CVE-2009-1122] The WebDAV extension in Microsoft Internet Information Services (IIS) 5.0 on Windows 2000 SP4 does not properly decode URLs, which allows remote attackers to bypass authentication, and possibly read or create files, via a crafted HTTP request, aka "IIS 5.0 WebDAV Authentication Bypass Vulnerability," a different vulnerability than CVE-2009-1535.
18600| [CVE-2009-0944] The Microsoft Office Spotlight Importer in Spotlight in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 does not properly validate Microsoft Office files, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a file that triggers memory corruption.
18601| [CVE-2009-0550] Windows HTTP Services (aka WinHTTP) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008
18602| [CVE-2009-0537] Integer overflow in the fts_build function in fts.c in libc in (1) OpenBSD 4.4 and earlier and (2) Microsoft Interix 6.0 build 10.0.6030.0 allows context-dependent attackers to cause a denial of service (application crash) via a deep directory tree, related to the fts_level structure member, as demonstrated by (a) du, (b) rm, (c) chmod, and (d) chgrp on OpenBSD
18603| [CVE-2009-0419] Microsoft XML Core Services, as used in Microsoft Expression Web, Office, Internet Explorer 6 and 7, and other products, does not properly restrict access from web pages to Set-Cookie2 HTTP response headers, which allows remote attackers to obtain sensitive information from cookies via XMLHttpRequest calls, related to the HTTPOnly protection mechanism. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2008-4033.
18604| [CVE-2009-0268] Race condition in the pseudo-terminal (aka pty) driver module in Sun Solaris 8 through 10, and OpenSolaris before snv_103, allows local users to cause a denial of service (panic) via unspecified vectors related to lack of "properly sequenced code" in ptc and ptsl.
18605| [CVE-2009-0244] Directory traversal vulnerability in the OBEX FTP Service in the Microsoft Bluetooth stack in Windows Mobile 6 Professional, and probably Windows Mobile 5.0 for Pocket PC and 5.0 for Pocket PC Phone Edition, allows remote authenticated users to list arbitrary directories, and create or read arbitrary files, via a .. (dot dot) in a pathname. NOTE: this can be leveraged for code execution by writing to a Startup folder.
18606| [CVE-2009-0234] The DNS Resolver Cache Service (aka DNSCache) in Windows DNS Server in Microsoft Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008 does not properly cache crafted DNS responses, which makes it easier for remote attackers to predict transaction IDs and poison caches by sending many crafted DNS queries that trigger "unnecessary lookups," aka "DNS Server Response Validation Vulnerability."
18607| [CVE-2009-0233] The DNS Resolver Cache Service (aka DNSCache) in Windows DNS Server in Microsoft Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008, when dynamic updates are enabled, does not reuse cached DNS responses in all applicable situations, which makes it easier for remote attackers to predict transaction IDs and poison caches by simultaneously sending crafted DNS queries and responses, aka "DNS Server Query Validation Vulnerability."
18608| [CVE-2009-0229] The Windows Printing Service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 allows local users to read arbitrary files via a crafted separator page, aka "Print Spooler Read File Vulnerability."
18609| [CVE-2009-0228] Stack-based buffer overflow in the EnumeratePrintShares function in Windows Print Spooler Service (win32spl.dll) in Microsoft Windows 2000 SP4 allows remote printer servers to execute arbitrary code via a a crafted ShareName in a response to an RPC request, related to "printing data structures," aka "Buffer Overflow in Print Spooler Vulnerability."
18610| [CVE-2009-0119] Buffer overflow in Microsoft Windows XP SP3 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted .chm file.
18611| [CVE-2009-0099] The Electronic Messaging System Microsoft Data Base (EMSMDB32) provider in Microsoft Exchange 2000 Server SP3 and Exchange Server 2003 SP2, as used in Exchange System Attendant, allows remote attackers to cause a denial of service (application outage) via a malformed MAPI command, aka "Literal Processing Vulnerability."
18612| [CVE-2009-0089] Windows HTTP Services (aka WinHTTP) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, and Vista Gold allows remote web servers to impersonate arbitrary https web sites by using DNS spoofing to "forward a connection" to a different https web site that has a valid certificate matching its own domain name, but not a certificate matching the domain name of the host requested by the user, aka "Windows HTTP Services Certificate Name Mismatch Vulnerability."
18613| [CVE-2009-0086] Integer underflow in Windows HTTP Services (aka WinHTTP) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote HTTP servers to execute arbitrary code via crafted parameter values in a response, related to error handling, aka "Windows HTTP Services Integer Underflow Vulnerability."
18614| [CVE-2009-0079] The RPCSS service in Microsoft Windows XP SP2 and SP3 and Server 2003 SP1 and SP2 does not properly implement isolation among a set of distinct processes that (1) all run under the NetworkService account or (2) all run under the LocalService account, which allows local users to gain privileges by accessing the resources of one of the processes, aka "Windows RPCSS Service Isolation Vulnerability."
18615| [CVE-2009-0078] The Windows Management Instrumentation (WMI) provider in Microsoft Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly implement isolation among a set of distinct processes that (1) all run under the NetworkService account or (2) all run under the LocalService account, which allows local users to gain privileges by accessing the resources of one of the processes, aka "Windows WMI Service Isolation Vulnerability."
18616| [CVE-2009-0072] Microsoft Internet Explorer 6.0 through 8.0 beta2 allows remote attackers to cause a denial of service (application crash) via an onload=screen[""] attribute value in a BODY element.
18617| [CVE-2008-7106] The installation of Sophos PureMessage for Microsoft Exchange 3.0 before 3.0.2, when both anti-virus and anti-spam are supported, does not create or launch the associated scan engines when the system is under heavy load, which has unspecified impact, probably remote bypass of scanner protection or a denial of service (message loss or delay).
18618| [CVE-2008-7105] Sophos PureMessage for Microsoft Exchange 3.0 before 3.0.2 allows remote attackers to cause a denial of service (EdgeTransport.exe termination) via a TNEF-encoded message with a crafted rich text body that is not properly handled during conversion to plain text. NOTE: this might be related to CVE-2008-7104.
18619| [CVE-2008-7104] Sophos PureMessage Scanner service (PMScanner.exe) in PureMessage for Microsoft Exchange 3.0 before 3.0.2 allows remote attackers to cause a denial of service (message queue delay and incomplete spam rule update) via a crafted (1) RTF or (2) PDF file.
18620| [CVE-2008-6819] win32k.sys in Microsoft Windows Server 2003 and Vista allows local users to cause a denial of service (system crash) via vectors related to CreateWindow, TranslateMessage, and DispatchMessage, possibly a race condition between threads, a different vulnerability than CVE-2008-1084. NOTE: some of these details are obtained from third party information.
18621| [CVE-2008-6219] nsrexecd.exe in multiple EMC Networker products including EMC NetWorker Server, Storage Node, and Client 7.3.x and 7.4, 7.4.1, 7.4.2, Client and Storage Node for Open VMS 7.3.2 ECO6 and earlier, Module for Microsoft Exchange 5.1 and earlier, Module for Microsoft Applications 2.0 and earlier, Module for Meditech 2.0 and earlier, and PowerSnap 2.4 SP1 and earlier does not properly control the allocation of memory, which allows remote attackers to cause a denial of service (memory exhaustion) via multiple crafted RPC requests.
18622| [CVE-2008-6194] Memory leak in the DNS server in Microsoft Windows allows remote attackers to cause a denial of service (memory consumption) via DNS packets. NOTE: this issue reportedly exists because of an incorrect fix for CVE-2007-3898.
18623| [CVE-2008-5823] An ActiveX control in prtstb06.dll in Microsoft Money 2006, when used with WScript in Windows Script Host (WSH) on Windows Vista, allows remote attackers to cause a denial of service (access violation and application crash) via a zero value for the Startup property.
18624| [CVE-2008-5745] Integer overflow in quartz.dll in the DirectShow framework in Microsoft Windows Media Player (WMP) 9, 10, and 11, including 11.0.5721.5260, allows remote attackers to cause a denial of service (application crash) via a crafted (1) WAV, (2) SND, or (3) MID file. NOTE: this has been incorrectly reported as a code-execution vulnerability. NOTE: it is not clear whether this issue is related to CVE-2008-4927.
18625| [CVE-2008-5232] Buffer overflow in the CallHTMLHelp method in the Microsoft Windows Media Services ActiveX control in nskey.dll 4.1.00.3917 in Windows Media Services on Microsoft Windows NT and 2000, and Avaya Media and Message Application servers, allows remote attackers to execute arbitrary code via a long argument. NOTE: the provenance of this information is unknown
18626| [CVE-2008-5229] Stack-based buffer overflow in Microsoft Device IO Control in iphlpapi.dll in Microsoft Windows Vista Gold and SP1 allows local users in the Network Configuration Operator group to gain privileges or cause a denial of service (system crash) via a large invalid PrefixLength to the CreateIpForwardEntry2 method, as demonstrated by a "route add" command. NOTE: this issue might not cross privilege boundaries.
18627| [CVE-2008-5181] Microsoft Communicator allows remote attackers to cause a denial of service (application or device outage) via instant messages containing large numbers of emoticons.
18628| [CVE-2008-5180] Microsoft Communicator, and Communicator in Microsoft Office 2010 beta, allows remote attackers to cause a denial of service (memory consumption) via a large number of SIP INVITE requests, which trigger the creation of many sessions.
18629| [CVE-2008-5179] Unspecified vulnerability in Microsoft Office Communications Server (OCS), Office Communicator, and Windows Live Messenger allows remote attackers to cause a denial of service (crash) via a crafted Real-time Transport Control Protocol (RTCP) receiver report packet.
18630| [CVE-2008-5044] Race condition in Microsoft Windows Server 2003 and Vista allows local users to cause a denial of service (crash or hang) via a multi-threaded application that makes many calls to UnhookWindowsHookEx while certain other desktop activity is occurring.
18631| [CVE-2008-4927] Microsoft Windows Media Player (WMP) 9.0 through 11 allows user-assisted attackers to cause a denial of service (application crash) via a malformed (1) MIDI or (2) DAT file, related to "MThd Header Parsing." NOTE: the provenance of this information is unknown
18632| [CVE-2008-4835] SMB in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to execute arbitrary code via malformed values of unspecified "fields inside the SMB packets" in an NT Trans2 request, related to "insufficiently validating the buffer size," aka "SMB Validation Remote Code Execution Vulnerability."
18633| [CVE-2008-4834] Buffer overflow in SMB in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via malformed values of unspecified "fields inside the SMB packets" in an NT Trans request, aka "SMB Buffer Overflow Remote Code Execution Vulnerability."
18634| [CVE-2008-4800] The DebugDiag ActiveX control in CrashHangExt.dll, possibly 1.0, in Microsoft Debug Diagnostic Tool allows remote attackers to cause a denial of service (NULL pointer dereference and Internet Explorer 6.0 crash) via a large negative integer argument to the GetEntryPointForThread method. NOTE: this issue might only be exploitable in limited environments or non-default browser settings.
18635| [CVE-2008-4609] The TCP implementation in (1) Linux, (2) platforms based on BSD Unix, (3) Microsoft Windows, (4) Cisco products, and probably other operating systems allows remote attackers to cause a denial of service (connection queue exhaustion) via multiple vectors that manipulate information in the TCP state table, as demonstrated by sockstress.
18636| [CVE-2008-4544] Unspecified vulnerability in an unspecified Microsoft API, as used by Cisco Unity and possibly other products, allows remote attackers to cause a denial of service by sending crafted packets to dynamic UDP ports, related to a "processing error."
18637| [CVE-2008-4510] Microsoft Windows Vista Home and Ultimate Edition SP1 and earlier allows local users to cause a denial of service (page fault and system crash) via multiple attempts to access a virtual address in a PAGE_NOACCESS memory page.
18638| [CVE-2008-4381] Microsoft Internet Explorer 7 allows remote attackers to cause a denial of service (application crash) via Javascript that calls the alert function with a URL-encoded string of a large number of invalid characters.
18639| [CVE-2008-4327] gdiplus.dll in GDI+ in Microsoft Windows XP SP3 does not properly handle crafted .ico files, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a certain crash.ico file on a web site, and allows user-assisted attackers to cause a denial of service (divide-by-zero error and persistent application crash) via this crash.ico file on the desktop, a different vulnerability than CVE-2007-2237.
18640| [CVE-2008-4323] Windows Explorer in Microsoft Windows XP SP3 allows user-assisted attackers to cause a denial of service (application crash) via a crafted .ZIP file.
18641| [CVE-2008-4301] ** DISPUTED ** A certain ActiveX control in iisext.dll in Microsoft Internet Information Services (IIS) allows remote attackers to set a password via a string argument to the SetPassword method. NOTE: this issue could not be reproduced by a reliable third party. In addition, the original researcher is unreliable. Therefore the original disclosure is probably erroneous.
18642| [CVE-2008-4300] A certain ActiveX control in adsiis.dll in Microsoft Internet Information Services (IIS) allows remote attackers to cause a denial of service (browser crash) via a long string in the second argument to the GetObject method. NOTE: this issue was disclosed by an unreliable researcher, so it might be incorrect.
18643| [CVE-2008-4299] A certain ActiveX control in the Microsoft Internet Authentication Service (IAS) Helper COM Component in iashlpr.dll allows remote attackers to cause a denial of service (browser crash) via a large integer value in the first argument to the PutProperty method. NOTE: this issue was disclosed by an unreliable researcher, so it might be incorrect.
18644| [CVE-2008-4295] Microsoft Windows Mobile 6.0 on HTC Wiza 200 and HTC MDA 8125 devices does not properly handle the first attempt to establish a Bluetooth connection to a peer with a long name, which allows remote attackers to cause a denial of service (device reboot) by configuring a Bluetooth device with a long hci name and (1) connecting directly to the Windows Mobile system or (2) waiting for the Windows Mobile system to scan for nearby devices.
18645| [CVE-2008-4250] The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitrary code via a crafted RPC request that triggers the overflow during path canonicalization, as exploited in the wild by Gimmiv.A in October 2008, aka "Server Service Vulnerability."
18646| [CVE-2008-4211] Integer signedness error in (1) QuickLook in Apple Mac OS X 10.5.5 and (2) Office Viewer in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via a crafted Microsoft Excel file that triggers an out-of-bounds memory access, related to "handling of columns."
18647| [CVE-2008-4127] Mshtml.dll in Microsoft Internet Explorer 7 Gold 7.0.5730 and 8 Beta 8.0.6001 on Windows XP SP2 allows remote attackers to cause a denial of service (failure of subsequent image rendering) via a crafted PNG file, related to an infinite loop in the CDwnTaskExec::ThreadExec function.
18648| [CVE-2008-4114] srv.sys in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to cause a denial of service (system crash) or possibly have unspecified other impact via an SMB WRITE_ANDX packet with an offset that is inconsistent with the packet size, related to "insufficiently validating the buffer size," as demonstrated by a request to the \PIPE\lsarpc named pipe, aka "SMB Validation Denial of Service Vulnerability."
18649| [CVE-2008-4110] Buffer overflow in the SQLVDIRLib.SQLVDirControl ActiveX control in Tools\Binn\sqlvdir.dll in Microsoft SQL Server 2000 (aka SQL Server 8.0) allows remote attackers to cause a denial of service (browser crash) or possibly execute arbitrary code via a long URL in the second argument to the Connect method. NOTE: this issue is not a vulnerability in many environments, since the control is not marked as safe for scripting and would not execute with default Internet Explorer settings.
18650| [CVE-2008-4071] A certain ActiveX control in Adobe Acrobat 9, when used with Microsoft Windows Vista and Internet Explorer 7, allows remote attackers to cause a denial of service (browser crash) via an src property value with an invalid acroie:// URL.
18651| [CVE-2008-4033] Cross-domain vulnerability in Microsoft XML Core Services 3.0 through 6.0, as used in Microsoft Expression Web, Office, Internet Explorer, and other products, allows remote attackers to obtain sensitive information from another domain and corrupt the session state via HTTP request header fields, as demonstrated by the Transfer-Encoding field, aka "MSXML Header Request Vulnerability."
18652| [CVE-2008-4032] Microsoft Office SharePoint Server 2007 Gold and SP1 and Microsoft Search Server 2008 do not properly perform authentication and authorization for administrative functions, which allows remote attackers to cause a denial of service (server load), obtain sensitive information, and "create scripts that would run in the context of the site" via requests to administrative URIs, aka "Access Control Vulnerability."
18653| [CVE-2008-4029] Cross-domain vulnerability in Microsoft XML Core Services 3.0 and 4.0, as used in Internet Explorer, allows remote attackers to obtain sensitive information from another domain via a crafted XML document, related to improper error checks for external DTDs, aka "MSXML DTD Cross-Domain Scripting Vulnerability."
18654| [CVE-2008-3956] orgchart.exe in Microsoft Organization Chart 2.00 allows user-assisted attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted .opx file.
18655| [CVE-2008-3479] Heap-based buffer overflow in the Microsoft Message Queuing (MSMQ) service (mqsvc.exe) in Microsoft Windows 2000 SP4 allows remote attackers to read memory contents and execute arbitrary code via a crafted RPC call, related to improper processing of parameters to string APIs, aka "Message Queuing Service Remote Code Execution Vulnerability."
18656| [CVE-2008-3465] Heap-based buffer overflow in an API in GDI in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows context-dependent attackers to cause a denial of service or execute arbitrary code via a WMF file with a malformed file-size parameter, which would not be properly handled by a third-party application that uses this API for a copy operation, aka "GDI Heap Overflow Vulnerability."
18657| [CVE-2008-3015] Integer overflow in gdiplus.dll in GDI+ in Microsoft Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a BMP image file with a malformed BitMapInfoHeader that triggers a buffer overflow, aka "GDI+ BMP Integer Overflow Vulnerability."
18658| [CVE-2008-3014] Buffer overflow in gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a malformed WMF image file that triggers improper memory allocation, aka "GDI+ WMF Buffer Overrun Vulnerability."
18659| [CVE-2008-3013] gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a malformed GIF image file containing many extension markers for graphic control extensions and subsequent unknown labels, aka "GDI+ GIF Parsing Vulnerability."
18660| [CVE-2008-3012] gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 does not properly perform memory allocation, which allows remote attackers to execute arbitrary code via a malformed EMF image file, aka "GDI+ EMF Memory Corruption Vulnerability."
18661| [CVE-2008-3010] Microsoft Windows Media Player 6.4, Windows Media Format Runtime 7.1 through 11, and Windows Media Services 4.1 and 9 incorrectly associate ISATAP addresses with the Local Intranet zone, which allows remote servers to capture NTLM credentials, and execute arbitrary code through credential-reflection attacks, by sending an authentication request, aka "ISATAP Vulnerability."
18662| [CVE-2008-3009] Microsoft Windows Media Player 6.4, Windows Media Format Runtime 7.1 through 11, and Windows Media Services 4.1, 9, and 2008 do not properly use the Service Principal Name (SPN) identifier when validating replies to authentication requests, which allows remote servers to execute arbitrary code via vectors that employ NTLM credential reflection, aka "SPN Vulnerability."
18663| [CVE-2008-2752] Microsoft Word 2000 9.0.2812 and 2003 11.8106.8172 does not properly handle unordered lists, which allows user-assisted remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted .doc file. NOTE: some of these details are obtained from third party information.
18664| [CVE-2008-2325] QuickLook in Apple Mac OS X 10.4.11 and 10.5.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Microsoft Office file, related to insufficient "bounds checking."
18665| [CVE-2008-2258] Microsoft Internet Explorer 5.01, 6, and 7 accesses uninitialized memory in certain conditions, which allows remote attackers to cause a denial of service (crash) and execute arbitrary code via vectors related to a document object "appended in a specific order" with "particular functions ... performed on" document objects, aka "HTML Objects Memory Corruption Vulnerability" or "Table Layout Memory Corruption Vulnerability," a different vulnerability than CVE-2008-2257.
18666| [CVE-2008-2257] Microsoft Internet Explorer 5.01, 6, and 7 accesses uninitialized memory in certain conditions, which allows remote attackers to cause a denial of service (crash) and execute arbitrary code via vectors related to a document object "appended in a specific order," aka "HTML Objects Memory Corruption Vulnerability" or "XHTML Rendering Memory Corruption Vulnerability," a different vulnerability than CVE-2008-2258.
18667| [CVE-2008-2256] Microsoft Internet Explorer 5.01, 6, and 7 does not properly handle objects that have been incorrectly initialized or deleted, which allows remote attackers to cause a denial of service (crash) and execute arbitrary code via unknown vectors, aka "Uninitialized Memory Corruption Vulnerability."
18668| [CVE-2008-2255] Microsoft Internet Explorer 5.01, 6, and 7 accesses uninitialized memory, which allows remote attackers to cause a denial of service (crash) and execute arbitrary code via unknown vectors, a different vulnerability than CVE-2008-2254, aka "HTML Object Memory Corruption Vulnerability."
18669| [CVE-2008-2254] Microsoft Internet Explorer 6 and 7 accesses uninitialized memory, which allows remote attackers to cause a denial of service (crash) and execute arbitrary code via unknown vectors, aka "HTML Object Memory Corruption Vulnerability."
18670| [CVE-2008-1898] A certain ActiveX control in WkImgSrv.dll 7.03.0616.0, as distributed in Microsoft Works 7 and Microsoft Office 2003 and 2007, allows remote attackers to execute arbitrary code or cause a denial of service (browser crash) via an invalid WksPictureInterface property value, which triggers an improper function call.
18671| [CVE-2008-1888] Cross-site scripting (XSS) vulnerability in Microsoft Windows SharePoint Services 2.0 allows remote attackers to inject arbitrary web script or HTML via the Picture Source (aka picture object source) field in the Rich Text Editor.
18672| [CVE-2008-1453] The Bluetooth stack in Microsoft Windows XP SP2 and SP3, and Vista Gold and SP1, allows physically proximate attackers to execute arbitrary code via a large series of Service Discovery Protocol (SDP) packets.
18673| [CVE-2008-1451] The WINS service on Microsoft Windows 2000 SP4, and Server 2003 SP1 and SP2, does not properly validate data structures in WINS network packets, which allows local users to gain privileges via a crafted packet, aka "Memory Overwrite Vulnerability."
18674| [CVE-2008-1446] Integer overflow in the Internet Printing Protocol (IPP) ISAPI extension in Microsoft Internet Information Services (IIS) 5.0 through 7.0 on Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, and Server 2008 allows remote authenticated users to execute arbitrary code via an HTTP POST request that triggers an outbound IPP connection from a web server to a machine operated by the attacker, aka "Integer Overflow in IPP Service Vulnerability."
18675| [CVE-2008-1445] Active Directory on Microsoft Windows 2000 Server SP4, XP Professional SP2 and SP3, Server 2003 SP1 and SP2, and Server 2008 allows remote authenticated users to cause a denial of service (system hang or reboot) via a crafted LDAP request.
18676| [CVE-2008-1441] Microsoft Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to cause a denial of service (system hang) via a series of Pragmatic General Multicast (PGM) packets with invalid fragment options, aka the "PGM Malformed Fragment Vulnerability."
18677| [CVE-2008-1440] Microsoft Windows XP SP2 and SP3, and Server 2003 SP1 and SP2, does not properly validate the option length field in Pragmatic General Multicast (PGM) packets, which allows remote attackers to cause a denial of service (infinite loop and system hang) via a crafted PGM packet, aka the "PGM Invalid Length Vulnerability."
18678| [CVE-2008-1438] Unspecified vulnerability in Microsoft Malware Protection Engine (mpengine.dll) 1.1.3520.0 and 0.1.13.192, as used in multiple Microsoft products, allows context-dependent attackers to cause a denial of service (disk space exhaustion) via a file with "crafted data structures" that trigger the creation of large temporary files, a different vulnerability than CVE-2008-1437.
18679| [CVE-2008-1437] Unspecified vulnerability in Microsoft Malware Protection Engine (mpengine.dll) 1.1.3520.0 and 0.1.13.192, as used in multiple Microsoft products, allows context-dependent attackers to cause a denial of service (engine hang and restart) via a crafted file, a different vulnerability than CVE-2008-1438.
18680| [CVE-2008-1436] Microsoft Windows XP Professional SP2, Vista, and Server 2003 and 2008 does not properly assign activities to the (1) NetworkService and (2) LocalService accounts, which might allow context-dependent attackers to gain privileges by using one service process to capture a resource from a second service process that has a LocalSystem privilege-escalation ability, related to improper management of the SeImpersonatePrivilege user right, as originally reported for Internet Information Services (IIS), aka Token Kidnapping.
18681| [CVE-2008-1088] Microsoft Project 2000 Service Release 1, 2002 SP1, and 2003 SP2 allows user-assisted remote attackers to execute arbitrary code via a crafted Project file, related to improper validation of "memory resource allocations."
18682| [CVE-2008-0088] Unspecified vulnerability in Active Directory on Microsoft Windows 2000 and Windows Server 2003, and Active Directory Application Mode (ADAM) on XP and Server 2003, allows remote attackers to cause a denial of service (hang and restart) via a crafted LDAP request.
18683| [CVE-2008-0084] Unspecified vulnerability in the TCP/IP support in Microsoft Windows Vista allows remote DHCP servers to cause a denial of service (hang and restart) via a crafted DHCP packet.
18684| [CVE-2008-0075] Unspecified vulnerability in Microsoft Internet Information Services (IIS) 5.1 through 6.0 allows remote attackers to execute arbitrary code via crafted inputs to ASP pages.
18685| [CVE-2008-0074] Unspecified vulnerability in Microsoft Internet Information Services (IIS) 5.0 through 7.0 allows local users to gain privileges via unknown vectors related to file change notifications in the TPRoot, NNTPFile\Root, or WWWRoot folders.
18686| [CVE-2007-6534] Multiple unspecified vulnerabilities in Microsoft Office Publisher allow user-assisted remote attackers to cause a denial of service (application crash) via a crafted PUB file, possibly involving wordart.
18687| [CVE-2007-6236] Microsoft Windows Media Player (WMP) allows remote attackers to cause a denial of service (application crash) via a certain AIFF file that triggers a divide-by-zero error, as demonstrated by kr.aiff.
18688| [CVE-2007-5861] Unspecified vulnerability in Spotlight in Apple Mac OS X 10.4.11 allows user-assisted attackers to cause a denial of service (application termination) or execute arbitrary code via a crafted .XLS file that triggers memory corruption in the Microsoft Office Spotlight Importer.
18689| [CVE-2007-5634] Speedfan.sys in Alfredo Milani Comparetti SpeedFan 4.33, when used on Microsoft Windows Vista x64, does not properly check a buffer during an IOCTL 0x9c402420 call, which allows local users to cause a denial of service (machine crash) and possibly gain privileges via unspecified vectors.
18690| [CVE-2007-5352] Unspecified vulnerability in Local Security Authority Subsystem Service (LSASS) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2 allows local users to gain privileges via a crafted local procedure call (LPC) request.
18691| [CVE-2007-5348] Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via an image file with crafted gradient sizes in gradient fill input, which triggers a heap-based buffer overflow related to GdiPlus.dll and VGX.DLL, aka "GDI+ VML Buffer Overrun Vulnerability."
18692| [CVE-2007-5145] Multiple buffer overflows in system DLL files in Microsoft Windows XP, as used by Microsoft Windows Explorer (explorer.exe) 6.00.2900.2180, Don Ho Notepad++, unspecified Adobe Macromedia applications, and other programs, allow user-assisted remote attackers to cause a denial of service (application crash) via long strings in the (1) author, (2) title, (3) subject, and (4) comment Properties fields of a file, possibly involving improper handling of extended file attributes by the (a) NtQueryInformationFile, (b) NtQueryDirectoryFile, (c) NtSetInformationFile, (d) FileAllInformation, (e) FileNameInformation, and other FILE_INFORMATION_CLASS functions in ntdll.dll and the (f) GetFileAttributesExW and (g) GetFileAttributesW functions in kernel32.dll, a related issue to CVE-2007-1347.
18693| [CVE-2007-5133] Microsoft Windows Explorer (explorer.exe) allows user-assisted remote attackers to cause a denial of service (CPU consumption) via a certain PNG file with a large tEXt chunk that possibly triggers an integer overflow in PNG chunk size handling, as demonstrated by badlycrafted.png.
18694| [CVE-2007-4916] Heap-based buffer overflow in the FileFind::FindFile method in (1) MFC42.dll, (2) MFC42u.dll, (3) MFC71.dll, and (4) MFC71u.dll in Microsoft Foundation Class (MFC) Library 8.0, as used by the ListFiles method in hpqutil.dll 2.0.0.138 in Hewlett-Packard (HP) All-in-One and Photo & Imaging Gallery 1.1 and probably other products, allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long first argument.
18695| [CVE-2007-4288] Microsoft Windows Media Player 11 (wmplayer.exe) allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted .au file that triggers a divide-by-zero error, as demonstrated by iapetus.au.
18696| [CVE-2007-4247] Windows Calendar on Microsoft Windows Vista allows remote attackers to cause a denial of service (NULL dereference and persistent application crash) via a malformed ICS file.
18697| [CVE-2007-4227] Microsoft Windows Explorer (explorer.exe) allows user-assisted remote attackers to cause a denial of service via a certain JPG file, as demonstrated by something.jpg. NOTE: this issue might be related to CVE-2007-3958.
18698| [CVE-2007-4036] ** DISPUTED ** Guidance Software EnCase allows user-assisted remote attackers to cause a denial of service via (1) a corrupted Microsoft Exchange database, which triggers an application crash when many options are selected
18699| [CVE-2007-3958] Microsoft Windows Explorer (explorer.exe) allows user-assisted remote attackers to cause a denial of service via a certain GIF file, as demonstrated by Art.gif.
18700| [CVE-2007-3724] The process scheduler in the Microsoft Windows XP kernel does not make use of the process statistics kept by the kernel, performs scheduling based on CPU billing gathered from periodic process sampling ticks, and gives preference to "interactive" processes that perform voluntary sleeps, which allows local users to cause a denial of service (CPU consumption), as described in "Secretly Monopolizing the CPU Without Superuser Privileges."
18701| [CVE-2007-3658] Unspecified vulnerability in Microsoft Register Server (REGSVR) allows attackers to cause a denial of service via a crafted DLL library.
18702| [CVE-2007-3550] ** DISPUTED ** Microsoft Internet Explorer 6.0 and 7.0 allows remote attackers to fill Zones with arbitrary domains using certain metacharacters such as wildcards via JavaScript, which results in a denial of service (website suppression and resource consumption), aka "Internet Explorer Zone Domain Specification Dos and Page Suppressing". NOTE: this issue has been disputed by a third party, who states that the zone settings cannot be manipulated.
18703| [CVE-2007-3436] Microsoft MSN Messenger 4.7 on Windows XP allows remote attackers to cause a denial of service (resource consumption) via a flood of SIP INVITE requests to the port specified for voice conversation.
18704| [CVE-2007-3282] Buffer overflow in the Microsoft Office MSODataSourceControl ActiveX object allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long argument to the DeleteRecordSourceIfUnused method.
18705| [CVE-2007-3040] Stack-based buffer overflow in agentdpv.dll 2.0.0.3425 in Microsoft Agent on Windows 2000 SP4 allows remote attackers to execute arbitrary code via a crafted URL to the Agent (Agent.Control) ActiveX control, which triggers an overflow within the Agent Service (agentsrv.exe) process, a different issue than CVE-2007-1205.
18706| [CVE-2007-3039] Stack-based buffer overflow in the Microsoft Message Queuing (MSMQ) service in Microsoft Windows 2000 Server SP4, Windows 2000 Professional SP4, and Windows XP SP2 allows attackers to execute arbitrary code via a long string in an opnum 0x06 RPC call to port 2103. NOTE: this is remotely exploitable on Windows 2000 Server.
18707| [CVE-2007-3036] Unspecified vulnerability in the (1) Windows Services for UNIX 3.0 and 3.5, and (2) Subsystem for UNIX-based Applications in Microsoft Windows 2000, XP, Server 2003, and Vista allows local users to gain privileges via unspecified vectors related to "certain setuid binary files."
18708| [CVE-2007-3028] The LDAP service in Windows Active Directory in Microsoft Windows 2000 Server SP4 does not properly check "the number of convertible attributes", which allows remote attackers to cause a denial of service (service unavailability) via a crafted LDAP request, related to "client sent LDAP request logic," aka "Windows Active Directory Denial of Service Vulnerability". NOTE: this is probably a different issue than CVE-2007-0040.
18709| [CVE-2007-2967] Multiple F-Secure anti-virus products for Microsoft Windows and Linux before 20070522 allow remote attackers to cause a denial of service (file scanning infinite loop) via certain crafted (1) ARJ archives or (2) FSG packed files.
18710| [CVE-2007-2966] Buffer overflow in the LHA decompresion component in F-Secure anti-virus products for Microsoft Windows and Linux before 20070529 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted LHA archive, related to an integer wrap, a similar issue to CVE-2006-4335.
18711| [CVE-2007-2903] Buffer overflow in the HelpPopup method in the Microsoft Office 2000 Controllo UA di Microsoft Office ActiveX control (OUACTRL.OCX) 1.0.1.9 allows remote attackers to cause a denial of service (probably winhlp32.exe crash) via a long first argument. NOTE: it is not clear whether this issue crosses privilege boundaries.
18712| [CVE-2007-2897] Microsoft Internet Information Services (IIS) 6.0 allows remote attackers to cause a denial of service (server instability or device hang), and possibly obtain sensitive information (device communication traffic)
18713| [CVE-2007-2885] The NotSafe function in the MSVDTDatabaseDesigner7 ActiveX control in VDT70.DLL in Microsoft Visual Database Tools (MSVDT) Database Designer 7.0 allows remote attackers to cause a denial of service (Internet Explorer 6 crash) via a long argument.
18714| [CVE-2007-2884] Multiple stack-based buffer overflows in Microsoft Visual Basic 6 allow user-assisted remote attackers to cause a denial of service (CPU consumption) or execute arbitrary code via a Visual Basic Project (vbp) file with a long (1) Description or (2) Company Name (VersionCompanyName) field.
18715| [CVE-2007-2815] The "hit-highlighting" functionality in webhits.dll in Microsoft Internet Information Services (IIS) Web Server 5.0 only uses Windows NT ACL configuration, which allows remote attackers to bypass NTLM and basic authentication mechanisms and access private web directories via the CiWebhitsfile parameter to null.htw.
18716| [CVE-2007-2593] The Terminal Server in Microsoft Windows 2003 Server, when using TLS, allows remote attackers to bypass SSL and self-signed certificate requirements, downgrade the server security, and possibly conduct man-in-the-middle attacks via unspecified vectors, as demonstrated using the Remote Desktop Protocol (RDP) 6.0 client. NOTE: a third party claims that the vendor may have fixed this in approximately 2006.
18717| [CVE-2007-2581] Multiple cross-site scripting (XSS) vulnerabilities in Microsoft Windows SharePoint Services 3.0 for Windows Server 2003 and Office SharePoint Server 2007 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO (query string) in "every main page," as demonstrated by default.aspx.
18718| [CVE-2007-2237] Microsoft Windows Graphics Device Interface (GDI+, GdiPlus.dll) allows context-dependent attackers to cause a denial of service (crash) via an ICO file with an InfoHeader containing a Height of zero, which triggers a divide-by-zero error.
18719| [CVE-2007-2228] rpcrt4.dll (aka the RPC runtime library) in Microsoft Windows XP SP2, XP Professional x64 Edition, Server 2003 SP1 and SP2, Server 2003 x64 Edition and x64 Edition SP2, and Vista and Vista x64 Edition allows remote attackers to cause a denial of service (RPCSS service stop and system restart) via an RPC request that uses NTLMSSP PACKET authentication with a zero-valued verification trailer signature, which triggers an invalid dereference. NOTE: this also affects Windows 2000 SP4, although the impact is an information leak.
18720| [CVE-2007-2223] Microsoft XML Core Services (MSXML) 3.0 through 6.0 allows remote attackers to execute arbitrary code via the substringData method on a (1) TextNode or (2) XMLDOM object, which causes an integer overflow that leads to a buffer overflow.
18721| [CVE-2007-2218] Unspecified vulnerability in the Windows Schannel Security Package for Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2, allows remote servers to execute arbitrary code or cause a denial of service via crafted digital signatures that are processed during an SSL handshake.
18722| [CVE-2007-2161] Microsoft Internet Explorer 7 allows remote attackers to cause a denial of service (browser hang) via JavaScript that matches a regular expression against a long string, as demonstrated using /(.)*/.
18723| [CVE-2007-1946] Integer overflow in Windows Explorer in Microsoft Windows XP SP1 might allow user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large width dimension in a crafted BMP image, as demonstrated by w4intof.bmp.
18724| [CVE-2007-1911] Multiple unspecified vulnerabilities in Microsoft Word 2007 allow remote attackers to cause a denial of service (CPU consumption) via crafted documents, as demonstrated by (1) file798-1.doc and (2) file613-1.doc, possibly related to a buffer overflow.
18725| [CVE-2007-1910] Buffer overflow in wwlib.dll in Microsoft Word 2007 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted document, as demonstrated by file789-1.doc.
18726| [CVE-2007-1765] Unspecified vulnerability in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a malformed ANI file, which results in memory corruption when processing cursors, animated cursors, and icons, a similar issue to CVE-2005-0416, as originally demonstrated using Internet Explorer 6 and 7. NOTE: this issue might be a duplicate of CVE-2007-0038
18727| [CVE-2007-1763] The ATI kernel driver (atikmdag.sys) in Microsoft Windows Vista allows user-assisted remote attackers to cause a denial of service (crash) via a crafted JPG image, as demonstrated by a slideshow, possibly due to a buffer overflow.
18728| [CVE-2007-1748] Stack-based buffer overflow in the RPC interface in the Domain Name System (DNS) Server Service in Microsoft Windows 2000 Server SP 4, Server 2003 SP 1, and Server 2003 SP 2 allows remote attackers to execute arbitrary code via a long zone name containing character constants represented by escape sequences.
18729| [CVE-2007-1644] The dynamic DNS update mechanism in the DNS Server service on Microsoft Windows does not properly authenticate clients in certain deployments or configurations, which allows remote attackers to change DNS records for a web proxy server and conduct man-in-the-middle (MITM) attacks on web traffic, conduct pharming attacks by poisoning DNS records, and cause a denial of service (erroneous name resolution).
18730| [CVE-2007-1537] \Device\NdisTapi (NDISTAPI.sys) in Microsoft Windows XP SP2 and 2003 SP1 uses weak permissions, which allows local users to write to the device and cause a denial of service, as demonstrated by using an IRQL to acquire a spinlock on paged memory via the NdisTapiDispatch function.
18731| [CVE-2007-1531] Microsoft Windows XP and Vista overwrites ARP table entries included in gratuitous ARP, which allows remote attackers to cause a denial of service (loss of network access) by sending a gratuitous ARP for the address of the Vista host.
18732| [CVE-2007-1530] The LLTD Mapper in Microsoft Windows Vista does not properly gather responses to EMIT packets, which allows remote attackers to cause a denial of service (mapping failure) by omitting an ACK response, which triggers an XML syntax error.
18733| [CVE-2007-1492] winmm.dll in Microsoft Windows XP allows user-assisted remote attackers to cause a denial of service (infinite loop) via a large cch argument value to the mmioRead function, as demonstrated by a crafted WAV file.
18734| [CVE-2007-1347] Microsoft Windows Explorer on Windows 2000 SP4 FR and XP SP2 FR, and possibly other versions and platforms, allows remote attackers to cause a denial of service (memory corruption and crash) via an Office file with crafted document summary information, which causes an error in Ole32.dll.
18735| [CVE-2007-1278] Unspecified vulnerability in the IIS connector in Adobe JRun 4.0 Updater 6, and ColdFusion MX 6.1 and 7.0 Enterprise, when using Microsoft IIS 6, allows remote attackers to cause a denial of service via unspecified vectors, involving the request of a file in the JRun web root.
18736| [CVE-2007-1239] Microsoft Excel 2003 does not properly parse .XLS files, which allows remote attackers to cause a denial of service (application crash) via a file with a (1) corrupted XML format or a (2) corrupted XLS format, which triggers a NULL pointer dereference.
18737| [CVE-2007-1238] Microsoft Office 2003 allows user-assisted remote attackers to cause a denial of service (application crash) by attempting to insert a corrupted WMF file.
18738| [CVE-2007-1204] Stack-based buffer overflow in the Universal Plug and Play (UPnP) service in Microsoft Windows XP SP2 allows remote attackers on the same subnet to execute arbitrary code via crafted HTTP headers in request or notification messages, which trigger memory corruption.
18739| [CVE-2007-1094] Microsoft Internet Explorer 7 allows remote attackers to cause a denial of service (NULL dereference and application crash) via JavaScript onUnload handlers that modify the structure of a document.
18740| [CVE-2007-1090] Microsoft Windows Explorer on Windows XP and 2003 allows remote user-assisted attackers to cause a denial of service (crash) via a malformed WMF file, which triggers the crash when the user browses the folder.
18741| [CVE-2007-1083] Buffer overflow in the Configuration Checker (ConfigChk) ActiveX control in VSCnfChk.dll 2.0.0.2 for Verisign Managed PKI Service, Secure Messaging for Microsoft Exchange, and Go Secure! allows remote attackers to execute arbitrary code via long arguments to the VerCompare method.
18742| [CVE-2007-0878] Unspecified vulnerability in Microsoft Internet Explorer on Windows Mobile 5.0 allows remote attackers to cause a denial of service (loss of browser and other device functionality) via a malformed WML page, related to an "overflow state." NOTE: it is possible that this issue is related to CVE-2007-0685.
18743| [CVE-2007-0870] Unspecified vulnerability in Microsoft Word 2000 allows remote attackers to cause a denial of service (crash) via unknown vectors, a different vulnerability than CVE-2006-5994, CVE-2006-6456, CVE-2006-6561, and CVE-2007-0515, a variant of Exploit-MS06-027.
18744| [CVE-2007-0842] The 64-bit versions of Microsoft Visual C++ 8.0 standard library (MSVCR80.DLL) time functions, including (1) localtime, (2) localtime_s, (3) gmtime, (4) gmtime_s, (5) ctime, (6) ctime_s, (7) wctime, (8) wctime_s, and (9) fstat, trigger an assertion error instead of a NULL pointer or EINVAL when processing a time argument later than Jan 1, 3000, which might allow context-dependent attackers to cause a denial of service (application exit) via large time values. NOTE: it could be argued that this is a design limitation of the functions, and the vulnerability lies with any application that does not validate arguments to these functions. However, this behavior is inconsistent with documentation, which does not list assertions as a possible result of an error condition.
18745| [CVE-2007-0811] Microsoft Internet Explorer 6.0 SP1 on Windows 2000, and 6.0 SP2 on Windows XP, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an HTML document containing a certain JavaScript for loop with an empty loop body, possibly involving getElementById.
18746| [CVE-2007-0612] Multiple ActiveX controls in Microsoft Windows 2000, XP, 2003, and Vista allows remote attackers to cause a denial of service (Internet Explorer crash) by accessing the bgColor, fgColor, linkColor, alinkColor, vlinkColor, or defaultCharset properties in the (1) giffile, (2) htmlfile, (3) jpegfile, (4) mhtmlfile, (5) ODCfile, (6) pjpegfile, (7) pngfile, (8) xbmfile, (9) xmlfile, (10) xslfile, or (11) wdfile objects in (a) mshtml.dll
18747| [CVE-2007-0562] Windows Explorer (explorer.exe) 6.0.2900.2180 in Microsoft Windows XP SP2 allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted .avi file, which triggers the crash when the user right clicks on the file.
18748| [CVE-2007-0515] Unspecified vulnerability in Microsoft Word allows user-assisted remote attackers to execute arbitrary code on Word 2000, and cause a denial of service on Word 2003, via unknown attack vectors that trigger memory corruption, as exploited by Trojan.Mdropper.W and later by Trojan.Mdropper.X, a different issue than CVE-2006-6456, CVE-2006-5994, and CVE-2006-6561.
18749| [CVE-2007-0221] Integer overflow in the IMAP (IMAP4) support in Microsoft Exchange Server 2000 SP3 allows remote attackers to cause a denial of service (service hang) via crafted literals in an IMAP command, aka the "IMAP Literal Processing Vulnerability."
18750| [CVE-2007-0210] The Window Image Acquisition (WIA) Service in Microsoft Windows XP SP2 allows local users to gain privileges via unspecified vectors involving an "unchecked buffer," probably a buffer overflow.
18751| [CVE-2007-0108] nwgina.dll in Novell Client 4.91 SP3 for Windows 2000/XP/2003 does not delete user profiles during a Terminal Service or Citrix session, which allows remote authenticated users to invoke alternate user profiles.
18752| [CVE-2007-0099] Race condition in the msxml3 module in Microsoft XML Core Services 3.0, as used in Internet Explorer 6 and other applications, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via many nested tags in an XML document in an IFRAME, when synchronous document rendering is frequently disrupted with asynchronous events, as demonstrated using a JavaScript timer, which can trigger NULL pointer dereferences or memory corruption, aka "MSXML Memory Corruption Vulnerability."
18753| [CVE-2007-0087] ** DISPUTED ** Microsoft Internet Information Services (IIS), when accessed through a TCP connection with a large window size, allows remote attackers to cause a denial of service (network bandwidth consumption) via a Range header that specifies multiple copies of the same fragment. NOTE: the severity of this issue has been disputed by third parties, who state that the large window size required by the attack is not normally supported or configured by the server, or that a DDoS-style attack would accomplish the same goal.
18754| [CVE-2007-0069] Unspecified vulnerability in the kernel in Microsoft Windows XP SP2, Server 2003, and Vista allows remote attackers to cause a denial of service (CPU consumption) and possibly execute arbitrary code via crafted (1) IGMPv3 and (2) MLDv2 packets that trigger memory corruption, aka "Windows Kernel TCP/IP/IGMPv3 and MLDv2 Vulnerability."
18755| [CVE-2007-0066] The kernel in Microsoft Windows 2000 SP4, XP SP2, and Server 2003, when ICMP Router Discovery Protocol (RDP) is enabled, allows remote attackers to cause a denial of service via fragmented router advertisement ICMP packets that trigger an out-of-bounds read, aka "Windows Kernel TCP/IP/ICMP Vulnerability."
18756| [CVE-2007-0064] Heap-based buffer overflow in Windows Media Format Runtime 7.1, 9, 9.5, 9.5 x64 Edition, 11, and Windows Media Services 9.1 for Microsoft Windows 2000, XP, Server 2003, and Vista allows user-assisted remote attackers to execute arbitrary code via a crafted Advanced Systems Format (ASF) file.
18757| [CVE-2007-0043] The Just In Time (JIT) Compiler service in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows user-assisted remote attackers to execute arbitrary code via unspecified vectors involving an "unchecked buffer," probably a buffer overflow, aka ".NET JIT Compiler Vulnerability".
18758| [CVE-2007-0041] The PE Loader service in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows remote attackers to execute arbitrary code via unspecified vectors involving an "unchecked buffer" and unvalidated message lengths, probably a buffer overflow.
18759| [CVE-2007-0040] The LDAP service in Windows Active Directory in Microsoft Windows 2000 Server SP4, Server 2003 SP1 and SP2, Server 2003 x64 Edition and SP2, and Server 2003 for Itanium-based Systems SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted LDAP request with an unspecified number of "convertible attributes."
18760| [CVE-2007-0039] The Exchange Collaboration Data Objects (EXCDO) functionality in Microsoft Exchange Server 2000 SP3, 2003 SP1 and SP2, and 2007 allows remote attackers to cause a denial of service (crash) via an Internet Calendar (iCal) file containing multiple X-MICROSOFT-CDO-MODPROPS (MODPROPS) properties in which the second MODPROPS is longer than the first, which triggers a NULL pointer dereference and an unhandled exception.
18761| [CVE-2007-0038] Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a large length value in the second (or later) anih block of a RIFF .ANI, cur, or .ico file, which results in memory corruption when processing cursors, animated cursors, and icons, a variant of CVE-2005-0416, as originally demonstrated using Internet Explorer 6 and 7. NOTE: this might be a duplicate of CVE-2007-1765
18762| [CVE-2006-7210] Microsoft Windows 2000, XP, and Server 2003 allows remote attackers to cause a denial of service (cpu consumption) via a PNG image with crafted (1) Width and (2) Height values in the IHDR block.
18763| [CVE-2006-7206] Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) by creating a ADODB.Recordset object and making a series of calls to the NextRecordset method with a long string argument, which causes an "invalid memory access" in the SysFreeString function, a different issue than CVE-2006-3510 and CVE-2006-3899.
18764| [CVE-2006-7192] Microsoft ASP .NET Framework 2.0.50727.42 does not properly handle comment (/* */) enclosures, which allows remote attackers to bypass request filtering and conduct cross-site scripting (XSS) attacks, or cause a denial of service, as demonstrated via an xss:expression STYLE attribute in a closing XSS HTML tag.
18765| [CVE-2006-7066] Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) by creating an object inside an iframe, deleting the frame by setting its location.href to about:blank, then accessing a property of the object within the deleted frame, which triggers a NULL pointer dereference. NOTE: it was later reported that 7.0.6000.16473 and earlier are also affected.
18766| [CVE-2006-7065] Microsoft Internet Explorer allows remote attackers to cause a denial of service (crash) via an IFRAME with a certain XML file and XSL stylesheet that triggers a crash in mshtml.dll when a refresh is called, probably a null pointer dereference.
18767| [CVE-2006-7031] Microsoft Internet Explorer 6.0.2900 SP2 and earlier allows remote attackers to cause a denial of service (crash) via a table element with a CSS attribute that sets the position, which triggers an "unhandled exception" in mshtml.dll.
18768| [CVE-2006-7030] Microsoft Internet Explorer 6 SP2 and earlier allows remote attackers to cause a denial of service (crash) via certain malformed HTML, possibly involving applet and base tags without required arguments, which triggers a null pointer dereference in mshtml.dll.
18769| [CVE-2006-7029] Microsoft Internet Explorer 6 SP2 and earlier allows remote attackers to cause a denial of service (crash) via a frameset with only one frame that calls resizeTo with certain arguments. NOTE: this issue might be related to CVE-2006-3637.
18770| [CVE-2006-6956] Microsoft Internet Explorer allows remote attackers to cause a denial of service (crash) via a web page that contains a large number of nested marquee tags, a related issue to CVE-2006-2723.
18771| [CVE-2006-6797] The Client Server Run-Time Subsystem (CSRSS) in Microsoft Windows allows local users to cause a denial of service (crash) or read arbitrary memory from csrss.exe via crafted arguments to the NtRaiseHardError function with status 0x50000018, a different vulnerability than CVE-2006-6696.
18772| [CVE-2006-6723] The Workstation service in Microsoft Windows 2000 SP4 and XP SP2 allows remote attackers to cause a denial of service (memory consumption) via a large maxlen value in an NetrWkstaUserEnum RPC request.
18773| [CVE-2006-6696] Double free vulnerability in Microsoft Windows 2000, XP, 2003, and Vista allows local users to gain privileges by calling the MessageBox function with a MB_SERVICE_NOTIFICATION message with crafted data, which sends a HardError message to Client/Server Runtime Server Subsystem (CSRSS) process, which is not properly handled when invoking the UserHardError and GetHardErrorText functions in WINSRV.DLL.
18774| [CVE-2006-6659] The Microsoft Office Outlook Recipient ActiveX control (ole32.dll) in Windows XP SP2 allows remote attackers to cause a denial of service (Internet Explorer 7 hang) via crafted HTML.
18775| [CVE-2006-6602] explorer.exe in Windows Explorer 6.00.2900.2180 in Microsoft Windows XP SP2 allows user-assisted remote attackers to cause a denial of service via a crafted WMV file.
18776| [CVE-2006-6601] Windows Media Player 10.00.00.4036 in Microsoft Windows XP SP2 allows user-assisted remote attackers to cause a denial of service via a .MID (MIDI) file with a malformed header chunk without any track chunks, possibly involving (1) number of tracks of (2) time division fields that are set to 0.
18777| [CVE-2006-6578] Microsoft Internet Information Services (IIS) 5.1 permits the IUSR_Machine account to execute non-EXE files such as .COM files, which allows attackers to execute arbitrary commands via arguments to any .COM file that executes those arguments, as demonstrated using win.com when it is in a web directory with certain permissions.
18778| [CVE-2006-6311] Microsoft Internet Explorer 6.0.2900.2180 allows remote attackers to cause a denial of service via a style attribute in an HTML table tag with a width value that is dynamically calculated using JavaScript.
18779| [CVE-2006-6310] Microsoft Internet Explorer 6.0 SP1 and earlier allows remote attackers to cause a denial of service (crash) via an invalid src attribute value ("?") in an HTML frame tag that is in a frameset tag with a large rows attribute. NOTE: The provenance of this information is unknown
18780| [CVE-2006-6296] The RpcGetPrinterData function in the Print Spooler (spoolsv.exe) service in Microsoft Windows 2000 SP4 and earlier, and possibly Windows XP SP1 and earlier, allows remote attackers to cause a denial of service (memory consumption) via an RPC request that specifies a large 'offered' value (output buffer size), a variant of CVE-2005-3644.
18781| [CVE-2006-6252] Microsoft Windows Live Messenger 8.0 and earlier, when gestual emoticons are enabled, allows remote attackers to cause a denial of service (CPU consumption) via a long string composed of ":D" sequences, which are interpreted as emoticons.
18782| [CVE-2006-6134] Heap-based buffer overflow in the WMCheckURLScheme function in WMVCORE.DLL in Microsoft Windows Media Player (WMP) 10.00.00.4036 on Windows XP SP2, Server 2003, and Server 2003 SP1 allows remote attackers to cause a denial of service (application crash) and execute arbitrary code via a long HREF attribute, using an unrecognized protocol, in a REF element in an ASX PlayList file.
18783| [CVE-2006-5758] The Graphics Rendering Engine in Microsoft Windows 2000 through 2000 SP4 and Windows XP through SP2 maps GDI Kernel structures on a global shared memory section that is mapped with read-only permissions, but can be remapped by other processes as read-write, which allows local users to cause a denial of service (memory corruption and crash) and gain privileges by modifying the kernel structures.
18784| [CVE-2006-5745] Unspecified vulnerability in the setRequestHeader method in the XMLHTTP (XML HTTP) ActiveX Control 4.0 in Microsoft XML Core Services 4.0 on Windows, when accessed by Internet Explorer, allows remote attackers to execute arbitrary code via crafted arguments that lead to memory corruption, a different vulnerability than CVE-2006-4685. NOTE: some of these details are obtained from third party information.
18785| [CVE-2006-5614] Microsoft Windows NAT Helper Components (ipnathlp.dll) on Windows XP SP2, when Internet Connection Sharing is enabled, allows remote attackers to cause a denial of service (svchost.exe crash) via a malformed DNS query, which results in a null pointer dereference.
18786| [CVE-2006-5584] The Remote Installation Service (RIS) in Microsoft Windows 2000 SP4 uses a TFTP server that allows anonymous access, which allows remote attackers to upload and overwrite arbitrary files to gain privileges on systems that use RIS.
18787| [CVE-2006-5583] Buffer overflow in the SNMP Service in Microsoft Windows 2000 SP4, XP SP2, Server 2003, Server 2003 SP1, and possibly other versions allows remote attackers to execute arbitrary code via a crafted SNMP packet, aka "SNMP Memory Corruption Vulnerability."
18788| [CVE-2006-5559] The Execute method in the ADODB.Connection 2.7 and 2.8 ActiveX control objects (ADODB.Connection.2.7 and ADODB.Connection.2.8) in the Microsoft Data Access Components (MDAC) 2.5 SP3, 2.7 SP1, 2.8, and 2.8 SP1 does not properly track freed memory when the second argument is a BSTR, which allows remote attackers to cause a denial of service (Internet Explorer crash) and possibly execute arbitrary code via certain strings in the second and third arguments.
18789| [CVE-2006-5448] The drmstor.dll ActiveX object in Microsoft Windows Digital Rights Management System (DRM) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long parameter to the StoreLicense function, which triggers "memory corruption" and possibly a buffer overflow.
18790| [CVE-2006-5296] PowerPoint in Microsoft Office 2003 does not properly handle a container object whose position value exceeds the record length, which allows user-assisted attackers to cause a denial of service (NULL dereference and application crash) via a crafted PowerPoint (.PPT) file, as demonstrated by Nanika.ppt, and a different vulnerability than CVE-2006-3435, CVE-2006-3876, CVE-2006-3877, and CVE-2006-4694. NOTE: the impact of this issue was originally claimed to be arbitrary code execution, but later analysis demonstrated that this was erroneous.
18791| [CVE-2006-5265] Unspecified vulnerability in Microsoft Dynamics GP (formerly Great Plains) 9.0 and earlier allows remote attackers to cause a denial of service (crash) via an invalid magic number in a Distributed Process Server (DPS) message.
18792| [CVE-2006-5162] wininet.dll in Microsoft Internet Explorer 6.0 SP2 and earlier allows remote attackers to cause a denial of service (unhandled exception and crash) via a long Content-Type header, which triggers a stack overflow.
18793| [CVE-2006-4888] Microsoft Internet Explorer 6 and earlier allows remote attackers to cause a denial of service (application hang) via a CSS-formatted HTML INPUT element within a DIV element that has a larger size than the INPUT.
18794| [CVE-2006-4696] Unspecified vulnerability in the Server service in Microsoft Windows 2000 SP4, Server 2003 SP1 and earlier, and XP SP2 and earlier allows remote attackers to execute arbitrary code via a crafted packet, aka "SMB Rename Vulnerability."
18795| [CVE-2006-4691] Stack-based buffer overflow in the NetpManageIPCConnect function in the Workstation service (wkssvc.dll) in Microsoft Windows 2000 SP4 and XP SP2 allows remote attackers to execute arbitrary code via NetrJoinDomain2 RPC messages with a long hostname.
18796| [CVE-2006-4689] Unspecified vulnerability in the driver for the Client Service for NetWare (CSNW) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 allows remote attackers to cause a denial of service (hang and reboot) via has unknown attack vectors, aka "NetWare Driver Denial of Service Vulnerability."
18797| [CVE-2006-4688] Buffer overflow in Client Service for NetWare (CSNW) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 allows remote attackers to execute arbitrary code via crafted messages, aka "Client Service for NetWare Memory Corruption Vulnerability."
18798| [CVE-2006-4686] Buffer overflow in the Extensible Stylesheet Language Transformations (XSLT) processing in Microsoft XML Parser 2.6 and XML Core Services 3.0 through 6.0 allows remote attackers to execute arbitrary code via a crafted Web page.
18799| [CVE-2006-4685] The XMLHTTP ActiveX control in Microsoft XML Parser 2.6 and XML Core Services 3.0 through 6.0 does not properly handle HTTP server-side redirects, which allows remote user-assisted attackers to access content from other domains.
18800| [CVE-2006-4627] System Information ActiveX control (msinfo.dll), when accessed via Microsoft Internet Explorer, allows remote attackers to cause a denial of service (crash) via a SaveFile function with a long (1) computer and possibly (2) filename and (3) category argument.
18801| [CVE-2006-4495] Microsoft Internet Explorer allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code by instantiating certain Windows 2000 ActiveX COM Objects including (1) ciodm.dll, (2) myinfo.dll, (3) msdxm.ocx, and (4) creator.dll.
18802| [CVE-2006-4494] Microsoft Visual Studio 6.0 allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code by instantiating certain Visual Studio 6.0 ActiveX COM Objects in Internet Explorer, including (1) tcprops.dll, (2) fp30wec.dll, (3) mdt2db.dll, (4) mdt2qd.dll, and (5) vi30aut.dll.
18803| [CVE-2006-4465] ** DISPUTED ** Microsoft Terminal Server, when running an application session with the "Start program at logon" and "Override settings from user profile and Client Connection Manager wizard" options, allows local users to execute arbitrary code by forcing an Explorer error. NOTE: a third-party researcher has stated that the options are "a convenience to users" and were not intended to restrict execution of arbitrary code.
18804| [CVE-2006-4446] Heap-based buffer overflow in DirectAnimation.PathControl COM object (daxctle.ocx) in Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a Spline function call whose first argument specifies a large number of points.
18805| [CVE-2006-4301] Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service (crash) via a long Color attribute in multiple DirectX Media Image DirectX Transforms ActiveX COM Objects from (a) dxtmsft.dll and (b) dxtmsft3.dll, including (1) DXImageTransform.Microsoft.MaskFilter.1, (2) DXImageTransform.Microsoft.Chroma.1, and (3) DX3DTransform.Microsoft.Shapes.1.
18806| [CVE-2006-4193] Microsoft Internet Explorer 6.0 SP1 and possibly other versions allows remote attackers to cause a denial of service and possibly execute arbitrary code by instantiating COM objects as ActiveX controls, including (1) imskdic.dll (Microsoft IME), (2) chtskdic.dll (Microsoft IME), and (3) msoe.dll (Outlook), which leads to memory corruption. NOTE: it is not certain whether the issue is in Internet Explorer or the individual DLL files.
18807| [CVE-2006-4071] Sign extension vulnerability in the createBrushIndirect function in the GDI library (gdi32.dll) in Microsoft Windows XP, Server 2003, and possibly other versions, allows user-assisted attackers to cause a denial of service (application crash) via a crafted WMF file.
18808| [CVE-2006-4066] The Graphical Device Interface Plus library (gdiplus.dll) in Microsoft Windows XP SP2 allows context-dependent attackers to cause a denial of service (application crash) via certain images that trigger a divide-by-zero error, as demonstrated by a (1) .ico file, (2) .png file that crashes MSN Messenger, and (3) .jpg file that crashes Internet Explorer. NOTE: another researcher has not been able to reproduce this issue.
18809| [CVE-2006-3944] Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) via a (1) Forms.ListBox.1 or (2) Forms.ListBox.1 object with the ListWidth property set to (a) 0x7fffffff, which triggers an integer overflow exception, or to (b) 0x7ffffffe, which triggers a null dereference.
18810| [CVE-2006-3943] Stack-based buffer overflow in NDFXArtEffects in Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) via long (1) RGBExtraColor, (2) RGBForeColor, and (3) RGBBackColor properties.
18811| [CVE-2006-3942] The server driver (srv.sys) in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause a denial of service (system crash) via an SMB_COM_TRANSACTION SMB message that contains a string without null character termination, which leads to a NULL dereference in the ExecuteTransaction function, possibly related to an "SMB PIPE," aka the "Mailslot DOS" vulnerability. NOTE: the name "Mailslot DOS" was derived from incomplete initial research
18812| [CVE-2006-3915] Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) by iterating over any native function, as demonstrated with the window.alert function, which triggers a null dereference.
18813| [CVE-2006-3899] Microsoft Internet Explorer 6.0 on Windows XP SP2 allows remote attackers to cause a denial of service (application crash) by calling the stringToBinary function of the CEnroll.CEnroll.2 ActiveX object with a long second argument, which triggers an invalid memory access inside the SysAllocStringLen function.
18814| [CVE-2006-3898] Microsoft Internet Explorer 6.0 on Windows XP SP2 allows remote attackers to cause a denial of service (application crash) by calling the Click method of the Internet.HHCtrl.1 ActiveX object before initializing the URL, which triggers a null dereference.
18815| [CVE-2006-3897] Stack overflow in Microsoft Internet Explorer 6 on Windows 2000 allows remote attackers to cause a denial of service (application crash) by creating an NMSA.ASFSourceMediaDescription.1 ActiveX object with a long dispValue property.
18816| [CVE-2006-3880] ** DISPUTED ** Microsoft Windows NT 4.0, Windows 2000, Windows XP, and Windows Small Business Server 2003 allow remote attackers to cause a denial of service (IP stack hang) via a continuous stream of packets on TCP port 135 that have incorrect TCP header checksums and random numbers in certain TCP header fields, as demonstrated by the Achilles Windows Attack Tool. NOTE: the researcher reports that the Microsoft Security Response Center has stated "Our investigation which has included code review, review of the TCPDump, and attempts on reproing the issue on multiple fresh installs of various Windows Operating Systems have all resulted in non confirmation."
18817| [CVE-2006-3873] Heap-based buffer overflow in URLMON.DLL in Microsoft Internet Explorer 6 SP1 on Windows 2000 and XP SP1, with versions the MS06-042 patch before 20060912, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long URL in a GZIP-encoded website that was the target of an HTTP redirect, due to an incomplete fix for CVE-2006-3869.
18818| [CVE-2006-3869] Heap-based buffer overflow in URLMON.DLL in Microsoft Internet Explorer 6 SP1 on Windows 2000 and XP SP1, with versions the MS06-042 patch before 20060824, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long URL on a website that uses HTTP 1.1 compression.
18819| [CVE-2006-3730] Integer overflow in Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a 0x7fffffff argument to the setSlice method on a WebViewFolderIcon ActiveX object, which leads to an invalid memory copy.
18820| [CVE-2006-3659] Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by setting the location or URL property of a MHTMLFile ActiveX object.
18821| [CVE-2006-3658] Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by accessing the object references of a FolderItem ActiveX object, which triggers a null dereference in the security check.
18822| [CVE-2006-3657] Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (stack overflow exception) via a DXImageTransform.Microsoft.Gradient ActiveX object with a long (1) StartColorStr or (2) EndColorStr property.
18823| [CVE-2006-3654] Buffer overflow in wksss.exe 8.4.702.0 in Microsoft Works Spreadsheet 8.0 allows remote attackers to cause a denial of service (CPU consumption or crash) via crafted Excel files.
18824| [CVE-2006-3653] wksss.exe 8.4.702.0 in Microsoft Works Spreadsheet 8.0 allows remote attackers to cause a denial of service (CPU consumption or crash) via crafted (1) Works, (2) Excel, and (3) Lotus 1-2-3 files.
18825| [CVE-2006-3638] Microsoft Internet Explorer 5.01 and 6 does not properly handle uninitialized COM objects, which allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code, as demonstrated by the Nth function in the DirectAnimation.DATuple ActiveX control, aka "COM Object Instantiation Memory Corruption Vulnerability."
18826| [CVE-2006-3605] Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by setting the Transition property on an uninitialized DXImageTransform.Microsoft.RevealTrans.1 ActiveX Object, which triggers a null dereference.
18827| [CVE-2006-3591] Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (application crash) by accessing the URL property of a TriEditDocument.TriEditDocument object before it has been initialized, which triggers a NULL pointer dereference.
18828| [CVE-2006-3545] ** DISPUTED ** Microsoft Internet Explorer 7.0 Beta allows remote attackers to cause a denial of service (application crash) via a web page with multiple empty APPLET start tags. NOTE: a third party has disputed this issue, stating that the crash does not occur with Microsoft Internet Explorer 7.0 Beta3.
18829| [CVE-2006-3513] danim.dll in Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (application crash) by accessing the Data property of a DirectAnimation DAUserData object before it is initialized, which triggers a NULL pointer dereference.
18830| [CVE-2006-3510] The Remote Data Service Object (RDS.DataControl) in Microsoft Internet Explorer 6 on Windows 2000 allows remote attackers to cause a denial of service (crash) via a series of operations that result in an invalid length calculation when using SysAllocStringLen, then triggers a buffer over-read.
18831| [CVE-2006-3493] Buffer overflow in LsCreateLine function (mso_203) in mso.dll and mso9.dll, as used by Microsoft Word and possibly other products in Microsoft Office 2003, 2002, and 2000, allows remote user-assisted attackers to cause a denial of service (crash) via a crafted Word DOC or other Office file type. NOTE: this issue was originally reported to allow code execution, but on 20060710 Microsoft stated that code execution is not possible, and the original researcher agrees.
18832| [CVE-2006-3472] Microsoft Internet Explorer 6.0 and 6.0 SP1 allows remote attackers to cause a denial of service via an HTML page with an A tag containing a long title attribute. NOTE: the provenance of this information is unknown
18833| [CVE-2006-3471] Microsoft Internet Explorer 6 on Windows XP allows remote attackers to cause a denial of service (crash) via a table with a frameset as a child, which triggers a null dereference, as demonstrated using the appendChild method.
18834| [CVE-2006-3441] Buffer overflow in the DNS Client service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted record response. NOTE: while MS06-041 implies that there is a single issue, there are multiple vectors, and likely multiple vulnerabilities, related to (1) a heap-based buffer overflow in a DNS server response to the client, (2) a DNS server response with malformed ATMA records, and (3) a length miscalculation in TXT, HINFO, X25, and ISDN records.
18835| [CVE-2006-3439] Buffer overflow in the Server Service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers, including anonymous users, to execute arbitrary code via a crafted RPC message, a different vulnerability than CVE-2006-1314.
18836| [CVE-2006-3427] Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by declaring the sourceURL attribute on an uninitialized DirectAnimation.StructuredGraphicsControl ActiveX Object, which triggers a null dereference.
18837| [CVE-2006-3357] Heap-based buffer overflow in HTML Help ActiveX control (hhctrl.ocx) in Microsoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code by repeatedly setting the Image field of an Internet.HHCtrl.1 object to certain values, possibly related to improper escaping and long strings.
18838| [CVE-2006-3354] Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by setting the Filter property of an ADODB.Recordset ActiveX object to certain values multiple times, which triggers a null dereference.
18839| [CVE-2006-3086] Stack-based buffer overflow in the HrShellOpenWithMonikerDisplayName function in Microsoft Hyperlink Object Library (hlink.dll) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long hyperlink, as demonstrated using an Excel worksheet with a long link in Unicode, aka "Hyperlink COM Object Buffer Overflow Vulnerability." NOTE: this is a different issue than CVE-2006-3059.
18840| [CVE-2006-2919] Unspecified vulnerability in Microsoft NetMeeting 3.01 allows remote attackers to cause a denial of service (crash or CPU consumption) and possibly execute arbitrary code via crafted inputs that trigger memory corruption.
18841| [CVE-2006-2838] Buffer overflow in the web console in F-Secure Anti-Virus for Microsoft Exchange 6.40, and Internet Gatekeeper 6.40 through 6.42 and 6.50 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown attack vectors. NOTE: By default, the connections are only allowed from the local host.
18842| [CVE-2006-2766] Buffer overflow in INETCOMM.DLL, as used in Microsoft Internet Explorer 6.0 through 6.0 SP2, Windows Explorer, Outlook Express 6, and possibly other programs, allows remote user-assisted attackers to cause a denial of service (application crash) via a long mhtml URI in the URL value in a URL file.
18843| [CVE-2006-2374] The Server Message Block (SMB) driver (MRXSMB.SYS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows local users to cause a denial of service (hang) by calling the MrxSmbCscIoctlCloseForCopyChunk with the file handle of the shadow device, which results in a deadlock, aka the "SMB Invalid Handle Vulnerability."
18844| [CVE-2006-2372] Buffer overflow in the DHCP Client service for Microsoft Windows 2000 SP4, Windows XP SP1 and SP2, and Server 2003 up to SP1 allows remote attackers to execute arbitrary code via a crafted DHCP response.
18845| [CVE-2006-2371] Buffer overflow in the Remote Access Connection Manager service (RASMAN) service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote unauthenticated or authenticated attackers to execute arbitrary code via certain crafted "RPC related requests," that lead to registry corruption and stack corruption, aka the "RASMAN Registry Corruption Vulnerability."
18846| [CVE-2006-2370] Buffer overflow in the Routing and Remote Access service (RRAS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote unauthenticated or authenticated attackers to execute arbitrary code via certain crafted "RPC related requests," aka the "RRAS Memory Corruption Vulnerability."
18847| [CVE-2006-2094] Microsoft Internet Explorer before Windows XP Service Pack 2 and Windows Server 2003 Service Pack 1, when Prompt is configured in Security Settings, uses modal dialogs to verify that a user wishes to run an ActiveX control or perform other risky actions, which allows user-assisted remote attackers to construct a race condition that tricks a user into clicking an object or pressing keys that are actually applied to a "Yes" approval for executing the control.
18848| [CVE-2006-1992] mshtml.dll 6.00.2900.2873, as used in Microsoft Internet Explorer, allows remote attackers to cause a denial of service (crash) via nested OBJECT tags, which trigger invalid pointer dereferences including NULL dereferences. NOTE: the possibility of code execution was originally theorized, but Microsoft has stated that this issue is non-exploitable.
18849| [CVE-2006-1540] MSO.DLL in Microsoft Office 2000, Office XP (2002), and Office 2003 allows user-assisted attackers to cause a denial of service and execute arbitrary code via multiple attack vectors, as originally demonstrated using a crafted document record with a malformed string, as demonstrated by replacing a certain "01 00 00 00" byte sequence with an "FF FF FF FF" byte sequence, possibly causing an invalid array index, in (1) an Excel .xls document, which triggers an access violation in ole32.dll
18850| [CVE-2006-1364] Microsoft w3wp (aka w3wp.exe) does not properly handle when the AspCompat directive is not used when referencing COM components in ASP.NET, which allows remote attackers to cause a denial of service (resource consumption or crash) by repeatedly requesting each of several documents that refer to COM components, or are restricted documents located under the ASP.NET application path.
18851| [CVE-2006-1359] Microsoft Internet Explorer 6 and 7 Beta 2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a certain createTextRange call on a checkbox object, which results in a dereference of an invalid table pointer.
18852| [CVE-2006-1315] The Server Service (SRV.SYS driver) in Microsoft Windows 2000 SP4, XP SP1 and SP2, Server 2003 up to SP1, and other products, allows remote attackers to obtain sensitive information via crafted requests that leak information in SMB buffers, which are not properly initialized, aka "SMB Information Disclosure Vulnerability."
18853| [CVE-2006-1314] Heap-based buffer overflow in the Server Service (SRV.SYS driver) in Microsoft Windows 2000 SP4, XP SP1 and SP2, Server 2003 up to SP1, and other products, allows remote attackers to execute arbitrary code via crafted first-class Mailslot messages that triggers memory corruption and bypasses size restrictions on second-class Mailslot messages.
18854| [CVE-2006-1305] Microsoft Outlook 2000, 2002, and 2003 allows user-assisted remote attackers to cause a denial of service (memory exhaustion and interrupted mail recovery) via malformed e-mail header information, possibly related to (1) long subject lines or (2) large numbers of recipients in To or CC headers.
18855| [CVE-2006-1184] Microsoft Distributed Transaction Coordinator (MSDTC) for Windows NT 4.0, 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote attackers to cause a denial of service (crash) via a BuildContextW request with a large (1) UuidString or (2) GuidIn of a certain length, which causes an out-of-range memory access, aka the MSDTC Denial of Service Vulnerability. NOTE: this is a variant of CVE-2005-2119.
18856| [CVE-2006-0988] The default configuration of the DNS Server service on Windows Server 2003 and Windows 2000, and the Microsoft DNS Server service on Windows NT 4.0, allows recursive queries and provides additional delegation information to arbitrary IP addresses, which allows remote attackers to cause a denial of service (traffic amplification) via DNS queries with spoofed source IP addresses.
18857| [CVE-2006-0935] Microsoft Word 2003 allows remote attackers to cause a denial of service (application crash) via a crafted file, as demonstrated by 101_filefuzz.
18858| [CVE-2006-0761] Buffer overflow in BlackBerry Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server 2.2 and 4.0 before SP3 Hotfix 4 for IBM Lotus Domino, 3.6 before SP7 and 5.0 before SP3 Hotfix 3 for Microsoft Exchangem, and 4.0 for Novell GroupWise before SP3 Hotfix 1 might allow user-assisted remote attackers to execute arbitrary code on the server via a crafted Microsoft Word document that is opened on a wireless device.
18859| [CVE-2006-0753] Memory leak in Microsoft Internet Explorer 6 for Windows XP Service Pack 2 allows remote attackers to cause a denial of service (memory consumption) via JavaScript that uses setInterval to repeatedly call a function to set the value of window.status.
18860| [CVE-2006-0585] jscript.dll in Microsoft Internet Explorer 6.0 SP1 and earlier allows remote attackers to cause a denial of service (application crash) via a Shockwave Flash object that contains ActionScript code that calls VBScript, which in turn calls the Javascript document.write function, which triggers a null dereference.
18861| [CVE-2006-0544] urlmon.dll in Microsoft Internet Explorer 7.0 beta 2 (aka 7.0.5296.0) allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a BGSOUND element with its SRC attribute set to "file://" followed by a large number of "-" (dash of hyphen) characters.
18862| [CVE-2006-0143] Microsoft Windows Graphics Rendering Engine (GRE) allows remote attackers to corrupt memory and cause a denial of service (crash) via a WMF file containing (1) ExtCreateRegion or (2) ExtEscape function calls with arguments with inconsistent lengths.
18863| [CVE-2006-0032] Cross-site scripting (XSS) vulnerability in the Indexing Service in Microsoft Windows 2000, XP, and Server 2003, when the Encoding option is set to Auto Select, allows remote attackers to inject arbitrary web script or HTML via a UTF-7 encoded URL, which is injected into an error message whose charset is set to UTF-7.
18864| [CVE-2006-0026] Buffer overflow in Microsoft Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows local and possibly remote attackers to execute arbitrary code via crafted Active Server Pages (ASP).
18865| [CVE-2006-0023] Microsoft Windows XP SP1 and SP2 before August 2004, and possibly other operating systems and versions, uses insecure default ACLs that allow the Authenticated Users group to gain privileges by modifying critical configuration information for the (1) Simple Service Discovery Protocol (SSDP), (2) Universal Plug and Play Device Host (UPnP), (3) NetBT, (4) SCardSvr, (5) DHCP, and (6) DnsCache services, aka "Permissive Windows Services DACLs." NOTE: the NetBT, SCardSvr, DHCP, DnsCache already require privileged access to exploit.
18866| [CVE-2006-0021] Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote attackers to cause a denial of service (hang) via an IGMP packet with an invalid IP option, aka the "IGMP v3 DoS Vulnerability."
18867| [CVE-2006-0020] An unspecified Microsoft WMF parsing application, as used in Internet Explorer 5.01 SP4 on Windows 2000 SP4, and 5.5 SP2 on Windows Millennium, and possibly other versions, allows attackers to cause a denial of service (crash) and possibly execute code via a crafted WMF file with a manipulated WMF header size, possibly involving an integer overflow, a different vulnerability than CVE-2005-4560, and aka "WMF Image Parsing Memory Corruption Vulnerability."
18868| [CVE-2006-0015] Cross-site scripting (XSS) vulnerability in _vti_bin/_vti_adm/fpadmdll.dll in Microsoft FrontPage Server Extensions 2002 and SharePoint Team Services allows remote attackers to inject arbitrary web script or HTML, then leverage the attack to execute arbitrary programs or create new accounts, via the (1) operation, (2) command, and (3) name parameters.
18869| [CVE-2006-0013] Buffer overflow in the Web Client service (WebClnt.dll) for Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote authenticated users or Guests to execute arbitrary code via crafted RPC requests, a different vulnerability than CVE-2005-1207.
18870| [CVE-2005-4810] Microsoft Internet Explorer 7.0 Beta3 and earlier allows remote attackers to cause a denial of service (crash) via a "text/html" HTML Content-type header sent in response to an XMLHttpRequest (AJAX).
18871| [CVE-2005-4717] Microsoft Internet Explorer 6.0 on Windows NT 4.0 SP6a, Windows 2000 SP4, Windows XP SP1, Windows XP SP2, and Windows Server 2003 SP1 allows remote attackers to cause a denial of service (client crash) via a certain combination of a malformed HTML file and a CSS file that triggers a null dereference, probably related to rendering of a DIV element that contains a malformed IMG tag, as demonstrated by IEcrash.htm and IEcrash.rar.
18872| [CVE-2005-4360] The URL parser in Microsoft Internet Information Services (IIS) 5.1 on Windows XP Professional SP2 allows remote attackers to execute arbitrary code via multiple requests to ".dll" followed by arguments such as "~0" through "~9", which causes ntdll.dll to produce a return value that is not correctly handled by IIS, as demonstrated using "/_vti_bin/.dll/*/~0". NOTE: the consequence was originally believed to be only a denial of service (application crash and reboot).
18873| [CVE-2005-4269] mshtml.dll in Microsoft Windows XP, Server 2003, and Internet Explorer 6.0 SP1 allows attackers to cause a denial of service (access violation) by causing mshtml.dll to process button-focus events at the same time that a document is reloading, as seen in Microsoft Office InfoPath 2003 by repeatedly clicking the "Delete" button in a repeating section in a form. NOTE: the normal operation of InfoPath appears to involve a local user without any privilege boundaries, so this might not be a vulnerability in InfoPath. If no realistic scenarios exist for this problem in other products, then perhaps it should be excluded from CVE.
18874| [CVE-2005-3983] Unknown vulnerability in the login page for HP Systems Insight Manager (SIM) 4.0 and 4.1, when accessed by Microsoft Internet Explorer with the MS04-025 patch, leads to a denial of service (browser hang). NOTE: although the advisory is vague, this issue does not appear to involve an attacker at all. If not, then this issue is not a vulnerability.
18875| [CVE-2005-3945] The SynAttackProtect protection in Microsoft Windows 2003 before SP1 and Windows 2000 before SP4 with Update Roll-up uses a hash of predictable data, which allows remote attackers to cause a denial of service (CPU consumption) via a flood of SYN packets that produce identical hash values, which slows down the hash table lookups.
18876| [CVE-2005-3644] PNP_GetDeviceList (upnp_getdevicelist) in UPnP for Microsoft Windows 2000 SP4 and earlier, and possibly Windows XP SP1 and earlier, allows remote attackers to cause a denial of service (memory consumption) via a DCE RPC request that specifies a large output buffer size, a variant of CVE-2006-6296, and a different vulnerability than CVE-2005-2120.
18877| [CVE-2005-3589] Buffer overflow in FileZilla Server Terminal 0.9.4d may allow remote attackers to cause a denial of service (terminal crash) via a long USER ftp command.
18878| [CVE-2005-3568] db2fmp process in IBM DB2 Content Manager before 8.2 Fix Pack 10 allows local users to cause a denial of service (CPU consumption) by importing a corrupted Microsoft Excel file, aka "CORRUPTED EXEL FILE WILL CAUSE TEXT SEARCH PROCESS LOOPING."
18879| [CVE-2005-3169] Microsoft Windows 2000 before Update Rollup 1 for SP4, when the "audit directory service access" policy is enabled, does not record a 565 event message for File Delete Child operations on an Active Directory object in the security event log, which could allow attackers to conduct unauthorized activities without detection.
18880| [CVE-2005-3077] Microsoft Internet Explorer 5.2.3 for Mac OS allows remote attackers to cause a denial of service (crash) via a web page with malformed attributes in a BGSOUND tag, possibly involving double-quotes in an about: URI.
18881| [CVE-2005-2831] Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, aka a variant of the "COM Object Instantiation Memory Corruption Vulnerability," a different vulnerability than CVE-2005-2127.
18882| [CVE-2005-2308] The JPEG decoder in Microsoft Internet Explorer allows remote attackers to cause a denial of service (CPU consumption or crash) and possibly execute arbitrary code via certain crafted JPEG images, as demonstrated using (1) mov_fencepost.jpg, (2) cmp_fencepost.jpg, (3) oom_dos.jpg, or (4) random.jpg.
18883| [CVE-2005-2307] netman.dll in Microsoft Windows Connections Manager Library allows local users to cause a denial of service (Network Connections Service crash) via a large integer argument to a particular function, aka "Network Connection Manager Vulnerability."
18884| [CVE-2005-2304] Microsoft MSN Messenger 9.0 and Internet Explorer 6.0 allows remote attackers to cause a denial of service (crash) via an image with an ICC Profile with a large Tag Count.
18885| [CVE-2005-2225] Microsoft MSN Messenger allows remote attackers to cause a denial of service via a plaintext message containing the ".pif" string, which is interpreted as a malicious file extension and causes users to be kicked from a group conversation. NOTE: it has been reported that Gaim is also affected, so this may be an issue in the protocol or MSN servers.
18886| [CVE-2005-2224] aspnet_wp.exe in Microsoft ASP.NET web services allows remote attackers to cause a denial of service (CPU consumption from infinite loop) via a crafted SOAP message to an RPC/Encoded method.
18887| [CVE-2005-2143] Microsoft Front Page allows attackers to cause a denial of service (crash) via a crafted style tag in a web page.
18888| [CVE-2005-2127] Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, as originally demonstrated using the (1) DDS Library Shape Control (Msdds.dll) COM object, and other objects including (2) Blnmgrps.dll, (3) Ciodm.dll, (4) Comsvcs.dll, (5) Danim.dll, (6) Htmlmarq.ocx, (7) Mdt2dd.dll (as demonstrated using a heap corruption attack with uninitialized memory), (8) Mdt2qd.dll, (9) Mpg4ds32.ax, (10) Msadds32.ax, (11) Msb1esen.dll, (12) Msb1fren.dll, (13) Msb1geen.dll, (14) Msdtctm.dll, (15) Mshtml.dll, (16) Msoeacct.dll, (17) Msosvfbr.dll, (18) Mswcrun.dll, (19) Netshell.dll, (20) Ole2disp.dll, (21) Outllib.dll, (22) Psisdecd.dll, (23) Qdvd.dll, (24) Repodbc.dll, (25) Shdocvw.dll, (26) Shell32.dll, (27) Soa.dll, (28) Srchui.dll, (29) Stobject.dll, (30) Vdt70.dll, (31) Vmhelper.dll, and (32) Wbemads.dll, aka a variant of the "COM Object Instantiation Memory Corruption vulnerability."
18889| [CVE-2005-2120] Stack-based buffer overflow in the Plug and Play (PnP) service (UMPNPMGR.DLL) in Microsoft Windows 2000 SP4, and XP SP1 and SP2, allows remote or local authenticated attackers to execute arbitrary code via a large number of "\" (backslash) characters in a registry key name, which triggers the overflow in a wsprintfW function call.
18890| [CVE-2005-1985] The Client Service for NetWare (CSNW) on Microsoft Windows 2000 SP4, XP SP1 and Sp2, and Server 2003 SP1 and earlier, allows remote attackers to execute arbitrary code due to an "unchecked buffer" when processing certain crafted network messages.
18891| [CVE-2005-1984] Buffer overflow in the Print Spooler service (Spoolsv.exe) for Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via a malicious message.
18892| [CVE-2005-1983] Stack-based buffer overflow in the Plug and Play (PnP) service for Microsoft Windows 2000 and Windows XP Service Pack 1 allows remote attackers to execute arbitrary code via a crafted packet, and local users to gain privileges via a malicious application, as exploited by the Zotob (aka Mytob) worm.
18893| [CVE-2005-1981] Unknown vulnerability in Microsoft Windows 2000 Server and Windows Server 2003 domain controllers allows remote authenticated users to cause a denial of service (system crash) via a crafted Kerberos message.
18894| [CVE-2005-1980] Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC service hang) via a crafted Transaction Internet Protocol (TIP) message that causes DTC to repeatedly connect to a target IP and port number after an error occurs, aka the "Distributed TIP Vulnerability."
18895| [CVE-2005-1979] Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC service exception and exit) via an "unexpected protocol command during the reconnection request," which is not properly handled by the Transaction Internet Protocol (TIP) functionality.
18896| [CVE-2005-1907] The ISA Firewall service in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service (Wspsrv.exe crash) via a large amount of SecureNAT network traffic.
18897| [CVE-2005-1829] Microsoft Internet Explorer 6 SP2 allows remote attackers to cause a denial of service (infinite loop and application crash) via two embedded files that call each other.
18898| [CVE-2005-1794] Microsoft Terminal Server using Remote Desktop Protocol (RDP) 5.2 stores an RSA private key in mstlsapi.dll and uses it to sign a certificate, which allows remote attackers to spoof public keys of legitimate servers and conduct man-in-the-middle attacks.
18899| [CVE-2005-1793] User32.DLL in Microsoft Windows 98SE, and possibly other operating systems, allows local and remote attackers to cause a denial of service (crash) via an icon (.ico) bitmap file with large width and height values.
18900| [CVE-2005-1790] Microsoft Internet Explorer 6 SP2 6.0.2900.2180 and 6.0.2800.1106, and earlier versions, allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a Javascript BODY onload event that calls the window function, aka "Mismatched Document Object Model Objects Memory Corruption Vulnerability."
18901| [CVE-2005-1683] Buffer overflow in winword.exe 10.2627.6714 and earlier in Microsoft Word for the Macintosh, before SP3 for Word 2002, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted mcw file.
18902| [CVE-2005-1665] The __VIEWSTATE functionality in Microsoft ASP.NET 1.x, when not cryptographically signed, allows remote attackers to cause a denial of service (CPU consumption) via deeply nested markup.
18903| [CVE-2005-1218] The Microsoft Windows kernel in Microsoft Windows 2000 Server, Windows XP, and Windows Server 2003 allows remote attackers to cause a denial of service (crash) via crafted Remote Desktop Protocol (RDP) requests.
18904| [CVE-2005-1216] Microsoft ISA Server 2000 allows remote attackers to connect to services utilizing the NetBIOS protocol via a NetBIOS connection with an ISA Server that uses the NetBIOS (all) predefined packet filter.
18905| [CVE-2005-1207] Buffer overflow in the Web Client service in Microsoft Windows XP and Windows Server 2003 allows remote authenticated users to execute arbitrary code via a crafted WebDAV request containing special parameters.
18906| [CVE-2005-1205] The Telnet client for Microsoft Windows XP, Windows Server 2003, and Windows Services for UNIX allows remote attackers to read sensitive environment variables via the NEW-ENVIRON option with a SEND ENV_USERVAR command.
18907| [CVE-2005-0852] Microsoft Windows XP SP1 allows local users to cause a denial of service (system crash) via an empty datagram to a raw IP over IP socket (IP protocol 4), as originally demonstrated using code in Python 2.3.
18908| [CVE-2005-0738] Stack consumption vulnerability in Microsoft Exchange Server 2003 SP1 allows users to cause a denial of service (hang) by deleting or moving a folder with deeply nested subfolders, which causes Microsoft Exchange Information Store service (Store.exe) to hang as a result of a large number of recursive calls.
18909| [CVE-2005-0554] Buffer overflow in the URL processor of Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a URL with a long hostname, aka "URL Parsing Memory Corruption Vulnerability."
18910| [CVE-2005-0550] Buffer overflow in Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to cause a denial of service (i.e., system crash) via a malformed request, aka "Object Management Vulnerability".
18911| [CVE-2005-0048] Microsoft Windows XP SP2 and earlier, 2000 SP3 and SP4, Server 2003, and older operating systems allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted IP packets with malformed options, aka the "IP Validation Vulnerability."
18912| [CVE-2004-2527] The local and remote desktop login screens in Microsoft Windows XP before SP2 and 2003 allow remote attackers to cause a denial of service (CPU and memory consumption) by repeatedly using the WinKey+"U" key combination, which causes multiple copies of Windows Utility Manager to be loaded more quickly than they can be closed when the copies detect that another instance is running.
18913| [CVE-2004-2476] Microsoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (infinite loop and crash) via an IFRAME with "?" as the file source.
18914| [CVE-2004-2434] Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service (browser crash) via a link with "::{" (colon colon left brace), which triggers a null dereference when the user attempts to save the link using "Save As" and Internet Explorer prepares an error message with an attacker-controlled format string.
18915| [CVE-2004-2382] The PerfectNav plugin for Microsoft Internet Explorer allows remote attackers to cause a denial of service (browser crash) via a malformed URL such as "?".
18916| [CVE-2004-2365] Memory leak in Microsoft Windows XP and Windows Server 2003 allows local users to cause a denial of service (memory exhaustion) by repeatedly creating and deleting directories using a non-standard tool such as smbmount.
18917| [CVE-2004-2307] Microsoft Internet Explorer 6.0.2600 on Windows XP allows remote attackers to cause a denial of service (browser crash) via a shell: URI with double backslashes (\\) in an HTML tag such as IFRAME or A.
18918| [CVE-2004-2179] asycpict.dll, as used in Microsoft products such as Front Page 97 and 98, allows remote attackers to cause a denial of service (hang) via a JPEG image with maximum height and width values.
18919| [CVE-2004-2147] Unknown versions of Symantec Norton AntiVirus and Microsoft Outlook allow attackers to cause a denial of service (crash) via malformed e-mail messages (1) without a body or (2) without a carriage return ("\n") separating the headers from the body.
18920| [CVE-2004-1922] Microsoft Internet Explorer 5.5 and 6.0 allocates memory based on the memory size written in the BMP file instead of the actual BMP file size, which allows remote attackers to cause a denial of service (memory consumption) via a small BMP file with has a large memory size.
18921| [CVE-2004-1889] Unknown vulnerability in ftpd in SGI IRIX 6.5.20 through 6.5.23 allows remote attackers to cause a denial of service (hang) via a link failure with Microsoft Windows.
18922| [CVE-2004-1560] Microsoft SQL Server 7.0 allows remote attackers to cause a denial of service (mssqlserver service halt) via a long request to TCP port 1433, possibly triggering a buffer overflow.
18923| [CVE-2004-1464] Cisco IOS 12.2(15) and earlier allows remote attackers to cause a denial of service (refused VTY (virtual terminal) connections), via a crafted TCP connection to the Telnet or reverse Telnet port.
18924| [CVE-2004-1312] A bug in the HTML parser in a certain Microsoft HTML library, as used in various third party products, may allow remote attackers to cause a denial of service via certain strings, as reported in GFI MailEssentials for Exchange 9 and 10, and GFI MailSecurity for Exchange 8, which causes emails to remain in IIS or Exchange mail queues.
18925| [CVE-2004-1198] Microsoft Internet Explorer allows remote attackers to cause a denial of service (application crash from memory consumption), as demonstrated using Javascript code that continuously creates nested arrays and then sorts the newly created arrays.
18926| [CVE-2004-1134] Buffer overflow in the Microsoft W3Who ISAPI (w3who.dll) allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long query string.
18927| [CVE-2004-1080] The WINS service (wins.exe) on Microsoft Windows NT Server 4.0, Windows 2000 Server, and Windows Server 2003 allows remote attackers to write to arbitrary memory locations and possibly execute arbitrary code via a modified memory pointer in a WINS replication packet to TCP port 42, aka the "Association Context Vulnerability."
18928| [CVE-2004-0963] Buffer overflow in Microsoft Word 2002 (10.6612.6714) SP3, and possibly other versions, allows remote attackers to cause a denial of service (application exception) and possibly execute arbitrary code in winword.exe via certain unexpected values in a .doc file, including (1) an offset that triggers an out-of-bounds memory access, (2) a certain value that causes a large memory copy as triggered by an integer conversion error, and other values.
18929| [CVE-2004-0897] The Indexing Service for Microsoft Windows XP and Server 2003 does not properly validate the length of a message, which allows remote attackers to execute arbitrary code via a buffer overflow attack.
18930| [CVE-2004-0830] The Content Scanner Server in F-Secure Anti-Virus for Microsoft Exchange 6.21 and earlier, F-Secure Anti-Virus for Microsoft Exchange 6.01 and earlier, and F-Secure Internet Gatekeeper 6.32 and earlier allow remote attackers to cause a denial of service (service crash due to unhandled exception) via a certain malformed packet.
18931| [CVE-2004-0814] Multiple race conditions in the terminal layer in Linux 2.4.x, and 2.6.x before 2.6.9, allow (1) local users to obtain portions of kernel data via a TIOCSETD ioctl call to a terminal interface that is being accessed by another thread, or (2) remote attackers to cause a denial of service (panic) by switching from console to PPP line discipline, then quickly sending data that is received during the switch.
18932| [CVE-2004-0728] The Remote Control Client service in Microsoft's Systems Management Server (SMS) 2.50.2726.0 allows remote attackers to cause a denial of service (crash) via a data packet to TCP port 2702 that causes the server to read or write to an invalid memory address.
18933| [CVE-2004-0610] The Web administration interface in Microsoft MN-500 Wireless Router allows remote attackers to cause a denial of service (connection refusal) via a large number of open HTTP connections.
18934| [CVE-2004-0569] The RPC Runtime Library for Microsoft Windows NT 4.0 allows remote attackers to read active memory or cause a denial of service (system crash) via a malicious message, possibly related to improper length values.
18935| [CVE-2004-0567] The Windows Internet Naming Service (WINS) in Windows NT Server 4.0 SP 6a, NT Terminal Server 4.0 SP 6, Windows 2000 Server SP3 and SP4, and Windows Server 2003 does not properly validate the computer name value in a WINS packet, which allows remote attackers to execute arbitrary code or cause a denial of service (server crash), which results in an "unchecked buffer" and possibly triggers a buffer overflow, aka the "Name Validation Vulnerability."
18936| [CVE-2004-0484] mshtml.dll in Microsoft Internet Explorer 6.0.2800 allows remote attackers to cause a denial of service (crash) via a table containing a form that crosses multiple td elements, and whose "float: left" class is defined in a link to a CSS stylesheet after the end of the table, which may trigger a null dereference.
18937| [CVE-2004-0284] Microsoft Internet Explorer 6.0, Outlook 2002, and Outlook 2003 allow remote attackers to cause a denial of service (CPU consumption), if "Do not save encrypted pages to disk" is disabled, via a web site or HTML e-mail that contains two null characters (%00) after the host name.
18938| [CVE-2004-0215] Microsoft Outlook Express 5.5 and 6 allows attackers to cause a denial of service (application crash) via a malformed e-mail header.
18939| [CVE-2004-0214] Buffer overflow in Microsoft Internet Explorer and Explorer on Windows XP SP1, WIndows 2000, Windows 98, and Windows Me may allow remote malicious servers to cause a denial of service (application crash) and possibly execute arbitrary code via long share names, as demonstrated using Samba.
18940| [CVE-2004-0211] The kernel for Microsoft Windows Server 2003 does not reset certain values in CPU data structures, which allows local users to cause a denial of service (system crash) via a malicious program.
18941| [CVE-2004-0206] Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to remotely execute arbitrary code or locally gain privileges via a malicious message or application that involves an "unchecked buffer," possibly a buffer overflow.
18942| [CVE-2004-0202] IDirectPlay4 Application Programming Interface (API) of Microsoft DirectPlay 7.0a thru 9.0b, as used in Windows Server 2003 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed packet.
18943| [CVE-2004-0120] The Microsoft Secure Sockets Layer (SSL) library, as used in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service via malformed SSL messages.
18944| [CVE-2004-0116] An Activation function in the RPCSS Service involved with DCOM activation for Microsoft Windows 2000, XP, and 2003 allows remote attackers to cause a denial of service (memory consumption) via an activation request with a large length field.
18945| [CVE-2004-0115] VirtualPC_Services in Microsoft Virtual PC for Mac 6.0 through 6.1 allows local attackers to truncate and overwrite arbitrary files, and execute arbitrary code, via a symlink attack on the VPCServices_Log temporary file.
18946| [CVE-2003-1582] Microsoft Internet Information Services (IIS) 6.0, when DNS resolution is enabled for client IP addresses, allows remote attackers to inject arbitrary text into log files via an HTTP request in conjunction with a crafted DNS response, as demonstrated by injecting XSS sequences, related to an "Inverse Lookup Log Corruption (ILLC)" issue.
18947| [CVE-2003-1567] The undocumented TRACK method in Microsoft Internet Information Services (IIS) 5.0 returns the content of the original request in the body of the response, which makes it easier for remote attackers to steal cookies and authentication credentials, or bypass the HttpOnly protection mechanism, by using TRACK to read the contents of the HTTP headers that are returned in the response, a technique that is similar to cross-site tracing (XST) using HTTP TRACE.
18948| [CVE-2003-1566] Microsoft Internet Information Services (IIS) 5.0 does not log requests that use the TRACK method, which allows remote attackers to obtain sensitive information without detection.
18949| [CVE-2003-1544] Unrestricted critical resource lock in Terminal Services for Windows 2000 before SP4 and Windows XP allows remote authenticated users to cause a denial of service (reboot) by obtaining a read lock on msgina.dll, which prevents msgina.dll from being loaded.
18950| [CVE-2003-1505] Microsoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (crash) by creating a web page or HTML e-mail with a textarea in a div element whose scrollbar-base-color is modified by a CSS style, which is then moved.
18951| [CVE-2003-1484] Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service (crash) by creating a DHTML link that uses the AnchorClick "A" object with a blank href attribute.
18952| [CVE-2003-1305] Microsoft Internet Explorer allows remote attackers to cause a denial of service (resource consumption) via a Javascript src attribute that recursively loads the current web page.
18953| [CVE-2003-1106] The SMTP service in Microsoft Windows 2000 before SP4 allows remote attackers to cause a denial of service (crash or hang) via an e-mail message with a malformed time stamp in the FILETIME attribute.
18954| [CVE-2003-0995] Buffer overflow in the Microsoft Message Queue Manager (MSQM) allows remote attackers to cause a denial of service (RPC service crash) via a queue registration request.
18955| [CVE-2003-0904] Microsoft Exchange 2003 and Outlook Web Access (OWA), when configured to use NTLM authentication, does not properly reuse HTTP connections, which can cause OWA users to view mailboxes of other users when Kerberos has been disabled as an authentication method for IIS 6.0, e.g. when SharePoint Services 2.0 is installed.
18956| [CVE-2003-0825] The Windows Internet Naming Service (WINS) for Microsoft Windows Server 2003, and possibly Windows NT and Server 2000, does not properly validate the length of certain packets, which allows attackers to cause a denial of service and possibly execute arbitrary code.
18957| [CVE-2003-0824] Unknown vulnerability in the SmartHTML interpreter (shtml.dll) in Microsoft FrontPage Server Extensions 2000 and 2002, and Microsoft SharePoint Team Services 2002, allows remote attackers to cause a denial of service (response failure) via a certain request.
18958| [CVE-2003-0819] Buffer overflow in the H.323 filter of Microsoft Internet Security and Acceleration Server 2000 allows remote attackers to execute arbitrary code in the Microsoft Firewall Service via certain H.323 traffic, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.
18959| [CVE-2003-0533] Stack-based buffer overflow in certain Active Directory service functions in LSASRV.DLL of the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via a packet that causes the DsRolerUpgradeDownlevelServer function to create long debug entries for the DCPROMO.LOG log file, as exploited by the Sasser worm.
18960| [CVE-2003-0506] Microsoft NetMeeting 3.01 2000 before SP4 allows remote attackers to cause a denial of service (shutdown of NetMeeting conference) via malformed packets, as demonstrated via the chat conversation.
18961| [CVE-2003-0349] Buffer overflow in the streaming media component for logging multicast requests in the ISAPI for the logging capability of Microsoft Windows Media Services (nsiislog.dll), as installed in IIS 5.0, allows remote attackers to execute arbitrary code via a large POST request to nsiislog.dll.
18962| [CVE-2003-0345] Buffer overflow in the SMB capability for Microsoft Windows XP, 2000, and NT allows remote attackers to cause a denial of service and possibly execute arbitrary code via an SMB packet that specifies a smaller buffer length than is required.
18963| [CVE-2003-0231] Microsoft SQL Server 7, 2000, and MSDE allows local or remote authenticated users to cause a denial of service (crash or hang) via a long request to a named pipe.
18964| [CVE-2003-0227] The logging capability for unicast and multicast transmissions in the ISAPI extension for Microsoft Windows Media Services in Microsoft Windows NT 4.0 and 2000, nsiislog.dll, allows remote attackers to cause a denial of service in Internet Information Server (IIS) and execute arbitrary code via a certain network request.
18965| [CVE-2003-0226] Microsoft Internet Information Services (IIS) 5.0 and 5.1 allows remote attackers to cause a denial of service via a long WebDAV request with a (1) PROPFIND or (2) SEARCH method, which generates an error condition that is not properly handled.
18966| [CVE-2003-0225] The ASP function Response.AddHeader in Microsoft Internet Information Server (IIS) 4.0 and 5.0 does not limit memory requests when constructing headers, which allow remote attackers to generate a large header to cause a denial of service (memory consumption) with an ASP page.
18967| [CVE-2003-0224] Buffer overflow in ssinc.dll for Microsoft Internet Information Services (IIS) 5.0 allows local users to execute arbitrary code via a web page with a Server Side Include (SSI) directive with a long filename, aka "Server Side Include Web Pages Buffer Overrun."
18968| [CVE-2003-0110] The Winsock Proxy service in Microsoft Proxy Server 2.0 and the Microsoft Firewall service in Internet Security and Acceleration (ISA) Server 2000 allow remote attackers to cause a denial of service (CPU consumption or packet storm) via a spoofed, malformed packet to UDP port 1745.
18969| [CVE-2003-0109] Buffer overflow in ntdll.dll on Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute arbitrary code, as demonstrated via a WebDAV request to IIS 5.0.
18970| [CVE-2003-0079] The DEC UDK processing feature in the hanterm (hanterm-xf) terminal emulator before 2.0.5 allows attackers to cause a denial of service via a certain character escape sequence that causes the terminal to enter a tight loop.
18971| [CVE-2003-0071] The DEC UDK processing feature in the xterm terminal emulator in XFree86 4.2.99.4 and earlier allows attackers to cause a denial of service via a certain character escape sequence that causes the terminal to enter a tight loop.
18972| [CVE-2003-0011] Unknown vulnerability in the DNS intrusion detection application filter for Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service (blocked traffic to DNS servers) via a certain type of incoming DNS request that is not properly handled.
18973| [CVE-2002-2164] Buffer overflow in Microsoft Outlook Express 5.0, 5.5, and 6.0 allows remote attackers to cause a denial of service (crash) via a long <A HREF> link.
18974| [CVE-2002-2117] Microsoft Windows XP allows remote attackers to cause a denial of service (CPU consumption) by flooding UDP port 500 (ISAKMP).
18975| [CVE-2002-2081] cphost.dll in Microsoft Site Server 3.0 allows remote attackers to cause a denial of service (disk consumption) via an HTTP POST of a file with a long TargetURL parameter, which causes Site Server to abort and leaves the uploaded file in c:\temp.
18976| [CVE-2002-1984] Microsoft Internet Explorer 5.0.1 through 6.0 on Windows 2000 or Windows XP allows remote attackers to cause a denial of service (crash) via an OBJECT tag that contains a crafted CLASSID (CLSID) value of "CLSID:00022613-0000-0000-C000-000000000046".
18977| [CVE-2002-1973] Buffer overflow in CHttpServer::OnParseError in the ISAPI extension (Isapi.cpp) when built using Microsoft Foundation Class (MFC) static libraries in Visual C++ 5.0, and 6.0 before SP3, as used in multiple products including BadBlue, allows remote attackers to cause a denial of service (access violation and crash) and possibly execute arbitrary code via a long query string that causes a parsing error.
18978| [CVE-2002-1908] Microsoft IIS 5.0 and 5.1 allows remote attackers to cause a denial of service (CPU consumption) via an HTTP request with a Host header that contains a large number of "/" (forward slash) characters.
18979| [CVE-2002-1876] Microsoft Exchange 2000 allows remote authenticated attackers to cause a denial of service via a large number of rapid requests, which consumes all of the licenses that are granted to Exchange by IIS.
18980| [CVE-2002-1873] Microsoft Exchange 2000, when used with Microsoft Remote Procedure Call (MSRPC), allows remote attackers to cause a denial of service (crash or memory consumption) via malformed MSRPC calls.
18981| [CVE-2002-1831] Microsoft MSN Messenger Service 1.0 through 4.6 allows remote attackers to cause a denial of service (crash) via an invite request that contains hex-encoded spaces (%20) in the Invitation-Cookie field.
18982| [CVE-2002-1790] The SMTP service in Microsoft Internet Information Services (IIS) 4.0 and 5.0 allows remote attackers to bypass anti-relaying rules and send spam or spoofed messages via encapsulated SMTP addresses, a similar vulnerability to CVE-1999-0682.
18983| [CVE-2002-1749] Windows 2000 Terminal Services, when using the disconnect feature of the client, does not properly lock itself if it is left idle until the screen saver activates and the user disconnects, which could allow attackers to gain administrator privileges.
18984| [CVE-2002-1714] Microsoft Internet Explorer 5.0 through 6.0 allows remote attackers to cause a denial of service (crash) via an object of type "text/html" with the DATA field that identifies the HTML document that contains the object, which may cause infinite recursion.
18985| [CVE-2002-1712] Microsoft Windows 2000 allows remote attackers to cause a denial of service (memory consumption) by sending a flood of empty TCP/IP packets with the ACK and FIN bits set to the NetBIOS port (TCP/139), as demonstrated by stream3.
18986| [CVE-2002-1705] Microsoft Internet Explorer 5.5 through 6.0 allows remote attackers to cause a denial of service (crash) via a Cascading Style Sheet (CSS) with the p{cssText} element declared and a bold font weight.
18987| [CVE-2002-1698] Buffer overflow in Microsoft MSN Messenger Service 1.0 through 4.6 allows remote attackers to cause a denial of service (crash) via a long FN (font) argument in the message header.
18988| [CVE-2002-1295] The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to cause a denial of service (crash) and possibly conduct other unauthorized activities via applet tags in HTML that bypass Java class restrictions (such as private constructors) by providing the class name in the code parameter, aka "Incomplete Java Object Instantiation Vulnerability."
18989| [CVE-2002-1294] The Microsoft Java implementation, as used in Internet Explorer, can provide HTML object references to applets via Javascript, which allows remote attackers to cause a denial of service (crash due to illegal memory accesses) and possibly conduct other unauthorized activities via an applet that uses those references to access proprietary Microsoft methods.
18990| [CVE-2002-1292] The Microsoft Java virtual machine (VM) build 5.0.3805 and earlier, as used in Internet Explorer, allows remote attackers to extend the Standard Security Manager (SSM) class (com.ms.security.StandardSecurityManager) and bypass intended StandardSecurityManager restrictions by modifying the (1) deniedDefinitionPackages or (2) deniedAccessPackages settings, causing a denial of service by adding Java applets to the list of applets that are prevented from running.
18991| [CVE-2002-1290] The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to read and modify the contents of the Clipboard via an applet that accesses the (1) ClipBoardGetText and (2) ClipBoardSetText methods of the INativeServices class.
18992| [CVE-2002-1289] The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to read restricted process memory, cause a denial of service (crash), and possibly execute arbitrary code via the getNativeServices function, which creates an instance of the com.ms.awt.peer.INativeServices (INativeServices) class, whose methods do not verify the memory addresses that are passed as parameters.
18993| [CVE-2002-1287] Stack-based buffer overflow in the Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to cause a denial of service via a long class name through (1) Class.forName or (2) ClassLoader.loadClass.
18994| [CVE-2002-1255] Microsoft Outlook 2002 allows remote attackers to cause a denial of service (repeated failure) via an email message with a certain invalid header field that is accessed using POP3, IMAP, or WebDAV, aka "E-mail Header Processing Flaw Could Cause Outlook 2002 to Fail."
18995| [CVE-2002-1214] Buffer overflow in Microsoft PPTP Service on Windows XP and Windows 2000 allows remote attackers to cause a denial of service (hang) and possibly execute arbitrary code via a certain PPTP packet with malformed control data.
18996| [CVE-2002-1142] Heap-based buffer overflow in the Remote Data Services (RDS) component of Microsoft Data Access Components (MDAC) 2.1 through 2.6, and Internet Explorer 5.01 through 6.0, allows remote attackers to execute code via a malformed HTTP request to the Data Stub.
18997| [CVE-2002-1141] An input validation error in the Sun Microsystems RPC library Services for Unix 3.0 Interix SD, as implemented on Microsoft Windows NT4, 2000, and XP, allows remote attackers to cause a denial of service via malformed fragmented RPC client packets, aka "Denial of service by sending an invalid RPC request."
18998| [CVE-2002-1140] The Sun Microsystems RPC library Services for Unix 3.0 Interix SD, as implemented on Microsoft Windows NT4, 2000, and XP, allows remote attackers to cause a denial of service (service hang) via malformed packet fragments, aka "Improper parameter size check leading to denial of service."
18999| [CVE-2002-0867] Microsoft Virtual Machine (VM) up to and including build 5.0.3805 allows remote attackers to cause a denial of service (crash) in Internet Explorer via invalid handle data in a Java applet, aka "Handle Validation Flaw."
19000| [CVE-2002-0864] The Remote Data Protocol (RDP) version 5.1 in Microsoft Windows XP allows remote attackers to cause a denial of service (crash) when Remote Desktop is enabled via a PDU Confirm Active data packet that does not set the Pattern BLT command, aka "Denial of Service in Remote Desktop."
19001| [CVE-2002-0729] Microsoft SQL Server 2000 allows remote attackers to cause a denial of service via a malformed 0x08 packet that is missing a colon separator.
19002| [CVE-2002-0724] Buffer overflow in SMB (Server Message Block) protocol in Microsoft Windows NT, Windows 2000, and Windows XP allows attackers to cause a denial of service (crash) via a SMB_COM_TRANSACTION packet with a request for the (1) NetShareEnum, (2) NetServerEnum2, or (3) NetServerEnum3, aka "Unchecked Buffer in Network Share Provider Can Lead to Denial of Service".
19003| [CVE-2002-0719] SQL injection vulnerability in the function that services for Microsoft Content Management Server (MCMS) 2001 allows remote attackers to execute arbitrary commands via an MCMS resource request for image files or other files.
19004| [CVE-2002-0697] Microsoft Metadirectory Services (MMS) 2.2 allows remote attackers to bypass authentication and modify sensitive data by using an LDAP client to directly connect to MMS and bypass the checks for MMS credentials.
19005| [CVE-2002-0694] The HTML Help facility in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP uses the Local Computer Security Zone when opening .chm files from the Temporary Internet Files folder, which allows remote attackers to execute arbitrary code via HTML mail that references or inserts a malicious .chm file containing shortcuts that can be executed, aka "Code Execution via Compiled HTML Help File."
19006| [CVE-2002-0693] Buffer overflow in the HTML Help ActiveX Control (hhctrl.ocx) in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute code via (1) a long parameter to the Alink function, or (2) script containing a long argument to the showHelp function.
19007| [CVE-2002-0692] Buffer overflow in SmartHTML Interpreter (shtml.dll) in Microsoft FrontPage Server Extensions (FPSE) 2000 and 2002 allows remote attackers to cause a denial of service (CPU consumption) or run arbitrary code, respectively, via a certain type of web file request.
19008| [CVE-2002-0650] The keep-alive mechanism for Microsoft SQL Server 2000 allows remote attackers to cause a denial of service (bandwidth consumption) via a "ping" style packet to the Resolution Service (UDP port 1434) with a spoofed IP address of another SQL Server system, which causes the two servers to exchange packets in an infinite loop.
19009| [CVE-2002-0649] Multiple buffer overflows in the Resolution Service for Microsoft SQL Server 2000 and Microsoft Desktop Engine 2000 (MSDE) allow remote attackers to cause a denial of service or execute arbitrary code via UDP packets to port 1434 in which (1) a 0x04 byte that causes the SQL Monitor thread to generate a long registry key name, or (2) a 0x08 byte with a long string causes heap corruption, as exploited by the Slammer/Sapphire worm.
19010| [CVE-2002-0642] The registry key containing the SQL Server service account information in Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, has insecure permissions, which allows local users to gain privileges, aka "Incorrect Permission on SQL Server Service Account Registry Key."
19011| [CVE-2002-0620] Buffer overflow in the Profile Service of Microsoft Commerce Server 2000 allows remote attackers to cause the server to fail or run arbitrary code in the LocalSystem security context via an input field using an affected API.
19012| [CVE-2002-0597] LANMAN service on Microsoft Windows 2000 allows remote attackers to cause a denial of service (CPU/memory exhaustion) via a stream of malformed data to microsoft-ds port 445.
19013| [CVE-2002-0444] Microsoft Windows 2000 running the Terminal Server 90-day trial version, and possibly other versions, does not apply group policies to incoming users when the number of connections to the SYSVOL share exceeds the maximum, e.g. with a maximum number of licenses, which can allow remote authenticated users to bypass group policies.
19014| [CVE-2002-0373] The Windows Media Device Manager (WMDM) Service in Microsoft Windows Media Player 7.1 on Windows 2000 systems allows local users to obtain LocalSystem rights via a program that calls the WMDM service to connect to an invalid local storage device, aka "Privilege Elevation through Windows Media Device Manager Service".
19015| [CVE-2002-0370] Buffer overflow in the ZIP capability for multiple products allows remote attackers to cause a denial of service or execute arbitrary code via ZIP files containing entries with long filenames, including (1) Microsoft Windows 98 with Plus! Pack, (2) Windows XP, (3) Windows ME, (4) Lotus Notes R4 through R6 (pre-gold), (5) Verity KeyView, and (6) Stuffit Expander before 7.0.
19016| [CVE-2002-0368] The Store Service in Microsoft Exchange 2000 allows remote attackers to cause a denial of service (CPU consumption) via a mail message with a malformed RFC message attribute, aka "Malformed Mail Attribute can Cause Exchange 2000 to Exhaust CPU Resources."
19017| [CVE-2002-0224] The MSDTC (Microsoft Distributed Transaction Service Coordinator) for Microsoft Windows 2000, Microsoft IIS 5.0 and SQL Server 6.5 through SQL 2000 0.0 allows remote attackers to cause a denial of service (crash or hang) via malformed (random) input.
19018| [CVE-2002-0154] Buffer overflows in extended stored procedures for Microsoft SQL Server 7.0 and 2000 allow remote attackers to cause a denial of service or execute arbitrary code via a database query with certain long arguments.
19019| [CVE-2002-0152] Buffer overflow in various Microsoft applications for Macintosh allows remote attackers to cause a denial of service (crash) or execute arbitrary code by invoking the file:// directive with a large number of / characters, which affects Internet Explorer 5.1, Outlook Express 5.0 through 5.0.2, Entourage v. X and 2001, PowerPoint v. X, 2001, and 98, and Excel v. X and 2001 for Macintosh.
19020| [CVE-2002-0151] Buffer overflow in Multiple UNC Provider (MUP) in Microsoft Windows operating systems allows local users to cause a denial of service or possibly gain SYSTEM privileges via a long UNC request.
19021| [CVE-2002-0147] Buffer overflow in the ASP data transfer mechanism in Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to cause a denial of service or execute code, aka "Microsoft-discovered variant of Chunked Encoding buffer overrun."
19022| [CVE-2002-0136] Microsoft Internet Explorer 5.5 on Windows 98 allows remote web pages to cause a denial of service (hang) via extremely long values for form fields such as INPUT and TEXTAREA, which can be automatically filled via Javascript.
19023| [CVE-2002-0101] Microsoft Internet Explorer 6.0 and earlier allows local users to cause a denial of service via an infinite loop for modeless dialogs showModelessDialog, which causes CPU usage while the focus for the dialog is not released.
19024| [CVE-2002-0057] XMLHTTP control in Microsoft XML Core Services 2.6 and later does not properly handle IE Security Zone settings, which allows remote attackers to read arbitrary files by specifying a local file as an XML Data Source.
19025| [CVE-2002-0055] SMTP service in Microsoft Windows 2000, Windows XP Professional, and Exchange 2000 allows remote attackers to cause a denial of service via a command with a malformed data transfer (BDAT) request.
19026| [CVE-2002-0054] SMTP service in (1) Microsoft Windows 2000 and (2) Internet Mail Connector (IMC) in Exchange Server 5.5 does not properly handle responses to NTLM authentication, which allows remote attackers to perform mail relaying via an SMTP AUTH command using null session credentials.
19027| [CVE-2002-0021] Network Product Identification (PID) Checker in Microsoft Office v. X for Mac allows remote attackers to cause a denial of service (crash) via a malformed product announcement.
19028| [CVE-2001-1533] ** DISPUTED * Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service via a flood of fragmented UDP packets. NOTE: the vendor disputes this issue, saying that it requires high bandwidth to exploit, and the server does not experience any instability. Therefore this "laws of physics" issue might not be included in CVE.
19029| [CVE-2001-1518] RunAs (runas.exe) in Windows 2000 only creates one session instance at a time, which allows local users to cause a denial of service (RunAs hang) by creating a named pipe session with the authentication server without any request for service. NOTE: the vendor disputes this vulnerability, however the vendor also presents a scenario in which other users could be affected if running on a Terminal Server. Therefore this is a vulnerability.
19030| [CVE-2001-1489] Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via a web page with a large number of images.
19031| [CVE-2001-1451] Memory leak in the SNMP LAN Manager (LANMAN) MIB extension for Microsoft Windows 2000 before SP3, when the Print Spooler is not running, allows remote attackers to cause a denial of service (memory consumption) via a large number of GET or GETNEXT requests.
19032| [CVE-2001-1450] Microsoft Internet Explorer 5.0 through 6.0 allows attackers to cause a denial of service (browser crash) via a crafted FTP URL such as "/.#./".
19033| [CVE-2001-1319] Microsoft Exchange 5.5 2000 allows remote attackers to cause a denial of service (hang) via exceptional BER encodings for the LDAP filter type field, as demonstrated by the PROTOS LDAPv3 test suite.
19034| [CVE-2001-1243] Scripting.FileSystemObject in asp.dll for Microsoft IIS 4.0 and 5.0 allows local or remote attackers to cause a denial of service (crash) via (1) creating an ASP program that uses Scripting.FileSystemObject to open a file with an MS-DOS device name, or (2) remotely injecting the device name into ASP programs that internally use Scripting.FileSystemObject.
19035| [CVE-2001-1219] Microsoft Internet Explorer 6.0 and earlier allows malicious website operators to cause a denial of service (client crash) via JavaScript that continually refreshes the window via self.location.
19036| [CVE-2001-1218] Microsoft Internet Explorer for Unix 5.0SP1 allows local users to possibly cause a denial of service (crash) in CDE or the X server on Solaris 2.6 by rapidly scrolling Chinese characters or maximizing the window.
19037| [CVE-2001-1186] Microsoft IIS 5.0 allows remote attackers to cause a denial of service via an HTTP request with a content-length value that is larger than the size of the request, which prevents IIS from timing out the connection.
19038| [CVE-2001-1055] The Microsoft Windows network stack allows remote attackers to cause a denial of service (CPU consumption) via a flood of malformed ARP request packets with random source IP and MAC addresses, as demonstrated by ARPNuke.
19039| [CVE-2001-0860] Terminal Services Manager MMC in Windows 2000 and XP trusts the Client Address (IP address) that is provided by the client instead of obtaining it from the packet headers, which allows clients to spoof their public IP address, e.g. through a Network Address Translation (NAT).
19040| [CVE-2001-0666] Outlook Web Access (OWA) in Microsoft Exchange 2000 allows an authenticated user to cause a denial of service (CPU consumption) via a malformed OWA request for a deeply nested folder within the user's mailbox.
19041| [CVE-2001-0663] Terminal Server in Windows NT and Windows 2000 allows remote attackers to cause a denial of service via a sequence of invalid Remote Desktop Protocol (RDP) packets.
19042| [CVE-2001-0547] Memory leak in the proxy service in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows local attackers to cause a denial of service (resource exhaustion).
19043| [CVE-2001-0546] Memory leak in H.323 Gatekeeper Service in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service (resource exhaustion) via a large amount of malformed H.323 data.
19044| [CVE-2001-0540] Memory leak in Terminal servers in Windows NT and Windows 2000 allows remote attackers to cause a denial of service (memory exhaustion) via a large number of malformed Remote Desktop Protocol (RDP) requests to port 3389.
19045| [CVE-2001-0509] Vulnerabilities in RPC servers in (1) Microsoft Exchange Server 2000 and earlier, (2) Microsoft SQL Server 2000 and earlier, (3) Windows NT 4.0, and (4) Windows 2000 allow remote attackers to cause a denial of service via malformed inputs.
19046| [CVE-2001-0505] Multiple memory leaks in Microsoft Services for Unix 2.0 allow remote attackers to cause a denial of service (memory exhaustion) via a large number of malformed requests to (1) the Telnet service, or (2) the NFS service.
19047| [CVE-2001-0504] Vulnerability in authentication process for SMTP service in Microsoft Windows 2000 allows remote attackers to use incorrect credentials to gain privileges and conduct activites such as mail relaying.
19048| [CVE-2001-0503] Microsoft NetMeeting 3.01 with Remote Desktop Sharing enabled allows remote attackers to cause a denial of service via a malformed string to the NetMeeting service port, aka a variant of the "NetMeeting Desktop Sharing" vulnerability.
19049| [CVE-2001-0351] Microsoft Windows 2000 telnet service allows a local user to make a certain system call that allows the user to terminate a Telnet session and cause a denial of service.
19050| [CVE-2001-0350] Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, which allows local users to execute arbitrary commands by creating a named pipe with the predictable name and associating a malicious program with it, the second of two variants of this vulnerability.
19051| [CVE-2001-0349] Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, which allows local users to execute arbitrary commands by creating a named pipe with the predictable name and associating a malicious program with it, the first of two variants of this vulnerability.
19052| [CVE-2001-0348] Microsoft Windows 2000 telnet service allows attackers to cause a denial of service (crash) via a long logon command that contains a backspace.
19053| [CVE-2001-0347] Information disclosure vulnerability in Microsoft Windows 2000 telnet service allows remote attackers to determine the existence of user accounts such as Guest, or log in to the server without specifying the domain name, via a malformed userid.
19054| [CVE-2001-0346] Handle leak in Microsoft Windows 2000 telnet service allows attackers to cause a denial of service by starting a large number of sessions and terminating them.
19055| [CVE-2001-0345] Microsoft Windows 2000 telnet service allows attackers to prevent idle Telnet sessions from timing out, causing a denial of service by creating a large number of idle sessions.
19056| [CVE-2001-0340] An interaction between the Outlook Web Access (OWA) service in Microsoft Exchange 2000 Server and Internet Explorer allows attackers to execute malicious script code against a user's mailbox via a message attachment that contains HTML code, which is executed automatically.
19057| [CVE-2001-0337] The Microsoft MS01-014 and MS01-016 patches for IIS 5.0 and earlier introduce a memory leak which allows attackers to cause a denial of service via a series of requests.
19058| [CVE-2001-0336] The Microsoft MS00-060 patch for IIS 5.0 and earlier introduces an error which allows attackers to cause a denial of service via a malformed request.
19059| [CVE-2001-0245] Microsoft Index Server 2.0 in Windows NT 4.0, and Indexing Service in Windows 2000, allows remote attackers to read server-side include files via a malformed search request, aka a new variant of the "Malformed Hit-Highlighting" vulnerability.
19060| [CVE-2001-0239] Microsoft Internet Security and Acceleration (ISA) Server 2000 Web Proxy allows remote attackers to cause a denial of service via a long web request with a specific type.
19061| [CVE-2001-0237] Memory leak in Microsoft 2000 domain controller allows remote attackers to cause a denial of service by repeatedly connecting to the Kerberos service and then disconnecting without sending any data.
19062| [CVE-2001-0146] IIS 5.0 and Microsoft Exchange 2000 allow remote attackers to cause a denial of service (memory allocation error) by repeatedly sending a series of specially formatted URL's.
19063| [CVE-2001-0048] The "Configure Your Server" tool in Microsoft 2000 domain controllers installs a blank password for the Directory Service Restore Mode, which allows attackers with physical access to the controller to install malicious programs, aka the "Directory Service Restore Mode Password" vulnerability.
19064| [CVE-2001-0014] Remote Data Protocol (RDP) in Windows 2000 Terminal Service does not properly handle certain malformed packets, which allows remote attackers to cause a denial of service, aka the "Invalid RDP Data" vulnerability.
19065| [CVE-2000-1217] Microsoft Windows 2000 before Service Pack 2 (SP2), when running in a non-Windows 2000 domain and using NTLM authentication, and when credentials of an account are locally cached, allows local users to bypass account lockout policies and make an unlimited number of login attempts, aka the "Domain Account Lockout" vulnerability.
19066| [CVE-2000-1089] Buffer overflow in Microsoft Phone Book Service allows local users to execute arbitrary commands, aka the "Phone Book Service Buffer Overflow" vulnerability.
19067| [CVE-2000-1088] The xp_SetSQLSecurity function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.
19068| [CVE-2000-1087] The xp_proxiedmetadata function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.
19069| [CVE-2000-1086] The xp_printstatements function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.
19070| [CVE-2000-1085] The xp_peekqueue function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.
19071| [CVE-2000-1084] The xp_updatecolvbm function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.
19072| [CVE-2000-1083] The xp_showcolv function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.
19073| [CVE-2000-1082] The xp_enumresultset function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.
19074| [CVE-2000-1081] The xp_displayparamstmt function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.
19075| [CVE-2000-1006] Microsoft Exchange Server 5.5 does not properly handle a MIME header with a blank charset specified, which allows remote attackers to cause a denial of service via a charset="" command, aka the "Malformed MIME Header" vulnerability.
19076| [CVE-2000-0983] Microsoft NetMeeting with Remote Desktop Sharing enabled allows remote attackers to cause a denial of service (CPU utilization) via a sequence of null bytes to the NetMeeting port, aka the "NetMeeting Desktop Sharing" vulnerability.
19077| [CVE-2000-0942] The CiWebHitsFile component in Microsoft Indexing Services for Windows 2000 allows remote attackers to conduct a cross site scripting (CSS) attack via a CiRestriction parameter in a .htw request, aka the "Indexing Services Cross Site Scripting" vulnerability.
19078| [CVE-2000-0929] Microsoft Windows Media Player 7 allows attackers to cause a denial of service in RTF-enabled email clients via an embedded OCX control that is not closed properly, aka the "OCX Attachment" vulnerability.
19079| [CVE-2000-0858] Vulnerability in Microsoft Windows NT 4.0 allows remote attackers to cause a denial of service in IIS by sending it a series of malformed requests which cause INETINFO.EXE to fail, aka the "Invalid URL" vulnerability.
19080| [CVE-2000-0849] Race condition in Microsoft Windows Media server allows remote attackers to cause a denial of service in the Windows Media Unicast Service via a malformed request, aka the "Unicast Service Race Condition" vulnerability.
19081| [CVE-2000-0771] Microsoft Windows 2000 allows local users to cause a denial of service by corrupting the local security policy via malformed RPC traffic, aka the "Local Security Policy Corruption" vulnerability.
19082| [CVE-2000-0756] Microsoft Outlook 2000 does not properly process long or malformed fields in vCard (.vcf) files, which allows attackers to cause a denial of service.
19083| [CVE-2000-0742] The IPX protocol implementation in Microsoft Windows 95 and 98 allows remote attackers to cause a denial of service by sending a ping packet with a source IP address that is a broadcast address, aka the "Malformed IPX Ping Packet" vulnerability.
19084| [CVE-2000-0709] The shtml.exe component of Microsoft FrontPage 2000 Server Extensions 1.1 allows remote attackers to cause a denial of service in some components by requesting a URL whose name includes a standard DOS device name.
19085| [CVE-2000-0654] Microsoft Enterprise Manager allows local users to obtain database passwords via the Data Transformation Service (DTS) package Registered Servers Dialog dialog, aka a variant of the "DTS Password" vulnerability.
19086| [CVE-2000-0524] Microsoft Outlook and Outlook Express allow remote attackers to cause a denial of service by sending email messages with blank fields such as BCC, Reply-To, Return-Path, or From.
19087| [CVE-2000-0495] Microsoft Windows Media Encoder allows remote attackers to cause a denial of service via a malformed request, aka the "Malformed Windows Media Encoder Request" vulnerability.
19088| [CVE-2000-0485] Microsoft SQL Server allows local users to obtain database passwords via the Data Transformation Service (DTS) package Properties dialog, aka the "DTS Password" vulnerability.
19089| [CVE-2000-0402] The Mixed Mode authentication capability in Microsoft SQL Server 7.0 stores the System Administrator (sa) account in plaintext in a log file which is readable by any user, aka the "SQL Server 7.0 Service Pack Password" vulnerability.
19090| [CVE-2000-0331] Buffer overflow in Microsoft command processor (CMD.EXE) for Windows NT and Windows 2000 allows a local user to cause a denial of service via a long environment variable, aka the "Malformed Environment Variable" vulnerability.
19091| [CVE-2000-0305] Windows 95, Windows 98, Windows 2000, Windows NT 4.0, and Terminal Server systems allow a remote attacker to cause a denial of service by sending a large number of identical fragmented IP packets, aka jolt2 or the "IP Fragment Reassembly" vulnerability.
19092| [CVE-2000-0304] Microsoft IIS 4.0 and 5.0 with the IISADMPWD virtual directory installed allows a remote attacker to cause a denial of service via a malformed request to the inetinfo.exe program, aka the "Undelimited .HTR Request" vulnerability.
19093| [CVE-2000-0260] Buffer overflow in the dvwssr.dll DLL in Microsoft Visual Interdev 1.0 allows users to cause a denial of service or execute commands, aka the "Link View Server-Side Component" vulnerability.
19094| [CVE-2000-0232] Microsoft TCP/IP Printing Services, aka Print Services for Unix, allows an attacker to cause a denial of service via a malformed TCP/IP print request.
19095| [CVE-2000-0228] Microsoft Windows Media License Manager allows remote attackers to cause a denial of service by sending a malformed request that causes the manager to halt, aka the "Malformed Media License Request" Vulnerability.
19096| [CVE-2000-0212] InterAccess TelnetID Server 4.0 allows remote attackers to conduct a denial of service via malformed terminal client configuration information.
19097| [CVE-2000-0200] Buffer overflow in Microsoft Clip Art Gallery allows remote attackers to cause a denial of service or execute commands via a malformed CIL (clip art library) file, aka the "Clip Art Buffer Overrun" vulnerability.
19098| [CVE-2000-0168] Microsoft Windows 9x operating systems allow an attacker to cause a denial of service via a pathname that includes file device names, aka the "DOS Device in Path Name" vulnerability.
19099| [CVE-2000-0089] The rdisk utility in Microsoft Terminal Server Edition and Windows NT 4.0 stores registry hive information in a temporary file with permissions that allow local users to read it, aka the "RDISK Registry Enumeration File" vulnerability.
19100| [CVE-2000-0073] Buffer overflow in Microsoft Rich Text Format (RTF) reader allows attackers to cause a denial of service via a malformed control word.
19101| [CVE-2000-0053] Microsoft Commercial Internet System (MCIS) IMAP server allows remote attackers to cause a denial of service via a malformed IMAP request.
19102| [CVE-1999-1591] Microsoft Internet Information Services (IIS) server 4.0 SP4, without certain hotfixes released for SP4, does not require authentication credentials under certain conditions, which allows remote attackers to bypass authentication requirements, as demonstrated by connecting via Microsoft Visual InterDev 6.0.
19103| [CVE-1999-1579] The Cenroll ActiveX control (xenroll.dll) for Terminal Server Editions of Windows NT 4.0 and Windows NT Server 4.0 before SP6 allows remote attackers to cause a denial of service (resource consumption) by creating a large number of arbitrary files on the target machine.
19104| [CVE-1999-1544] Buffer overflow in FTP server in Microsoft IIS 3.0 and 4.0 allows local and sometimes remote attackers to cause a denial of service via a long NLST (ls) command.
19105| [CVE-1999-1164] Microsoft Outlook client allows remote attackers to cause a denial of service by sending multiple email messages with the same X-UIDL headers, which causes Outlook to hang.
19106| [CVE-1999-1070] Buffer overflow in ping CGI program in Xylogics Annex terminal service allows remote attackers to cause a denial of service via a long query parameter.
19107| [CVE-1999-1043] Microsoft Exchange Server 5.5 and 5.0 does not properly handle (1) malformed NNTP data, or (2) malformed SMTP data, which allows remote attackers to cause a denial of service (application error).
19108| [CVE-1999-1016] Microsoft HTML control as used in (1) Internet Explorer 5.0, (2) FrontPage Express, (3) Outlook Express 5, and (4) Eudora, and possibly others, allows remote malicious web site or HTML emails to cause a denial of service (100% CPU consumption) via large HTML form fields such as text inputs in a table cell.
19109| [CVE-1999-1011] The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x exposes unsafe methods, which allows remote attackers to execute arbitrary commands.
19110| [CVE-1999-0999] Microsoft SQL 7.0 server allows a remote attacker to cause a denial of service via a malformed TDS packet.
19111| [CVE-1999-0945] Buffer overflow in Internet Mail Service (IMS) for Microsoft Exchange 5.5 and 5.0 allows remote attackers to conduct a denial of service via AUTH or AUTHINFO commands.
19112| [CVE-1999-0681] Buffer overflow in Microsoft FrontPage Server Extensions (PWS) 3.0.2.926 on Windows 95, and possibly other versions, allows remote attackers to cause a denial of service via a long URL.
19113| [CVE-1999-0680] Windows NT Terminal Server performs extra work when a client opens a new connection but before it is authenticated, allowing for a denial of service.
19114| [CVE-1999-0419] When the Microsoft SMTP service attempts to send a message to a server and receives a 4xx error code, it quickly and repeatedly attempts to redeliver the message, causing a denial of service.
19115| [CVE-1999-0288] The WINS server in Microsoft Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service (process termination) via invalid UDP frames to port 137 (NETBIOS Name Service), as demonstrated via a flood of random packets.
19116|
19117| SecurityFocus - https://www.securityfocus.com/bid/:
19118| [23899] Microsoft Windows Terminal Services Remote Security Restriction Bypass Vulnerability
19119| [10325] Microsoft Windows Terminal Server Patch Unspecified Denial Of Service Vulnerability
19120| [8102] Microsoft Windows Terminal Service Kerberos Double Authorization Data Entry Vulnerability
19121| [8098] Microsoft Windows 2000 Terminal Services Named Pipe System Account Access Vulnerability
19122| [5535] Microsoft Terminal Services Inactive Console Screensaver Lock Failure Weakness
19123| [5376] Microsoft Windows Terminal Services Denial Of Service Vulnerability
19124| [4095] Microsoft Windows 2000 Server Terminal Services Failure To Lock Terminal Vulnerability
19125| [3541] Microsoft Windows Terminal Services False IP Address Vulnerability
19126| [3445] Microsoft Windows 2000/NT Terminal Server Service RDP DoS Vulnerability
19127| [3099] Microsoft Windows Terminal Server Service DoS Vulnerability
19128| [104402] Microsoft Windows Hyper-V CVE-2018-8218 Remote Denial of Service Vulnerability
19129| [104391] Microsoft Windows CVE-2018-8205 Local Denial of Service Vulnerability
19130| [104389] Microsoft Windows Code Integrity Module CVE-2018-1040 Denial of Service Vulnerability
19131| [104361] Microsoft Windows 'HTTP.sys' CVE-2018-8226 Denial of Service Vulnerability
19132| [104359] Microsoft Windows WebDAV CVE-2018-8175 Denial of Service Vulnerability
19133| [104061] Microsoft Windows Host Compute Service Shim CVE-2018-8115 Remote Code Execution Vulnerability
19134| [104060] Microsoft .NET CVE-2018-0765 Denial Of Service Vulnerability
19135| [103705] Microsoft Windows Graphics Component CVE-2018-8116 Denial of Service Vulnerability
19136| [103652] Microsoft Windows SNMP Service CVE-2018-0967 Denial of Service Vulnerability
19137| [103651] Microsoft Windows Remote Desktop Protocol CVE-2018-0976 Denial of Service Vulnerability
19138| [103650] Microsoft Windows 'HTTP.sys' CVE-2018-0956 Denial of Service Vulnerability
19139| [103381] Microsoft Windows Storage Services CVE-2018-0983 Local Privilege Escalation Vulnerability
19140| [103261] Microsoft Windows Hyper-V CVE-2018-0885 Remote Denial of Service Vulnerability
19141| [103226] Microsoft ASP.NET CVE-2018-0808 Denial Of Service Vulnerability
19142| [103225] Microsoft .NET CVE-2018-0875 Denial Of Service Vulnerability
19143| [102924] Microsoft Windows SMB Server CVE-2018-0833 Denial of Service Vulnerability
19144| [102387] Microsoft .NET Framework CVE-2018-0764 Remote Denial of Service Vulnerability
19145| [102361] Microsoft Windows IPSec CVE-2018-0753 Denial of Service Vulnerability
19146| [101835] Microsoft ASP.NET Core CVE-2017-11883 Denial of Service Vulnerability
19147| [101711] Microsoft Windows Search CVE-2017-11788 Remote Denial of Service Vulnerability
19148| [101710] Microsoft ASP.NET Core CVE-2017-11770 Denial of Service Vulnerability
19149| [101192] Microsoft Windows WAV File Handling Denial of Service Vulnerability
19150| [101164] Microsoft Windows Subsystem for Linux CVE-2017-8703 Local Denial of Service Vulnerability
19151| [101140] Microsoft Windows SMB Server CVE-2017-11781 Denial of Service Vulnerability
19152| [100787] Microsoft Windows Hyper-V CVE-2017-8704 Remote Denial of Service Vulnerability
19153| [100079] Microsoft Windows Remote Desktop Protocol CVE-2017-8673 Denial of Service Vulnerability
19154| [100065] Microsoft Windows CVE-2017-8627 Local Denial of Service Vulnerability
19155| [100042] Microsoft Windows Hyper-V CVE-2017-8623 Remote Denial of Service Vulnerability
19156| [100038] Microsoft Windows NetBIOS CVE-2017-0174 Denial of Service Vulnerability
19157| [99432] Microsoft .NET CVE-2017-8585 Denial of Service Vulnerability
19158| [99413] Microsoft Windows Explorer CVE-2017-8587 Denial of Service Vulnerability
19159| [98833] Microsoft Windows CVE-2017-8515 Denial of Service Vulnerability
19160| [98729] Microsoft Windows NTFS File System Denial of Service Vulnerability
19161| [98708] Microsoft Malware Protection Engine CVE-2017-8536 Remote Denial of Service Vulnerability
19162| [98707] Microsoft Malware Protection Engine CVE-2017-8542 Remote Denial of Service Vulnerability
19163| [98705] Microsoft Malware Protection Engine CVE-2017-8537 Remote Denial of Service Vulnerability
19164| [98704] Microsoft Malware Protection Engine CVE-2017-8539 Remote Denial of Service Vulnerability
19165| [98702] Microsoft Malware Protection Engine CVE-2017-8535 Remote Denial of Service Vulnerability
19166| [98658] Microsoft Windows Type 1 Fonts Remote Denial of Service Vulnerability
19167| [98274] Microsoft Windows SMB Server CVE-2017-0273 Remote Denial of Service Vulnerability
19168| [98273] Microsoft Windows SMB Server CVE-2017-0280 Remote Denial of Service Vulnerability
19169| [98263] Microsoft Windows SMB Server CVE-2017-0269 Remote Denial of Service Vulnerability
19170| [98116] Microsoft ASP.NET Core CVE-2017-0247 Denial of Service Vulnerability
19171| [98097] Microsoft Windows CVE-2017-0171 Denial of Service Vulnerability
19172| [97466] Microsoft Windows CVE-2017-0191 Denial of Service Vulnerability
19173| [97448] Microsoft Windows Active Directory CVE-2017-0164 Denial of Service Vulnerability
19174| [97438] Microsoft Windows Hyper-V CVE-2017-0186 Remote Denial of Service Vulnerability
19175| [97437] Microsoft Windows Hyper-V CVE-2017-0185 Remote Denial of Service Vulnerability
19176| [97435] Microsoft Windows Hyper-V CVE-2017-0184 Remote Denial of Service Vulnerability
19177| [97428] Microsoft Windows Hyper-V CVE-2017-0183 Remote Denial of Service Vulnerability
19178| [97427] Microsoft Windows Hyper-V CVE-2017-0182 Remote Denial of Service Vulnerability
19179| [97426] Microsoft Windows Hyper-V CVE-2017-0179 Remote Denial of Service Vulnerability
19180| [97416] Microsoft Windows Hyper-V CVE-2017-0178 Remote Denial of Service Vulnerability
19181| [97127] Microsoft Internet Information Services CVE-2017-7269 Buffer Overflow Vulnerability
19182| [96925] Palo Alto Networks Terminal Services CVE-2017-6356 Information Disclosure Vulnerability
19183| [96642] Microsoft Windows Hyper-V CVE-2017-0098 Remote Denial of Service Vulnerability
19184| [96641] Microsoft Windows Hyper-V CVE-2017-0074 Remote Denial of Service Vulnerability
19185| [96640] Microsoft Windows Hyper-V CVE-2017-0099 Remote Denial of Service Vulnerability
19186| [96639] Microsoft Windows Hyper-V CVE-2017-0097 Remote Denial of Service Vulnerability
19187| [96636] Microsoft Windows Hyper-V CVE-2017-0076 Remote Denial of Service Vulnerability
19188| [96069] Microsoft XML Core Services CVE-2017-0022 Information Disclosure Vulnerability
19189| [96045] Microsoft Office CVE-2017-0029 Denial of Service Vulnerability
19190| [96026] Microsoft Windows Hyper-V CVE-2017-0051 Remote Denial of Service Vulnerability
19191| [95834] Microsoft ASP.NET Core MVC Denial of Service Vulnerability
19192| [95823] Terminal Services Agent CVE-2017-5328 Spoofing Vulnerability
19193| [95818] Palo Alto Networks Terminal Services Agent CVE-2017-5329 Local Privilege Escalation Vulnerability
19194| [95318] Microsoft Windows LSASS CVE-2017-0004 Denial of Service Vulnerability
19195| [94043] Microsoft SQL Server Master Data Services CVE-2016-7251 Cross Site Scripting Vulnerability
19196| [94040] Microsoft Windows CVE-2016-7237 Denial of Service Vulnerability
19197| [94029] Microsoft Office CVE-2016-7244 Denial of Service Vulnerability
19198| [93481] Microsoft Windows 'Cryptography API: Next Generation' Denial of Service Vulnerability
19199| [92850] Microsoft Windows CVE-2016-3369 Denial of Service Vulnerability
19200| [91118] Microsoft Windows Active Directory CVE-2016-3226 Denial of Service Vulnerability
19201| [91113] Microsoft Windows StructuredQuery Component CVE-2016-3230 Denial of Service Vulnerability
19202| [90065] Microsoft Windows Kernel 'Win32k.sys' CVE-2016-0174 Local Privilege Escalation Vulnerability
19203| [89764] Microsoft Internet Explorer CVE-2001-1539 Denial-Of-Service Vulnerability
19204| [87122] Microsoft Outlook Express CVE-2003-0301 Denial-Of-Service Vulnerability
19205| [86214] Microsoft Atlas framework CVE-2007-2380 Denial-Of-Service Vulnerability
19206| [85909] Microsoft XML Core Services CVE-2016-0147 Remote Code Execution Vulnerability
19207| [85908] Microsoft Windows 'HTTP.sys' CVE-2016-0150 Denial of Service Vulnerability
19208| [84758] Microsoft Windows CVE-2008-4323 Denial-Of-Service Vulnerability
19209| [84563] Microsoft Windows DNS CVE-2008-6194 Denial-Of-Service Vulnerability
19210| [84071] Microsoft Windows OpenType Fonts CVE-2016-0120 Remote Denial of Service Vulnerability
19211| [82717] Microsoft .NET Framework CVE-2016-0033 Stack Overflow Denial of Service Vulnerability
19212| [82513] Microsoft Network Policy Server RADIUS Implementation CVE-2016-0050 Denial of Service Vulnerability
19213| [82511] Microsoft Windows CVE-2016-0044 DLL Loading Denial of Service Vulnerability
19214| [82507] Microsoft Active Directory Federation Services CVE-2016-0037 Denial of Service Vulnerability
19215| [82492] Microsoft SMTP Service CVE-1999-0419 Denial-Of-Service Vulnerability
19216| [81429] Microsoft Internet Explorer CVE-2006-3200 Denial-Of-Service Vulnerability
19217| [80383] Microsoft Internet Information Services CVE-2003-1566 Information Disclosure Vulnerability
19218| [79431] Microsoft Internet Explorer CVE-2009-2668 Denial-Of-Service Vulnerability
19219| [79383] Microsoft Internet Explorer CVE-2009-3019 Denial-Of-Service Vulnerability
19220| [78309] Microsoft Internet Explorer CVE-2003-1305 Denial-Of-Service Vulnerability
19221| [77481] Microsoft Windows IPSec CVE-2015-6111 Denial of Service Vulnerability
19222| [76651] Microsoft Internet Explorer Stack Overflow Condition Denial of Service Vulnerability
19223| [76567] Microsoft .NET Framework Model View Controller CVE-2015-2526 Remote Denial of Service Vulnerability
19224| [76559] Microsoft Windows Journal CVE-2015-2516 Denial of Service Vulnerability
19225| [76554] Microsoft Active Directory CVE-2015-2535 Denial of Service Vulnerability
19226| [76259] Microsoft Windows UDDI Services CVE-2015-2475 Cross Site Scripting Vulnerability
19227| [76257] Microsoft XML Core Services CVE-2015-2471 Man in the Middle Information Disclosure Vulnerability
19228| [76232] Microsoft XML Core Services CVE-2015-2440 Information Disclosure Vulnerability
19229| [76229] Microsoft XML Core Services CVE-2015-2434 Man in the Middle Information Disclosure Vulnerability
19230| [75633] Microsoft Windows 'Netlogon' Service CVE-2015-2374 Remote Privilege Escalation Vulnerability
19231| [75023] Microsoft Active Directory Federation Services CVE-2015-1757 Privilege Escalation Vulnerability
19232| [74492] Microsoft Windows Service Control Manager CVE-2015-1702 Remote Privilege Escalation Vulnerability
19233| [74486] Microsoft Windows CVE-2015-1681 Denial of Service Vulnerability
19234| [74482] Microsoft .NET Framework CVE-2015-1672 Remote Denial of Service Vulnerability
19235| [74015] Microsoft Windows Hyper-V CVE-2015-1647 Remote Denial of Service Vulnerability
19236| [74009] Microsoft XML Core Services CVE-2015-1646 Same Origin Policy Security Bypass Vulnerability
19237| [74002] Microsoft Active Directory Federation Services CVE-2015-1638 Information Disclosure Vulnerability
19238| [72921] Microsoft Remote Desktop Protocol CVE-2015-0079 Denial of Service Vulnerability
19239| [72892] Microsoft Windows Adobe Font Driver CVE-2015-0074 Denial of Service Vulnerability
19240| [72886] Microsoft Windows Text Services CVE-2015-0081 Remote Code Execution Vulnerability
19241| [72472] Microsoft Windows Kernel Font Driver CVE-2015-0060 Denial of Service Vulnerability
19242| [71968] Microsoft Windows CVE-2015-0014 Telnet Service Buffer Overflow Vulnerability
19243| [71933] Microsoft Windows Network Policy Server CVE-2015-0015 Remote Denial of Service Vulnerability
19244| [70957] Microsoft XML Core Services CVE-2014-4118 Remote Code Execution Vulnerability
19245| [70949] Microsoft Windows Kernel TrueType Font Parsing CVE-2014-6317 Denial of Service Vulnerability
19246| [70938] Microsoft Active Directory Federation Services CVE-2014-6331 Information Disclosure Vulnerability
19247| [70937] Microsoft Internet Information Services CVE-2014-4078 Security Bypass Vulnerability
19248| [69603] Microsoft .NET Framework CVE-2014-4072 Remote Denial of Service Vulnerability
19249| [69592] Microsoft Lync Server CVE-2014-4071 Remote Denial of Service Vulnerability
19250| [69586] Microsoft Lync Server CVE-2014-4068 Remote Denial of Service Vulnerability
19251| [69112] Microsoft Windows Installer Service CVE-2014-1814 Local Privilege Escalation Vulnerability
19252| [69088] Microsoft SQL Server CVE-2014-4061 Local Denial of Service Vulnerability
19253| [69071] Microsoft SQL Server Master Data Services CVE-2014-1820 Cross Site Scripting Vulnerability
19254| [68393] Microsoft Service Bus AMQP Message Handling Remote Denial of Service Vulnerability
19255| [68076] Microsoft Malware Protection Engine CVE-2014-2779 Remote Denial of Service Vulnerability
19256| [67895] Microsoft XML Core Services CVE-2014-1816 Information Disclosure Vulnerability
19257| [67888] Microsoft Windows TCP/IP Protocol CVE-2014-1811 Remote Denial of Service Vulnerability
19258| [67758] Microsoft Internet Explorer 'TryGetValueAndRemove()' Method Remote Denial of Service Vulnerability
19259| [67743] Microsoft Windows 'GreSetPaletteEntries()' Local Denial of Service Vulnerability
19260| [67742] Microsoft Windows Touch Injection API Local Denial of Service Vulnerability
19261| [67281] Microsoft Windows iSCSI Connections Handling CVE-2014-0256 Remote Denial of Service Vulnerability
19262| [67280] Microsoft Windows iSCSI Packets Handling CVE-2014-0255 Remote Denial of Service Vulnerability
19263| [65854] Microsoft XMLDOM ActiveX Control CVE-2013-7332 Remote Denial of Service Vulnerability
19264| [65415] Microsoft .NET Framework CVE-2014-0253 Remote Denial of Service Vulnerability
19265| [65409] Microsoft Windows TCP/IP IPv6 Router Advertisement Remote Denial of Service Vulnerability
19266| [65407] Microsoft XML Core Services CVE-2014-0266 Information Disclosure Vulnerability
19267| [64724] Microsoft Dynamics AX CVE-2014-0261 Remote Denial of Service Vulnerability
19268| [64091] Microsoft Windows Kernel 'Win32k.sys' CVE-2013-5058 Local Denial of Service Vulnerability
19269| [64057] Microsoft Windows Kernel 'IsHandleEntrySecure()' Function Local Denial of Service Vulnerability
19270| [63777] Microsoft Word '.doc' File Remote Denial of Service Vulnerability
19271| [63561] Microsoft Windows XML Digital Signatures CVE-2013-3869 Remote Denial of Service Vulnerability
19272| [62820] Microsoft .NET Framework CVE-2013-3860 Remote Denial of Service Vulnerability
19273| [62807] Microsoft .NET Framework CVE-2013-3861 Remote Denial of Service Vulnerability
19274| [62205] Microsoft SharePoint CVE-2013-0081 Denial of Service Vulnerability
19275| [62184] Microsoft Windows Active Directory CVE-2013-3868 Denial of Service Vulnerability
19276| [62182] Microsoft Windows Service Control Manager CVE-2013-3862 Local Privilege Escalation Vulnerability
19277| [61685] Microsoft NAT Driver CVE-2013-3182 Denial of Service Vulnerability
19278| [61672] Microsoft Active Directory Federation Services CVE-2013-3185 Information Disclosure Vulnerability
19279| [61666] Microsoft Windows TCP/IP ICMPv6 CVE-2013-3183 Remote Denial of Service Vulnerability
19280| [61334] Microsoft Windows Movie Maker '.wav' File Denial of Service Vulnerability
19281| [60951] Microsoft Windows Kernel 'Win32k.sys' CVE-2013-3172 Local Denial of Service Vulnerability
19282| [60407] Microsoft Windows Print Spooler Service CVE-2013-1339 Local Privilege Escalation Vulnerability
19283| [60358] Microsoft Windows TCP/IP Driver CVE-2013-3138 Remote Denial of Service Vulnerability
19284| [60159] Microsoft Windows Kernel 'Win32k.sys' CVE-2013-3661 Local Denial Of Service Vulnerability
19285| [59784] Microsoft Windows 'HTTP.sys' Remote Denial of Service Vulnerability
19286| [58853] Microsoft Windows CVE-2013-1291 OpenType Font Parsing Remote Denial of Service Vulnerability
19287| [58848] Microsoft Windows Active Directory CVE-2013-1282 Denial of Service Vulnerability
19288| [58560] Microsoft Windows CVE-2013-2558 Denial of Service Vulnerability
19289| [58372] Microsoft SharePoint CVE-2013-0085 Denial of Service Vulnerability
19290| [57961] Microsoft Windows 'ZwSetInformationProcess()' Local Denial of Service Vulnerability
19291| [57858] Microsoft Windows TCP/IP TCP FIN WAIT CVE-2013-0075 Remote Denial of Service Vulnerability
19292| [57853] Microsoft Windows NFS Server NULL Pointer Dereference Remote Denial of Service Vulnerability
19293| [57142] Microsoft Windows Print Spooler Service CVE-2013-0011 Code Execution Vulnerability
19294| [57141] Microsoft OData CVE-2013-0005 Denial of Service Vulnerability
19295| [57122] Microsoft XML Core Services CVE-2013-0007 Remote Code Execution Vulnerability
19296| [57116] Microsoft XML Core Services CVE-2013-0006 Remote Code Execution Vulnerability
19297| [57002] Microsoft Internet Explorer Crafted HTML Stack Overflow Denial of Service Vulnerability
19298| [56836] Microsoft Exchange Server RSS Feed Remote Denial of Service Vulnerability
19299| [56440] Microsoft IIS FTP Service CVE-2012-2532 Remote Command Injection Vulnerability
19300| [56312] Microsoft Office Publisher '.pub' File Denial of Service Vulnerability
19301| [56311] Microsoft Paint '.bmp' Denial of Service Vulnerability
19302| [56309] Microsoft Office Excel CVE-2012-5672 Denial of Service Vulnerability
19303| [56304] Microsoft Office Excel 2010 Memory Corruption Denial of Service Vulnerability
19304| [56303] RETIRED: Microsoft Windows Help Viewer Memory Corruption Denial of Service Vulnerability
19305| [56239] Microsoft Office Picture Manager Memory Corruption Denial of Service Vulnerability
19306| [56235] Microsoft Word Stack Overflow Denial Of Service Vulnerability
19307| [55778] Microsoft Windows Kerberos CVE-2012-2551 Denial of Service Vulnerability
19308| [55202] Microsoft Indexing Service 'ixsso.dll' ActiveX Control Denial of Service Vulnerability
19309| [54921] Microsoft Windows Remote Administration Protocol (RAP) Remote Denial of Service Vulnerability
19310| [54276] Microsoft IIS Multiple FTP Command Request Denial of Service Vulnerability
19311| [54012] Microsoft Windows OpenType 'atmfd.dll' Denial of Service Vulnerability
19312| [53934] Microsoft XML Core Services CVE-2012-1889 Remote Code Execution Vulnerability
19313| [53751] Microsoft Wordpad '.doc' File NULL Pointer Dereference Denial Of Service Vulnerability
19314| [53363] Microsoft .NET Framework Index Comparison Denial Of Service Vulnerability
19315| [53343] Microsoft Windows Kernel 'Win32k.sys' Local Denial of Service Vulnerability
19316| [52374] Microsoft Windows DNS Server (CVE-2012-0006) Remote Denial of Service Vulnerability
19317| [52354] Microsoft Remote Desktop Protocol Service CVE-2012-0152 Denial of Service Vulnerability
19318| [52332] Microsoft Windows 'DirectWrite' API Denial of Service Vulnerability
19319| [51527] Microsoft Internet Information Services DOS Device Request Security Bypass Vulnerability
19320| [51186] Microsoft ASP.NET Hash Collision Denial Of Service Vulnerability
19321| [51179] Microsoft Windows Phone Messages Processing Denial of Service Vulnerability
19322| [50510] Microsoft Windows Kernel TrueType Font Parsing (CVE-2011-2004) Denial of Service Vulnerability
19323| [49998] Microsoft Host Integration Server CVE-2011-2008 Remote Denial Of Service Vulnerability
19324| [49997] Microsoft Host Integration Server CVE-2011-2007 Remote Denial Of Service Vulnerability
19325| [49980] Microsoft Forefront Unified Access Gateway Null Session Cookie Denial of Service Vulnerability
19326| [49973] Microsoft Windows Kernel 'Win32k.sys' TrueType Font File Remote Denial of Service Vulnerability
19327| [49489] Microsoft Windows stdout/stdin Local Denial of Service Vulnerability
19328| [49165] Microsoft Internet Explorer 9 'Iedvtool.dll' Malformed HTML Denial of Service Vulnerability
19329| [49164] Microsoft Windows DHCPv6 Packets Remote Denial Of Service Vulnerability
19330| [49019] Microsoft Windows DNS Server Uninitialized Memory Remote Denial of Service Vulnerability
19331| [48997] Microsoft Windows Kernel CVE-2011-1971 Remote Denial of Service Vulnerability
19332| [48995] Microsoft Remote Desktop Protocol CVE-2011-1968 Denial of Service Vulnerability
19333| [48990] Microsoft Windows TCP/IP QOS CVE-2011-1965 Remote Denial Of Service Vulnerability
19334| [48987] Microsoft Windows TCP/IP ICMP CVE-2011-1871 Remote Denial Of Service Vulnerability
19335| [48187] Microsoft Windows Distributed File System Remote Denial of Service Vulnerability
19336| [48185] Microsoft Windows SMB Server Remote Denial of Service Vulnerability
19337| [48179] Microsoft Hyper-V VMBus 'vmswitch.sys' Denial of Service Vulnerability
19338| [48175] Microsoft Active Directory Certificate Services Web Enrollment Cross-Site Scripting Vulnerability
19339| [47897] Microsoft Windows 'nsiproxy.sys' Driver Local Denial of Service Vulnerability
19340| [47730] Microsoft Windows Internet Name Service (WINS) Failed Response Remote Code Execution Vulnerability
19341| [47724] Microsoft Silverlight Prior to 4.0.60310 Multiple Remote Denial Of Service Vulnerabilities
19342| [47413] Microsoft Windows Media Player '.ogg' File Remote Denial Of Service Vulnerability
19343| [47315] Microsoft Host Integration Server Multiple Remote Denial Of Service Vulnerabilities
19344| [47279] Microsoft Windows 'AFD.sys' Driver Local Denial of Service Vulnerability
19345| [46773] Microsoft .NET Runtime Optimization Service Local Privilege Escalation Vulnerability
19346| [46145] Microsoft Active Directory Service Principal Names (CVE-2011-0040) Denial Of Service Vulnerability
19347| [46099] Terminal Server Client '.rdp' File Processing Remote Denial of Service Vulnerability
19348| [45542] Microsoft IIS FTP Service Remote Buffer Overflow Vulnerability
19349| [45297] Microsoft Exchange Server 2007 Infinite Loop Remote Denial of Service Vulnerability
19350| [45293] Microsoft Hyper-V VMBus Denial of Service Vulnerability
19351| [45271] Microsoft 'Netlogon' RPC Null Pointer Dereference Remote Denial of Service Vulnerability
19352| [45065] Microsoft Outlook File Attachment Denial Of Service Vulnerability
19353| [44357] Microsoft Windows Kernel Task Scheduler Service Local Privilege Escalation Vulnerability
19354| [44287] Microsoft Windows Mobile Overly Long vCard Name Field Denial of Service Vulnerability
19355| [43780] Microsoft Windows SChannel TLSv1 Remote Denial of Service Vulnerability
19356| [43561] Microsoft Internet Information Services Remote Script Code Execution Vulnerability
19357| [43465] Microsoft MPEG Layer-3 Audio Decoder Divide-By-Zero Denial of Service Vulnerability
19358| [43322] Microsoft Paint Memory Corruption Denial Of Service Vulnerability
19359| [43140] Microsoft IIS Repeated Parameter Request Denial of Service Vulnerability
19360| [43073] Microsoft Windows Print Spooler Service Remote Code Execution Vulnerability
19361| [42606] Microsoft Windows 'IcmpSendEcho()' Local Denial Of Service Vulnerability
19362| [42496] Microsoft Windows 'win32k!GreStretchBltInternal()' Local Denial Of Service Vulnerability
19363| [42300] Microsoft XML Core Service Msxml2.XMLHTTP.3.0 Response Handling Memory Corruption Vulnerability
19364| [42278] Microsoft Windows Service Isolation Bypass Local Privilege Escalation Vulnerability
19365| [42267] Microsoft Windows SMB Stack Exhaustion Denial of Service Vulnerability
19366| [42263] Microsoft Windows SMB Variable Validation Denial of Service Vulnerability
19367| [42251] Microsoft Windows TCP/IP IPv6 Extension Header Remote Denial of Service Vulnerability
19368| [42250] Microsoft Windows 'xxxRealDrawMenuItem()' Function Local Denial Of Service Vulnerability
19369| [42221] Microsoft Windows Kernel Access Control Lists Local Denial of Service Vulnerability
19370| [41990] Microsoft Internet Explorer Frame Border Property Denial of Service Vulnerability
19371| [41794] Microsoft DirectX DirectPlay Multiple Denial Of Service Vulnerabilities
19372| [40559] Microsoft SharePoint Help Page Remote Denial of Service Vulnerability
19373| [40487] Microsoft Internet Explorer CSS 'expression' Remote Denial of Service Vulnerability
19374| [39631] Microsoft Windows 'SfnINSTRING' Local Denial Of Service Vulnerability
19375| [39356] Microsoft Windows Media Service Transport Information Packet Stack Buffer Overflow Vulnerability
19376| [39322] Microsoft Windows Kernel Exception Handling Local Denial Of Service Vulnerability
19377| [39320] Microsoft Windows Kernel Image File Relocation Local Denial Of Service Vulnerability
19378| [39319] Microsoft Windows Kernel Virtual Path Local Denial Of Service Vulnerability
19379| [39318] Microsoft Windows Kernel Invalid Registry Key Local Denial Of Service Vulnerability
19380| [39309] Microsoft Windows Kernel Symbolic Link Local Denial Of Service Vulnerability
19381| [39308] Microsoft Windows SMTP Server MX Record Denial of Service Vulnerability
19382| [39297] Microsoft Windows Kernel NULL Pointer Local Denial Of Service Vulnerability
19383| [39221] Microsoft Office Communicator SIP Remote Denial of Service Vulnerability
19384| [38579] Microsoft Windows '.ani' File 'tagBITMAPINFOHEADER' Denial of Service Vulnerability
19385| [38420] Microsoft Windows Unspecified Denial of Service Vulnerability
19386| [38113] Microsoft Hyper-V Local Denial of Service Vulnerability
19387| [38110] Microsoft Windows Kerberos 'Ticket-Granting-Ticket' Remote Denial of Service Vulnerability
19388| [38064] Microsoft Windows TCP/IP Selective Acknowledgement Remote Denial of Service Vulnerability
19389| [38054] Microsoft Windows SMB Memory Corruption Remote Denial of Service Vulnerability
19390| [38051] Microsoft Windows SMB Null Pointer Remote Denial of Service Vulnerability
19391| [37877] Microsoft Internet Explorer Null Pointer Dereference Denial of Service Vulnerabilities
19392| [37218] Microsoft Windows LSASS ISAKMP Message Remote Denial of Service Vulnerability
19393| [37214] Microsoft Active Directory Federation Services Header Validation Remote Code Execution Vulnerability
19394| [36989] Microsoft Windows SMB Packet Remote Denial of Service Vulnerability
19395| [36919] Microsoft Windows Web Services on Devices API Remote Code Execution Vulnerability
19396| [36918] Microsoft Active Directory LDAP Request Stack Exhaustion Denial Of Service Vulnerability
19397| [36817] Microsoft SharePoint Team Services Download Feature Source Code Information Disclosure Vulnerability
19398| [36629] Microsoft Indexing Service ActiveX Control Remote Code Execution Vulnerability
19399| [36625] Microsoft Windows Kernel Exception Handler Local Denial Of Service Vulnerability
19400| [36595] Microsoft Windows SMB2 Field Validation Remote Denial of Service Vulnerability
19401| [36593] Microsoft Windows LSASS NTLM Implementation Remote Denial of Service Vulnerability
19402| [36276] RETIRED: Microsoft IIS FTPd Globbing Functionality Remote Denial of Service Vulnerability
19403| [36273] Microsoft IIS FTPd Globbing Functionality Remote Denial of Service Vulnerability
19404| [36269] Microsoft Windows TCP/IP Orphaned Connection Remote Denial of Service Vulnerability
19405| [36070] Microsoft Internet Explorer 'li' Element Denial of Service Vulnerability
19406| [35985] Microsoft ASP.NET Request Scheduling Denial Of Service Vulnerability
19407| [35972] Microsoft Windows Workstation Service Double Free Remote Code Execution Vulnerability
19408| [35969] Microsoft Message Queuing Service NULL Pointer Dereference Local Privilege Escalation Vulnerability
19409| [35941] Microsoft Internet Explorer 8 Denial of Service Vulnerability
19410| [35799] Microsoft Internet Explorer 'findText()' Unicode Parsing Denial of Service Vulnerability
19411| [35620] Microsoft Internet Explorer 'AddFavorite' Method Denial of Service Vulnerability
19412| [35225] Microsoft Active Directory Memory Leak Denial Of Service Vulnerability
19413| [34587] Microsoft Windows Media Player WAV File Multiple Denial of Service Vulnerabilities
19414| [34586] Microsoft GDI+ Plugin PNG File Infinite Loop Denial of Service Vulnerability
19415| [34585] Microsoft Windows Media Player MIDI File Denial of Service Vulnerability
19416| [34478] Microsoft Internet Explorer File Download Denial of Service Vulnerability
19417| [34443] Microsoft Windows RPCSS Service Isolation Local Privilege Escalation Vulnerability
19418| [34442] Microsoft Windows WMI Service Isolation Local Privilege Escalation Vulnerability
19419| [34414] Microsoft ISA Server and Forefront Threat Management Gateway Denial of Service Vulnerability
19420| [34258] Microsoft Windows Services for UNIX / Subsystem for UNIX-based Applications Multiple Vulnerabilities
19421| [33803] Microsoft XML Core Services XMLHttpRequest 'SetCookie2' Header Information Disclosure Vulnerability
19422| [33494] Microsoft Internet Explorer HTML Form Value Denial of Service Vulnerability
19423| [33406] Sun Solaris Pseudo-terminal Driver (pty(7D)) Local Denial Of Service Vulnerability
19424| [33149] Microsoft Internet Explorer 'screen[]' Remote Denial of Service Vulnerability
19425| [33136] Microsoft Exchange Server EMSMDB2 MAPI Command Remote Denial of Service Vulnerability
19426| [32702] Microsoft Outlook Express Malformed MIME Message Denial Of Service Vulnerability
19427| [32653] Microsoft Windows Media Components 'Service Principle Name' Remote Code Execution Vulnerability
19428| [32341] Microsoft Communicator RTCP Unspecified Remote Denial of Service Vulnerability
19429| [32206] Microsoft Windows 'UnhookWindowsHookEx' Local Denial Of Service Vulnerability
19430| [32204] Microsoft XML Core Services Transfer Encoding Cross Domain Information Disclosure Vulnerability
19431| [32155] Microsoft XML Core Services DTD Cross Domain Information Disclosure Vulnerability
19432| [32077] Microsoft Windows Media Player MIDI File MThd Header Parsing Denial of Service Vulnerability
19433| [31996] Microsoft DebugDiag 'CrashHangExt.dll' ActiveX Control Remote Denial of Service Vulnerability
19434| [31874] Microsoft Windows Server Service RPC Handling Remote Code Execution Vulnerability
19435| [31682] Microsoft Windows Internet Printing Service Integer Overflow Vulnerability
19436| [31637] Microsoft Message Queuing Service RPC Query Heap Corruption Vulnerability
19437| [31570] Microsoft Windows Vista Local Denial Of Service Vulnerability
19438| [31432] Microsoft GDI+ 'GDIPLUS.dll' ICO File Divide-By-Zero Denial of Service Vulnerability
19439| [31420] Microsoft Windows Mobile Overly Long Bluetooth Device Name Denial of Service Vulnerability
19440| [31399] Microsoft WordPad '.doc' File Remote Denial of Service Vulnerability
19441| [31215] Microsoft Internet Explorer Malfromed PNG File Remote Denial of Service Vulnerability
19442| [31179] Microsoft Windows WRITE_ANDX SMB Processing Remote Denial Of Service Vulnerability
19443| [30881] PureMessage for Microsoft Exchange RTF Multiple Denial Of Service Vulnerabilities
19444| [30814] Microsoft Windows Media Services 'nskey.dll' ActiveX Control Remote Buffer Overflow Vulnerability
19445| [30357] Minix Psuedo Terminal Denial of Service Vulnerability
19446| [29991] Microsoft Dynamics GP Denial of Service and Multiple Remote Buffer Overflow Vulnerabilities
19447| [29584] Microsoft Windows Active Directory LDAP Request Validation Remote Denial Of Service Vulnerability
19448| [29509] Microsoft Windows PGM Invalid Fragment Remote Denial Of Service Vulnerability
19449| [29508] Microsoft Windows PGM Invalid Length Remote Denial Of Service Vulnerability
19450| [29073] Microsoft Malware Protection Engine Disk Space Exhaustion Remote Denial Of Service Vulnerability
19451| [29060] Microsoft Malware Protection Engine File Processing Remote Denial Of Service Vulnerability
19452| [28946] Microsoft Excel JavaScript Code Remote Denial Of Service Vulnerability
19453| [28580] Microsoft Internet Explorer XDR Prototype Hijacking Denial of Service Vulnerability
19454| [28553] Microsoft Windows DNS Client Service Response Spoofing Vulnerability
19455| [27676] Microsoft Internet Information Services ASP Remote Code Execution Vulnerability
19456| [27638] Microsoft Windows Active Directory LDAP Request Validation Remote Denial Of Service Vulnerability
19457| [27634] Microsoft Windows Vista DHCP Remote Denial Of Service Vulnerability
19458| [27139] Microsoft Windows TCP/IP ICMP Remote Denial Of Service Vulnerability
19459| [26982] Microsoft Office Publisher Multiple Denial Of Service Vulnerabilities
19460| [26981] Microsoft Word Wordart Doc Denial Of Service Vulnerability
19461| [26797] Microsoft Message Queuing Service Stack Buffer Overflow Vulnerability
19462| [26648] Microsoft Windows Media Player AIFF Parsing Divide-By-Zero Denial of Service Vulnerability
19463| [26414] Microsoft Forms 2.0 ActiveX Control Memory Access Violation Denial of Service Vulnerabilities
19464| [26405] Microsoft Office Web Component Memory Access Violation Denial of Service Vulnerability
19465| [25974] Microsoft Windows RPC NTLMSSP Remote Denial Of Service Vulnerability
19466| [25816] Microsoft Windows Explorer PNG Image Local Denial Of Service Vulnerability
19467| [25795] Microsoft Live Messenger Shared Files Denial of Service Vulnerability
19468| [25620] Microsoft Windows Services for UNIX Local Privilege Escalation Vulnerability
19469| [25301] Microsoft XML Core Services SubstringData Integer Overflow Vulnerability
19470| [25236] Microsoft Windows Media Player AU Divide-By-Zero Denial of Service Vulnerability
19471| [25222] Microsoft Internet Explorer Position:Relative Denial of Service Vulnerability
19472| [25207] Microsoft Windows Explorer JPG File Denial of Service Vulnerability
19473| [25201] Microsoft Windows Calendar ICS File Denial of Service Vulnerability
19474| [25066] Microsoft Windows ARP Request Denial of Service Vulnerability
19475| [25013] Microsoft Windows Explorer GIF File Denial of Service Vulnerability
19476| [24816] Microsoft Windows Vista Kernel Unspecified Remote Denial Of Service Vulnerability
19477| [24796] Microsoft Windows Active Directory LDAP Request Validation Remote Denial Of Service Vulnerability
19478| [24744] Microsoft Internet Explorer Zone Denial of Service Vulnerability
19479| [24691] Microsoft Excel Sheet Name Remote Denial Of Service Vulnerability
19480| [24469] Microsoft Windows CE POP3 Remote Denial of Service Vulnerability
19481| [24424] Microsoft Windows CE TCP/IP Requests Denial of Service Vulnerability
19482| [24420] Microsoft Windows CE Pocket Internet Explorer PNG Denial of Service Vulnerability
19483| [24395] Microsoft Windows CE Internet Explorer Remote Denial of Service Vulnerability
19484| [24394] Microsoft Windows CE Internet Explorer SSL Unspecified Denial Of Service Vulnerability
19485| [24393] Microsoft Windows CE Internet Explorer Content-Type Denial of Service Vulnerability
19486| [24391] Microsoft Windows CE Malformed RNDIS Packet Remote Denial of Service Vulnerability
19487| [24346] Microsoft Windows GDI+ ICO File Remote Denial of Service Vulnerability
19488| [24188] Microsoft DirectX Media DXTMSFT.DLL ActiveX Control Multiple Denial of Service Vulnerabilities
19489| [24129] Microsoft Visual Basic 6.0 Project Company Name Denial of Service Vulnerability
19490| [23810] Microsoft Exchange IMAP Command Processing Remote Denial of Service Vulnerability
19491| [23808] Microsoft Exchange iCal Request Remote Denial of Service Vulnerability
19492| [23566] OpenAFS for Microsoft Windows Local Denial of Service Vulnerability
19493| [23373] Microsoft Windows Explorer ANI File Denial of Service Vulnerability
19494| [23321] Microsoft Windows Explorer BMP Image Denial of Service Vulnerability
19495| [23275] Microsoft Windows GDI WMF Remote Denial of Service Vulnerability
19496| [23271] Microsoft Windows Vista LLTD Mapper EMIT Packet Remote Denial Of Service Vulnerability
19497| [23266] Microsoft Windows Vista ARP Table Entries Denial of Service Vulnerability
19498| [23178] Microsoft Internet Explorer HTML Denial of Service Vulnerability
19499| [22938] Microsoft Windows WinMM.DLL WAV Files Remote Denial of Service Vulnerability
19500| [22847] Microsoft Windows OLE32.DLL Word Document Handling Denial Of Service Vulnerability
19501| [22724] Microsoft Office Publisher Remote Denial of Service Vulnerability
19502| [22717] Microsoft Excel NULL Pointer Dereference Denial Of Service Vulnerability
19503| [22716] Microsoft Office 2003 Denial of Service Vulnerability
19504| [22715] Microsoft Windows Explorer WMF File Handling Denial of Service Vulnerability
19505| [22500] Microsoft Internet Explorer for Windows Mobile Remote WML Content Denial of Service Vulnerability
19506| [22499] Microsoft Windows Image Acquisition Service Privilege Escalation Vulnerability
19507| [22481] Microsoft Windows Shell Hardware Detection Service Privilege Escalation Vulnerability
19508| [22408] Microsoft Internet Explorer Malformed HTML For Script Denial of Service Vulnerability
19509| [22343] Microsoft Windows Mobile Multiple Remote Denial of Service Vulnerabilities
19510| [22288] Microsoft Internet Explorer Multiple ActiveX Controls Denial of Service Vulnerabilities
19511| [21992] Microsoft Windows Explorer WMF File Denial of Service Vulnerability
19512| [21937] Microsoft Outlook Malformed Email Header Remote Denial of Service Vulnerability
19513| [21872] Microsoft XML Core Services Race Condition Memory Corruption Vulnerability
19514| [21865] Apache And Microsoft IIS Range Denial of Service Vulnerability
19515| [21688] Microsoft Windows CSRSS HardError Messages Denial of Service Vulnerability
19516| [21649] Microsoft Outlook ActiveX Control Remote Internet Explorer Denial of Service Vulnerability
19517| [21537] Microsoft Windows SNMP Service Remote Code Execution Vulnerability
19518| [21495] Microsoft Windows 2000 Remote Installation Service Remote Code Execution Vulnerability
19519| [21466] Microsoft Internet Explorer CSS Width Element Denial of Service Vulnerability
19520| [21447] Microsoft Internet Explorer Frame Src Denial Of Service Vulnerability
19521| [21401] Microsoft Windows Print Spooler GetPrinterData Denial of Service Vulnerability
19522| [21262] Microsoft Office HTMLMARQ.OCX Library Denial of Service Vulnerability
19523| [21083] Microsoft Active Directory Unspecified Denial of Service Vulnerability
19524| [21023] Microsoft Windows Client Service For Netware Remote Code Execution Vulnerability
19525| [20985] Microsoft Windows Workstation Service NetpManageIPCConnect Remote Code Execution Vulnerability
19526| [20984] Microsoft Client Service for Netware Denial of Service Vulnerability
19527| [20915] Microsoft XML Core Service XMLHTTP ActiveX Control Remote Code Execution Vulnerability
19528| [20875] Microsoft Internet Explorer MHTML Denial of Service Vulnerability
19529| [20812] Microsoft Internet Explorer RemoveChild Denial of Service Vulnerability
19530| [20804] Microsoft Windows NAT Helper Remote Denial of Service Vulnerability
19531| [20495] Microsoft PowerPoint Remote Denial of Service Vulnerability
19532| [20373] Microsoft Windows SMB Rename Remote Denial of Service Vulnerability
19533| [20339] Microsoft XML Core Services Information Disclosure Vulnerability
19534| [20338] Microsoft Windows XML Core Services XSLT Buffer Overrun Vulnerability
19535| [19927] Microsoft Indexing Service Query Validation Cross-Site Scripting Vulnerability
19536| [19640] Microsoft Internet Explorer Multiple COM Object Color Property Denial of Service Vulnerabilities
19537| [19572] Microsoft Internet Explorer Visual Studio COM Object Instantiation Denial of Service Vulnerability
19538| [19530] Microsoft Internet Explorer MSOE.DLL Denial Of Service Vulnerability
19539| [19521] Microsoft Internet Explorer IMSKDIC.DLL Denial Of Service Vulnerability
19540| [19520] Microsoft Windows PNG File IHDR Block Denial of Service Vulnerability
19541| [19409] Microsoft Windows Server Service Remote Buffer Overflow Vulnerability
19542| [19365] Microsoft Windows GDI32.DLL WMF Remote Denial of Service Vulnerability
19543| [19364] Microsoft Internet Explorer IFrame Refresh Denial of Service Vulnerability
19544| [19301] RETIRED: Microsoft Windows GDI Plus Library Remote Denial Of Service Vulnerability
19545| [19300] Microsoft Windows Routing and Remote Access Denial of Service Vulnerability
19546| [19228] Microsoft Internet Explorer Deleted Frame Object Denial Of Service Vulnerability
19547| [19227] Microsoft Internet Explorer ADODB.Recordset NextRecordset Denial of Service Vulnerability
19548| [19221] Microsoft Windows Graphical Device Interface Plus Library Denial Of Service Vulnerability
19549| [19215] Microsoft Windows SMB PIPE Remote Denial of Service Vulnerability
19550| [19140] Microsoft Internet Explorer Native Function Iterator Denial Of Service Vulnerability
19551| [19135] Microsoft Windows Remote Denial of Service Vulnerability
19552| [19113] Microsoft Internet Explorer Multiple Object ListWidth Property Denial Of Service Vulnerability
19553| [19109] Microsoft Internet Explorer Internet.HHCtrl Click Denial Of Service Vulnerability
19554| [19102] Microsoft Internet Explorer String To Binary Function Denial Of Service Vulnerability
19555| [19092] Microsoft Internet Explorer Content-Type Denial Of Service Vulnerability
19556| [19079] Microsoft Internet Explorer OVCtl Denial Of Service Vulnerability
19557| [19069] Microsoft Internet Explorer DataSourceControl Denial of Service Vulnerability
19558| [19029] Microsoft Internet Explorer DXImageTransform Properties Denial Of Service Vulnerability
19559| [19013] Microsoft Internet Explorer MHTMLFile Denial Of Service Vulnerability
19560| [18995] Microsoft Windows Registry Access Local Denial of Service Vulnerability
19561| [18960] Microsoft Internet Explorer RevealTrans Denial Of Service Vulnerability
19562| [18946] Microsoft Internet Explorer TriEditDocument Denial Of Service Vulnerability
19563| [18929] Microsoft Internet Explorer HtmlDlgSafeHelper Remote Denial Of Service Vulnerability
19564| [18923] Microsoft Windows DHCP Client Service Remote Code Execution Vulnerability
19565| [18903] Microsoft Internet Explorer Object.Microsoft.DXTFilter Denial Of Service Vulnerability
19566| [18902] Microsoft Internet Explorer DirectAnimation.DAUserData Denial Of Service Vulnerability
19567| [18900] Microsoft Internet Explorer 6 RDS.DataControl Denial of Service Vulnerability
19568| [18873] Microsoft Internet Explorer Table Frameset Denial Of Service Vulnerability
19569| [18855] Microsoft Internet Explorer Structured Graphics Control Denial Of Service Vulnerability
19570| [18820] Microsoft Internet Explorer Href Title Denial Of Service Vulnerability
19571| [18773] Microsoft Internet Explorer ADODB.Recordset Filter Property Denial of Service Vulnerability
19572| [18771] Microsoft Internet Explorer OutlookExpress.AddressBook Denial of Service Vulnerability
19573| [18736] Microsoft Internet Explorer 7 Denial of Service Vulnerability
19574| [18639] Microsoft Windows Live Messenger Contact List Processing Remote Denial of Service Vulnerability
19575| [18389] Microsoft Windows RPC Mutual Authentication Service Spoofing Vulnerability
19576| [18357] Microsoft SMB Driver Local Denial Of Service Vulnerability
19577| [18311] Microsoft NetMeeting Remote Memory Corruption Denial of Service Vulnerability
19578| [18112] Microsoft Internet Explorer Malformed HTML Parsing Denial of Service Vulnerability
19579| [17932] Microsoft Internet Explorer Position CSS Denial of Service Vulnerability
19580| [17906] Microsoft Windows MSDTC Invalid Memory Access Denial Of Service Vulnerability
19581| [17252] Microsoft Office XP Array Index Denial of Service Vulnerability
19582| [17188] Microsoft ASP.NET COM Components W3WP Remote Denial Of Service Vulnerability
19583| [16978] Microsoft Internet Explorer Java Applet Handling Denial of Service Vulnerability
19584| [16782] Microsoft Word Malformed Document Denial Of Service Vulnerability
19585| [16645] Microsoft Windows IGMPv3 Denial of Service Vulnerability
19586| [16463] Microsoft Internet Explorer URLMon.DLL Denial Of Service Vulnerability
19587| [16441] Microsoft Internet Explorer Flash ActionScript JScript Handling Denial of Service Vulnerability
19588| [16240] Microsoft Internet Explorer Malformed IMG and XML Parsing Denial of Service Vulnerability
19589| [16079] Microsoft Internet Explorer MSHTML.DLL HTML Parsing Denial of Service Vulnerability
19590| [16070] Microsoft Internet Explorer HTML Parsing Denial of Service Vulnerabilities
19591| [15671] Microsoft Windows CreateRemoteThread Local Denial of Service Vulnerability
19592| [15613] Microsoft Windows SynAttackProtect Predictable Hash Remote Denial of Service Vulnerability
19593| [15460] Microsoft Windows Plug and Play Denial of Service Vulnerability
19594| [15268] Microsoft Internet Explorer Malformed HTML Parsing Denial of Service Vulnerability
19595| [15208] Microsoft Internet Explorer Java Applet Denial of Service Vulnerability
19596| [15066] Microsoft Windows Client Service For Netware Buffer Overflow Vulnerability
19597| [15059] Microsoft MSDTC TIP Distributed Denial Of Service Vulnerability
19598| [15058] Microsoft MSDTC TIP Denial Of Service Vulnerability
19599| [15008] Microsoft Windows Wireless Zero Configuration Service Information Disclosure Vulnerability
19600| [14899] Microsoft Internet Explorer for Mac OS Denial of Service Vulnerability
19601| [14772] Microsoft Exchange Server 2003 Exchange Information Store Denial Of Service Vulnerability
19602| [14519] Microsoft Windows Kerberos Denial Of Service Vulnerability
19603| [14518] Microsoft Windows Telephony Service Buffer Overflow Vulnerability
19604| [14515] Microsoft Internet Explorer Unspecified SharePoint Portal Services Log Sink ActiveX Vulnerability
19605| [14286] Microsoft Internet Explorer JPEG Image Rendering Unspecified Denial Of Service Vulnerability
19606| [14285] Microsoft Internet Explorer JPEG Image Rendering Memory Consumption Denial Of Service Vulnerability
19607| [14284] Microsoft Internet Explorer JPEG Image Rendering CMP Fencepost Denial Of Service Vulnerability
19608| [14260] Microsoft Windows Network Connections Manager Library Local Denial of Service Vulnerability
19609| [14259] Microsoft Windows Kernel Unspecified Remote Desktop Protocol Denial Of Service Vulnerability
19610| [14217] Microsoft ASP.NET RPC/Encoded Remote Denial Of Service Vulnerability
19611| [14177] Microsoft Windows MSRPC SVCCTL Service Enumeration Vulnerability
19612| [13955] Microsoft ISA Server HTTP/HTTPS Service Basic Auth Information Disclosure Vulnerability
19613| [13950] Microsoft Windows Web Client Service Remote Code Execution Vulnerability
19614| [13947] Microsoft Internet Explorer Unspecified GIF And BMP Denial Of Service Vulnerability
19615| [13846] Microsoft ISA Server SecureNAT Unspecified Denial Of Service Vulnerability
19616| [13801] Microsoft Windows XP Windows Management Instrumentation Denial of Service Vulnerability
19617| [13798] Microsoft Internet Explorer Restricted Sites Malformed URI Denial of Service Vulnerability
19618| [13791] Microsoft Windows User32.DLL Icon Handling Denial Of Service Vulnerability
19619| [13658] Microsoft IPv6 TCP/IP Loopback LAND Denial of Service Vulnerability
19620| [13110] Microsoft Windows Kernel Object Management Denial Of Service Vulnerability
19621| [13008] Microsoft Windows Server 2003 SMB Redirector Local Denial Of Service Vulnerability
19622| [12972] Microsoft Windows Server 2003 Service Pack 1 Released - Multiple Vulnerabilities Fixed
19623| [12889] Microsoft Windows XP TSShutdn.exe Remote Denial of Service Vulnerability
19624| [12870] Microsoft Windows Local Denial Of Service Vulnerability
19625| [12834] Microsoft Windows Graphical Device Interface Library Denial Of Service Vulnerability
19626| [12764] Microsoft Exchange Server Mail Box Sub Folder Denial Of Service Vulnerability
19627| [12565] Microsoft Internet Explorer Malformed File URI Denial of Service Vulnerability
19628| [12481] Microsoft Windows License Logging Service Buffer Overflow Vulnerability
19629| [12476] Microsoft Windows SharePoint Services Cross-Site Scripting and Spoofing Vulnerability
19630| [12228] Microsoft Windows Indexing Service Buffer Overflow Vulnerability
19631| [12141] Microsoft FrontPage 2000 Internet Publishing Service Provider DAV File Upload Vulnerability
19632| [12121] Hilgraeve HyperTerminal Remote Denial of Service Vulnerability
19633| [12094] Microsoft Windows ANI File Denial of Service Vulnerability
19634| [11919] Microsoft Windows DHCP Server Logging Remote Denial Of Service Vulnerability
19635| [11751] Microsoft Internet Explorer Infinite Array Sort Denial Of Service Vulnerability
19636| [11536] Microsoft Internet Explorer Font Tag Denial Of Service Vulnerability
19637| [11503] Microsoft Windows XP WAV File Handler Denial Of Service Vulnerability
19638| [11412] Microsoft Frontpage Asycpict.DLL JPEG Handling Remote Denial of Service Vulnerabilities
19639| [11387] Microsoft Windows 2003 Services Default SACL Access Right Weakness
19640| [11384] Microsoft XML Parser Remote Denial of Service Vulnerability
19641| [11380] Microsoft RPC Runtime Library Remote Denial Of Service And Information Disclosure Vulnerability
19642| [11374] Microsoft SMTP Service and Exchange Routing Engine Buffer Overflow Vulnerability
19643| [11365] Microsoft Windows Kernel Local Denial of Service Vulnerability
19644| [11350] Microsoft Word Multiple Remote Denial Of Service Vulnerabilities
19645| [11265] Microsoft SQL Server Remote Denial Of Service Vulnerability
19646| [11251] Microsoft GDI+ Library Malformed JPEG Handling Unspecified Denial of Service Vulnerability
19647| [11202] Microsoft Windows XP Explorer.EXE TIFF Image Denial of Service Vulnerability
19648| [10913] Microsoft Windows Large Image Processing Remote Denial Of Service Vulnerability
19649| [10901] Microsoft Windows 2000/XP CRL File Failed Integrity Check Denial Of Service Vulnerability
19650| [10726] Microsoft Systems Management Server Remote Denial Of Service Vulnerability
19651| [10711] Microsoft Outlook Express Malformed Email Header Denial Of Service Vulnerability
19652| [10694] Microsoft Internet Explorer JavaScript Null Pointer Exception Denial Of Service Vulnerability
19653| [10552] Microsoft Internet Explorer HREF Save As Denial of Service Vulnerability
19654| [10487] Microsoft DirectX DirectPlay Remote Malformed Packet Denial Of Service Vulnerability
19655| [10482] Microsoft ISA Server Redirect URI Handler Web Proxy Service Remote Denial Of Service Vulnerability
19656| [10477] Microsoft ISA Server Web Proxy Malformed SSL Packet Remote Denial of Service Vulnerability
19657| [10351] Microsoft Internet Explorer http-equiv Meta Tag Denial of Service Vulnerability
19658| [10318] Microsoft Internet Explorer XML Parsing Denial Of Service Vulnerability
19659| [10167] Microsoft Internet Explorer Object Element Data Denial Of Service Vulnerability
19660| [10144] Microsoft Outlook/Outlook Express Remote Denial Of Service Vulnerability
19661| [10127] Microsoft Windows RPCSS Service Remote Denial Of Service Vulnerability
19662| [10123] Microsoft Windows COM Internet Service/RPC Over HTTP Remote Denial Of Service Vulnerability
19663| [10115] Microsoft Windows SSL Library Denial of Service Vulnerability
19664| [10114] Microsoft Windows 2000 Domain Controller LDAP Denial Of Service Vulnerability
19665| [10098] Microsoft Outlook Express Malformed EML File Denial of Service Vulnerability
19666| [10097] Microsoft Internet Explorer Bitmap File Processing Denial of Service Vulnerability
19667| [10073] Microsoft Internet Explorer Remote IFRAME Denial Of Service Vulnerability
19668| [10057] Microsoft Internet Explorer Macromedia Flash Player Plug-in Remote Denial of Service Vulnerability
19669| [10056] Microsoft Internet Explorer MSWebDVD Object Denial of Service Vulnerability
19670| [9963] Microsoft Visual C++ MFC ISAPI Extension Denial Of Service Vulnerability
19671| [9924] Microsoft Windows XP Explorer.EXE Remote Denial of Service Vulnerability
19672| [9892] Microsoft Windows XP explorer.exe Remote Denial of Service Vulnerability
19673| [9825] Microsoft Windows Media Services Remote Denial of Service Vulnerability
19674| [9660] Microsoft IIS Unspecified Remote Denial Of Service Vulnerability
19675| [9629] Microsoft Internet Explorer Double-Null URI Denial Of Service Vulnerability
19676| [9624] Microsoft Windows Internet Naming Service Buffer Overflow Vulnerability
19677| [9011] Microsoft Windows Workstation Service Remote Buffer Overflow Vulnerability
19678| [9008] Microsoft FrontPage Server Extensions SmartHTML Interpreter Denial Of Service Vulnerability
19679| [8874] Microsoft Internet Explorer Scrollbar-Base-Color Partial Denial Of Service Vulnerability
19680| [8826] Microsoft Windows Messenger Service Buffer Overrun Vulnerability
19681| [8783] Microsoft Windows Message Queuing Service Heap Overflow Vulnerability
19682| [8761] Microsoft Word Malformed Document Denial of Service Vulnerability
19683| [8758] Microsoft Internet Explorer Absolute Position Block Denial Of Service Vulnerability
19684| [8543] Microsoft Windows 98 Fragmented UDP Flood Denial Of Service Vulnerability
19685| [8532] Microsoft Windows NetBIOS Name Service Reply Information Leakage Weakness
19686| [8274] Microsoft SQL Server / MSDE Named Pipe Denial Of Service Vulnerability
19687| [8259] Microsoft Windows NT File Management Function Denial Of Service Vulnerability
19688| [8234] Microsoft Windows RPCSS DCOM Interface Denial of Service Vulnerability
19689| [8221] Microsoft MSN Messenger Image File Transfer Denial of Service Vulnerability
19690| [8195] Microsoft SMTP Service Invalid FILETIME Denial of Service Vulnerability
19691| [8087] Microsoft Windows Security Accounts Manager API Denial Of Service Vulnerability
19692| [8085] Microsoft Windows 2000 ModifyDN Request Denial of Service Vulnerability
19693| [8035] Microsoft Windows Media Services NSIISlog.DLL Remote Buffer Overflow Vulnerability
19694| [7789] Microsoft Windows XP Nested Directory Denial of Service Vulnerability
19695| [7788] Microsoft Windows 2000/XP/2003 IPV6 ICMP Flood Denial Of Service Vulnerability
19696| [7735] Microsoft IIS WebDAV PROPFIND and SEARCH Method Denial of Service Vulnerability
19697| [7733] Microsoft IIS ASP Header Denial Of Service Vulnerability
19698| [7728] Microsoft Internet Information Service Multiple Vulnerabilities
19699| [7727] Microsoft Windows Media Services Logging ISAPI Buffer Overflow Vulnerability
19700| [7706] Microsoft Internet Explorer Malformed JavaScript Denial of Service Vulnerability
19701| [7502] Microsoft Internet Explorer DHTML AnchorClick Partial Denial Of Service Vulnerability
19702| [7402] Microsoft Shlwapi.dll Malformed HTML Form Tag Denial of Service Vulnerability
19703| [7384] Microsoft Internet Explorer CLASSID Variant Denial Of Service Vulnerability
19704| [7358] Microsoft Windows EngTextOut Non-ASCII Character Denial Of Service Vulnerability
19705| [7314] Microsoft Winsock Proxy Service Remote Denial Of Service Vulnerability
19706| [7150] Microsoft ActiveSync Null Pointer Dereference Denial Of Service Vulnerability
19707| [7145] Microsoft ISA Server DNS Intrusion Filter Denial of Service Vulnerability
19708| [6843] Microsoft Exchange Server 5.5 IMAP NOOP Denial of Service Vulnerability
19709| [6789] Microsoft IIS Malformed HTTP Get Request Denial Of Service Vulnerability
19710| [6769] Microsoft Windows 2000 RPC Service Privilege Escalation Vulnerability
19711| [6742] Microsoft Windows NT Win32k.sys Denial of Service Vulnerability
19712| [6672] Microsoft Windows MSGINA.DLL Read-Lock Denial Of Service Vulnerability
19713| [6666] Microsoft Windows Locator Service Buffer Overflow Vulnerability
19714| [6536] Microsoft Windows Fontview Denial of Service Vulnerability
19715| [6507] Microsoft Pocket Internet Explorer Denial Of Service Vulnerability
19716| [6382] Microsoft Java Virtual Machine Java Object Instantiation Denial Of Service Vulnerability
19717| [6319] Microsoft Outlook 2002 Email Header Processing Denial of Service Vulnerability
19718| [6140] Microsoft JVM INativeServices Unauthorized Memory Access Vulnerability
19719| [6135] Microsoft JVM Passed HTML Object Reference Denial Of Service Vulnerability
19720| [6070] Microsoft IIS WebDAV Denial Of Service Vulnerability
19721| [6030] Microsoft Windows 2000 SNMP Printer Query Denial of Service Vulnerability
19722| [6005] Microsoft Windows RPC Service Denial of Service Vulnerability
19723| [5907] Microsoft IIS Malformed HTTP HOST Header Field Denial Of Service Vulnerability
19724| [5880] Microsoft Invalid RPC Request Denial Of Service Vulnerability
19725| [5869] Multiple Microsoft Services for Unix 3.0 Interix SDK Vulnerabilities
19726| [5713] Microsoft Windows XP Professional Remote Desktop Denial Of Service Vulnerability
19727| [5413] Microsoft Exchange 2000 Post Authorization License Exhaustion Denial Of Service Vulnerability
19728| [5412] Microsoft Exchange 2000 Multiple MSRPC Denial Of Service Vulnerabilities
19729| [5312] Microsoft SQL Server 2000 Resolution Service Denial of Service Vulnerability
19730| [5311] Microsoft SQL Server 2000 Resolution Service Stack Overflow Vulnerability
19731| [5310] Microsoft SQL Server 2000 Resolution Service Heap Overflow Vulnerability
19732| [5308] Microsoft Metadirectory Services Remote LDAP Client Administration Vulnerability
19733| [5213] Microsoft IIS SMTP Service Encapsulated SMTP Address Vulnerability
19734| [5094] Microsoft Internet Explorer CLASSID Denial of Service Vulnerability
19735| [5027] Microsoft Internet Explorer CSSText Bold Font Denial Of Service Vulnerability
19736| [4853] Microsoft Commerce Server 2000 Profile Service Buffer Overflow Vulnerability
19737| [4852] Microsoft Windows 2000 Remote Access Service Buffer Overflow Vulnerability
19738| [4846] Microsoft IIS 5.0 Denial Of Service Vulnerability
19739| [4827] Microsoft MSN Messenger Malformed Invite Request Denial of Service
19740| [4675] Microsoft MSN Messenger Font Tag Denial Of Service Vulnerability
19741| [4584] Microsoft Outlook Express DOS Device Denial of Service Vulnerability
19742| [4564] Microsoft Internet Explorer Self-Referential Object Denial of Service Vulnerability
19743| [4532] Microsoft Windows 2000 Lanman Denial of Service Vulnerability
19744| [4482] Microsoft IIS FTP Connection Status Request Denial of Service Vulnerability
19745| [4479] Microsoft IIS ISAPI Filter Access Violation Denial of Service Vulnerability
19746| [4464] Microsoft Windows Terminal Server Group Policy Bypass Vulnerability
19747| [4463] Microsoft VBScript ActiveX Word Object Denial Of Service Vulnerability
19748| [4205] Microsoft Windows SMTP Service Authorization Bypass Vulnerability
19749| [4204] Microsoft SMTP Service Malformed Command Denial of Service Vulnerability
19750| [4045] Microsoft Office v. X for Macintosh Network PID Checker Denial of Service Vulnerability
19751| [4006] Microsoft MSDTC Service Denial of Service Vulnerability
19752| [4002] Microsoft Site Server 3.0 Content Upload Denial of Service Vulnerability
19753| [3942] Microsoft Windows XP .Manifest Denial of Service Vulnerability
19754| [3892] Microsoft Internet Explorer Form Denial of Service Vulnerability
19755| [3730] Microsoft Internet Explorer Refresh Denial of Service Vulnerability
19756| [3729] Microsoft IE for Solaris X Server Denial of Service Vulnerability
19757| [3724] Microsoft Universal Plug and Play Simple Service Discovery Protocol Denial of Service Vulnerability
19758| [3501] Microsoft ISA Server Denial of Service Vulnerability
19759| [3499] Microsoft UPnP Denial of Service Vulnerability
19760| [3481] Microsoft Windows 2000/XP GDI Denial of Service Vulnerability
19761| [3313] Microsoft Windows NT RPC Endpoint Mapper Denial of Service Vulnerability
19762| [3291] Microsoft Windows 2000 RunAs Service Denial of Services Vulnerability
19763| [3223] Microsoft Outlook Web Access Denial of Service Vulnerability
19764| [3215] Microsoft Windows 2000 IrDA Buffer Overflow Denial of Service Vulnerability
19765| [3197] Microsoft ISA Server Proxy Service Memory Leak Denial of Service Vulnerability
19766| [3196] Microsoft ISA Server H.323 Memory Leak Denial of Service Vulnerability
19767| [3195] Microsoft IIS MIME Header Denial of Service Vulnerability
19768| [3194] Microsoft IIS WebDAV Invalid Request Denial of Service Vulnerability
19769| [3185] Microsoft Windows 2000 RunAs Service Named Pipe Hijacking Vulnerability
19770| [3183] Microsoft Windows NNTP Denial of Service Vulnerability
19771| [3104] Microsoft Remote Procedure Call Service DoS Vulnerability
19772| [3090] Microsoft Services for Unix Telnet DoS Vulnerability
19773| [3089] Microsoft Services for Unix NFS DoS Vulnerability
19774| [3045] Microsoft Exchange 5.5 LDAP Denial of Service Vulnerabilities
19775| [2844] Microsoft Windows 2000 Telnet Service DoS Vulnerability
19776| [2717] Microsoft IIS FTP Denial of Service Vulnerability
19777| [2654] Microsoft IIS Long URL Denial of Service Vulnerability
19778| [2483] Microsoft IIS WebDAV 'Search' Denial of Service Vulnerability
19779| [2453] Microsoft IIS WebDAV Denial of Service Vulnerability
19780| [2218] Microsoft IIS '../..' Denial of Service Vulnerability
19781| [2133] Microsoft Windows 2000 Directory Services Restore Mode Blank Password Vulnerability
19782| [2123] Microsoft Windows Media Services Severed Connection DoS Vulnerability
19783| [2111] Microsoft NT RAS/PPTP Malformed Control Packet Denial of Service Attack
19784| [1987] Microsoft NT 4.0 SynAttackProtect Denial of Service Vulnerability
19785| [1933] Microsoft Indexing Services for Windows 2000 File Verification Vulnerability
19786| [1861] Microsoft Indexing Services .htw Cross-Site Scripting Vulnerability
19787| [1655] Microsoft Windows Media Unicast Services DoS Vulnerability
19788| [1651] Microsoft Windows 2000 Still Image Service Privilege Escalation Vulnerability
19789| [1608] Microsoft FrontPage Server Extensions MS-DOS Device Name Denial Of Service Vulnerability
19790| [1476] Microsoft IIS 3.0 .htr Missing Variable Denial of Service Vulnerability
19791| [1435] Microsoft FrontPage 2000 Server Extensions Denial Of Service Vulnerability
19792| [1282] Microsoft Media Service DoS Vulnerability
19793| [1000] Microsoft Windows Media Services Handshake Sequence DoS Vulnerability
19794|
19795| IBM X-Force - https://exchange.xforce.ibmcloud.com:
19796| [24402] Microsoft Windows 2000 Terminal Service client IP not logged
19797| [16521] Microsoft Windows 2003 Deny Logon Through Terminal Services privilege
19798| [11816] Microsoft Windows 2000 Terminal Services MSGINA.DLL insecure access permissions
19799| [11696] Microsoft Windows 2000 Terminal Services man-in-the-middle attack
19800| [11141] Microsoft Windows 2000 Terminal Services MSGINA.DLL denial of service
19801| [9946] Microsoft Windows 2000 Terminal Services session screensaver fails to lock the console
19802| [8813] Microsoft Windows 2000 Terminal Services allows attacker to bypass group policy settings
19803| [8199] Microsoft Windows 2000 Terminal Services unlocked client
19804| [7538] Microsoft Windows 2000 and XP Terminal services allow an attacker to spoof IP addresses
19805| [7302] Microsoft Windows NT and 2000 Terminal Server malformed RDP packet series denial of service
19806| [6912] Microsoft Windows NT and 2000 Terminal Server RDP memory leak denial of service
19807| [4083] Microsoft Windows 2000 Terminal Services may damage Office files saved as HTML
19808| [86090] Microsoft Windows ICMPv6 denial of service
19809| [86072] Microsoft Windows Active Directory Federation Services information disclosure
19810| [86069] Microsoft Windows Windows NAT Driver denial of service
19811| [85802] Microsoft PowerPoint denial of service
19812| [85801] Microsoft Windows Movie Maker .wav denial of service
19813| [85233] Microsoft Windows denial of service
19814| [84620] Microsoft Windows kernel denial of service
19815| [84571] Microsoft Windows denial of service
19816| [84546] Microsoft Windows Media Player .wav denial of service
19817| [83911] Microsoft Windows denial of service
19818| [83099] Microsoft Windows denial of service
19819| [83095] Microsoft Windows denial of service
19820| [82771] Microsoft Internet Explorer sandbox denial of service
19821| [82769] Microsoft Windows TTF denial of service
19822| [82421] Microsoft SharePoint W3WP denial of service
19823| [82089] Microsoft Windows ZwSetInformationProcess() denial of service
19824| [81677] Microsoft Windows TCP/IP sequence denial of service
19825| [81675] Microsoft Windows NFS server denial of service
19826| [80866] Microsoft .NET Framework OData denial of service
19827| [80750] Microsoft Internet Explorer denial of service
19828| [80523] Microsoft Exchange Server RSS feeds denial of service
19829| [79651] Microsoft Paint .bmp denial of service
19830| [79649] Microsoft Office Publisher denial of service
19831| [79648] Microsoft Windows Help Viewer denial of service
19832| [79479] Microsoft Windows Media Player .avi denial of service
19833| [78861] Microsoft Windows Kerberos denial of service
19834| [77993] Microsoft Indexing Service ActiveX control denial of service
19835| [77359] Microsoft Internet Information Services FTP information disclosure
19836| [77358] Microsoft Internet Information Services log files information disclosure
19837| [77354] Microsoft Windows Print Spooler service format string
19838| [77353] Microsoft Windows Remote Administration Protocol denial of service
19839| [76835] Synel SY-780/A terminal denial of service
19840| [76743] Microsoft .NET Framework tilde denial of service
19841| [76716] Microsoft IIS FTP denial of service
19842| [76223] Microsoft Windows .otf denial of service
19843| [76221] Microsoft Windows XML Core Services code execution
19844| [75977] Microsoft WordPad .doc denial of service
19845| [75329] Microsoft Windows xxxCreateWindowEx() denial of service
19846| [75134] Microsoft .NET Framework index denial of service
19847| [73870] Microsoft Internet Explorer Protected Mode denial of service
19848| [73542] Microsoft Windows Remote Desktop Protocol denial of service
19849| [73539] Microsoft DirectWrite denial of service
19850| [73532] Microsoft Windows DNS Server denial of service
19851| [73029] Microsoft Internet Explorer BODY denial of service
19852| [72346] Microsoft Windows Explorer denial of service
19853| [71989] Microsoft ASP.NET CaseInsensitiveHashProvider.getHashCode() function denial of service
19854| [71966] Microsoft Windows Media Player access denial of service
19855| [71944] Microsoft Windows Phone messages denial of service
19856| [71418] Microsoft Windows keyboard layout denial of service
19857| [70946] Microsoft Windows TrueType denial of service
19858| [70337] OpenOffice.org Microsoft Word .doc sprm file parser denial of service
19859| [70148] Microsoft Host Integration Server UDP denial of service
19860| [70112] Microsoft Windows TrueType denial of service
19861| [70107] Microsoft Forefront Unified Access Gateway NULL denial of service
19862| [69638] Microsoft Windows csrss.exe denial of service
19863| [69215] Microsoft Windows DHCPv6 denial of service
19864| [69214] Microsoft Internet Explorer Iedvtool.dll denial of service
19865| [68838] Microsoft SharePoint and Windows SharePoint Services cross-site scripting
19866| [68837] Microsoft SharePoint and Windows SharePoint Services XML file disclosure
19867| [68836] Microsoft SharePoint and Windows SharePoint Services contact details cross-site scripting
19868| [68830] Microsoft Windows Remote Desktop Protocol denial of service
19869| [68815] Microsoft Windows kernel meta-data denial of service
19870| [68808] Microsoft Windows DNS Server denial of service
19871| [68803] Microsoft Windows TCP/IP QoS denial of service
19872| [68802] Microsoft Windows TCP/IP ICMP denial of service
19873| [68469] Microsoft Windows GPU denial of service
19874| [68467] Microsoft Windows NVIDIA Geforce 310 denial of service
19875| [68465] Microsoft Windows Intel G41 denial of service
19876| [68002] Microsoft Windows Media Player klite denial of service
19877| [67761] Microsoft XML Editor Web Service Discovery information disclosure
19878| [67750] Microsoft Windows Active Directory Certificate Services Web Enrollment cross-site scripting
19879| [67730] Microsoft Windows Server Hyper-V VMBus denial of service
19880| [67727] Microsoft Windows DFS denial of service
19881| [67724] Microsoft Windows SMB request denial of service
19882| [67520] Microsoft Windows Vista nsiproxy.sys denial of service
19883| [67100] Microsoft Windows Windows Internet Name Service code execution
19884| [66855] Microsoft Windows Media Player .ogg denial of service
19885| [66639] Microsoft Windows XP afd.sys denial of service
19886| [66469] Microsoft Windows Explorer Shmedia.dll denial of service
19887| [64915] Microsoft Windows Active Directory denial of service
19888| [64583] Microsoft Windows Neighbor Discovery (ND) protocol denial of service
19889| [64248] Microsoft Internet Information Services TELNET_STREAM_CONTEXT::OnSendData buffer overflow
19890| [63585] Microsoft Windows Netlogon denial of service
19891| [63572] Microsoft Exchange Server RPC denial of service
19892| [63563] Microsoft Windows Server Hyper-V VMBus denial of service
19893| [63514] Microsoft Outlook file attachment denial of service
19894| [62737] Microsoft WindowsTask Scheduler service privilege escalation
19895| [62716] Microsoft Windows Mobile .vcf denial of service
19896| [62186] Microsoft Internet Information Services directory names code execution
19897| [62148] Microsoft Windows SChannel denial of service
19898| [61994] Microsoft Windows MPEG Layer-3 Audio Decoder denial of service
19899| [61937] Microsoft Word MSO.dll denial of service
19900| [61894] Microsoft Paint BMP denial of service
19901| [61513] Microsoft Internet Information Services (IIS) URL authentication bypass
19902| [61512] Microsoft Internet Information Services request header buffer overflow
19903| [61511] Microsoft Internet Information Services repeated POST denial of service
19904| [61503] Microsoft Windows Print Spooler service code execution
19905| [61258] Microsoft Windows IcmpSendEcho2Ex denial of service
19906| [61184] Microsoft Windows win32k!GreStretchBltInternal() denial of service
19907| [60739] Microsoft Internet Explorer frame.frameBorder denial of service
19908| [60721] Microsoft WindowsTCP/IP IPv6 denial of service
19909| [60704] Microsoft Windows kernel ACL denial of service
19910| [60693] Microsoft Windows kernel-mode drivers denial of service
19911| [60691] Microsoft Windows SMB stack denial of service
19912| [60690] Microsoft Windows SMB variable denial of service
19913| [60683] Microsoft Windows XML Core Services (MSXML) code execution
19914| [60678] Microsoft Windows Service Isolation privilege escalation
19915| [60522] Microsoft Clip Organizer ActiveX control denial of service
19916| [59088] Microsoft Internet Explorer nntp:// URIs denial of service
19917| [59087] Microsoft Internet Explorer news:// URIs denial of service
19918| [59069] Microsoft Internet Explorer CSS expression denial of service
19919| [58890] Microsoft SharePoint help page denial of service
19920| [58864] Microsoft Internet Information Services (IIS) authentication code execution
19921| [58757] Microsoft Internet Explorer IFRAME element denial of service
19922| [58345] Microsoft Windows SMTP Service query id spoofing
19923| [58344] Microsoft Windows SMTP Service DNS spoofing
19924| [58243] Microsoft Office SharePoint Server and Microsoft Windows SharePoint Services help.aspx cross-site scripting
19925| [58059] Microsoft Windows SfnLOGONNOTIFY() denial of service
19926| [57601] Microsoft Windows kernel exceptions denial of service
19927| [57600] Microsoft Windows kernel image file denial of service
19928| [57599] Microsoft Windows kernel path denial of service
19929| [57597] Microsoft Windows kernel registry keys denial of service
19930| [57596] Microsoft Windows kernel symbolic links denial of service
19931| [57595] Microsoft Windows kernel registry keys denial of service
19932| [57581] Microsoft Office Communicator SIP INVITE denial of service
19933| [57401] Microsoft Internet Explorer data structures denial of service
19934| [57329] Microsoft Windows Media Services info packets buffer overflow
19935| [57324] Microsoft Windows SMTP Service Simple Mail Transfer Protocol memory information disclosure
19936| [57323] Microsoft Windows SMTP Service and Microsoft Exchange SMTP DNS Mail Exchanger (MX) denial of service
19937| [56756] Microsoft Windows .ani file denial of service
19938| [56651] Microsoft Internet Information Services DNS cross-site scripting
19939| [56591] Microsoft Windows API denial of service
19940| [56435] Microsoft Windows Media Player .mpg denial of service
19941| [55925] Microsoft Windows Hyper-V instruction set denial of service
19942| [55922] Microsoft Windows Kerberos Ticket-Granting-Ticket (TGT) denial of service
19943| [55908] Microsoft Windows SMB NULL denial of service
19944| [55907] Microsoft Windows SMB denial of service
19945| [55900] Microsoft Internet Explorer createElement denial of service
19946| [55897] Microsoft Windows TCP/IP SACK denial of service
19947| [55863] Microsoft Internet Explorer multiple unspecified denial of service
19948| [55308] Microsoft Internet Information Services colon security bypass
19949| [55031] Microsoft Internet Information Services (IIS) filenames security bypass
19950| [54442] Microsoft Windows Local Security Authority Subsystem Service (LSASS) denial of service
19951| [54439] Microsoft Windows Internet Authentication Service (IAS) privilege escalation
19952| [54438] Microsoft Windows Internet Authentication Service (IAS) code execution
19953| [54426] Microsoft Windows Active Directory Federation Services (ADFS) code execution
19954| [54425] Microsoft Windows Active Directory Federation Services (ADFS) spoofing
19955| [54317] Microsoft Internet Explorer setHomePage denial of service
19956| [54217] Microsoft Windows KeAccumulateTicks() denial of service
19957| [53990] Microsoft Windows ADAM LDAP denial of service
19958| [53547] Microsoft Windows kernel exception handler denial of service
19959| [53540] Microsoft Windows Indexing Service ActiveX control code execution
19960| [53519] Microsoft Server Message Block (SMB) Protocol software denial of service
19961| [53511] Microsoft Windows Local Security Authority Subsystem Service (LSASS) denial of service
19962| [53417] Microsoft Internet KEYGEN denial of service
19963| [53414] Microsoft Internet window.print denial of service
19964| [53034] Microsoft Internet Information Services (IIS) directory listings denial of service
19965| [52925] Sophos PureMessage for Microsoft Exchange EdgeTransport.exe denial of service
19966| [52915] Microsoft Internet Information Services (IIS) FTP buffer overflow
19967| [52897] Microsoft Internet Explorer JavaScript code denial of service
19968| [52870] Microsoft Internet Explorer integer value denial of service
19969| [52765] Microsoft Internet Explorer XML denial of service
19970| [52762] Microsoft Internet Explorer Unicode string denial of service
19971| [52722] Microsoft Internet Explorer DIV element denial of service
19972| [52590] Microsoft Internet Explorer JavaScript SetAttribute denial of service
19973| [52403] Microsoft Windows OpenType font engine denial of service
19974| [52249] Microsoft Internet Explorer mshtml.dll denial of service
19975| [52127] Microsoft Windows TCP/IP orphaned connections denial of service
19976| [52116] Microsoft Windows RDP Services Client ActiveX control buffer overflow
19977| [52113] ASP.NET Framework component of Microsoft Windows HTTP denial of service
19978| [52110] Microsoft Windows Windows Internet Name Service (WINS) replication partner buffer overflow
19979| [52109] Microsoft Windows Windows Internet Name Service (WINS) replication buffer overflow
19980| [52106] Microsoft Message Queuing Service (MSMQ) IOCTL privilege escalation
19981| [52092] Microsoft Windows Workstation Service RPC message code execution
19982| [51468] Microsoft Windows Wireless LAN AutoConfig service buffer overflow
19983| [50973] Microsoft Windows Server 2003 and Vista win32k.sys denial of service
19984| [50903] Microsoft Windows SPI_SETDESKWALLPAPER SystemParametersInfo denial of service
19985| [50765] Microsoft Windows Print Spooler service privilege escalation
19986| [50764] Microsoft Print Spooler service information disclosure
19987| [50763] Microsoft Windows Print Spooler service buffer overflow
19988| [50761] Microsoft Windows Active Directory LDAP denial of service
19989| [50573] Microsoft Internet Information Services (IIS) WebDAV security bypass
19990| [50391] Microsoft Windows Media Player MID file denial of service
19991| [50350] Microsoft Internet Explorer unprintable characters denial of service
19992| [50129] Microsoft Windows gdiplus.dll PNG denial of service
19993| [49566] Microsoft Windows HTTP services certificate spoofing
19994| [49564] Microsoft ISAServer and Microsoft Forefront TMG Web proxy TCP state denial of service
19995| [49562] Microsoft Windows HTTP services integer underflow
19996| [49438] Microsoft Windows GDI+ EMF EmfPlusFont Object denial of service
19997| [49109] OpenBSD and Microsoft Interix fts_build function denial of service
19998| [49079] Microsoft Windows DNS server memory leak denial of service
19999| [48815] Microsoft XML Core Services HTTPOnly Set-Cookie2 HTTP response headers information disclosure
20000| [48335] Microsoft Internet Explorer HTML form value denial of service
20001| [48179] Sun Solaris pseudo-terminal driver denial of service
20002| [47867] Microsoft Windows .CHM file denial of service
20003| [47788] Microsoft Internet Explorer JavaScript onload=screen attribute denial of service
20004| [47756] Microsoft Money prtstb06.dll ActiveX control denial of service
20005| [47671] Microsoft Exchange Server EMSMDB2 invalid MAPI commands denial of service
20006| [47664] Microsoft Windows Media Player WAV or SND file denial of service
20007| [46673] Microsoft Communicator SIP INVITE message unspecified denial of service
20008| [46671] Microsoft Communicator emoticon unspecified denial of service
20009| [46670] Microsoft Communicator, Office Communications Server (OCS) and Windows Live Messenger RTCP unspecified denial of service
20010| [46506] Microsoft Windows UnhookWindowsHookEx() denial of service
20011| [46385] Microsoft Windows Media Player MIDI or DAT file denial of service
20012| [46309] Microsoft Debug Diagnostic Tool DebugDiag ActiveX control denial of service
20013| [46100] Microsoft Windows XP Service Pack 3 is not installed on the system
20014| [46099] Microsoft Windows XP Service Pack 1 is not installed on the system
20015| [46040] Microsoft Windows Server Service RPC code execution
20016| [45746] Cisco Unity Microsoft API unspecified denial of service
20017| [45719] Microsoft Windows Vista page faults denial of service
20018| [45639] Microsoft Internet Explorer alert function denial of service
20019| [45584] Microsoft IIS adsiis.dll ActiveX control denial of service
20020| [45556] Microsoft IAS Helper COM ActiveX control denial of service
20021| [45555] Microsoft XML Core Services chunked transfer-encoding headers information disclosure
20022| [45554] Microsoft XML Core Services DTD information disclosure
20023| [45464] Microsoft Windows XP GDI+ .ICO denial of service
20024| [45463] Microsoft Windows Mobile bluetooth device name denial of service
20025| [45420] Microsoft WordPad .doc denial of service
20026| [45225] Microsoft Internet Explorer PNG file denial of service
20027| [45146] Microsoft Windows WRITE_ANDX SMB packet denial of service
20028| [44775] PureMessage for Microsoft Exchange PMScanner.exe denial of service
20029| [43980] MINIX pseudo terminal denial of service
20030| [43869] F-PROT Antivirus Microsoft Office file denial of service
20031| [42696] Microsoft Windows PGM fragment option denial of service
20032| [42695] Microsoft Windows PGM option length denial of service
20033| [42668] Microsoft Windows Active Directory LDAP request denial of service
20034| [42232] Microsoft Internet Explorer ActiveX string concatenation denial of service
20035| [42108] Microsoft Malware Protection Engine data structure denial of service
20036| [42107] Microsoft Malware Protection Engine file denial of service
20037| [41934] Microsoft SharePoint Services Picture Source cross-site scripting
20038| [41338] Microsoft Internet Explorer CreateTextRange method denial of service
20039| [40579] Microsoft Active Directory unspecified denial of service
20040| [40577] Microsoft Internet Explorer files denial of service
20041| [40286] Microsoft Internet Explorer src attribute denial of service
20042| [40283] Microsoft Internet Explorer style attribute denial of service
20043| [40102] Microsoft Windows Active Directory LDAP request denial of service
20044| [40098] Microsoft Windows Vista DHCP denial of service
20045| [40087] Microsoft Internet Explorer multiple ActiveX control denial of service
20046| [39254] Microsoft Windows TCP/IP ICMP denial of service
20047| [39209] Microsoft Word wordart denial of service
20048| [39208] Microsoft Office Publisher multiple denial of service
20049| [38797] Microsoft Windows Media Player AIFF denial of service
20050| [38440] Microsoft Forms ActiveX control denial of service
20051| [38430] Microsoft Office Web Component OWC11.DataSourceControl ActiveX denial of service
20052| [37200] Microsoft SQL Server 2000 Service Pack 1 update is not installed
20053| [37198] Microsoft SQL Server 2000 Service Pack 3 update is not installed
20054| [36980] Microsoft Windows Explorer PNG file denial of service
20055| [36803] Microsoft Windows RPC NTLMSSP authentication denial of service
20056| [36378] Microsoft Windows UNIX services setuid binary privilege escalation
20057| [36128] Microsoft Internet Explorer position:relative HTML style code denial of service
20058| [36027] Microsoft Internet Explorer ActiveX popup blocker denial of service
20059| [35902] Microsoft Windows process scheduler denial of service
20060| [35886] Microsoft Windows ARP request denial of service
20061| [35878] Microsoft Windows Media Player .AU file denial of service
20062| [35855] Microsoft Register Server DLL file denial of service
20063| [35802] Microsoft Windows Vista Calendar ICS denial of service
20064| [35764] Microsoft Message Queuing Service buffer overflow
20065| [35538] Microsoft Windows Explorer GIF denial of service
20066| [35455] Microsoft Internet Explorer Zone domain name denial of service
20067| [35397] Microsoft Windows Vista USER32.DLL denial of service
20068| [35197] Microsoft Internet Information Services URL parser buffer overflow
20069| [35195] Microsoft XML Core Services (MSXML) memory request code execution
20070| [35180] Microsoft Windows Active Directory LDAP denial of service
20071| [34755] Microsoft Internet Explorer Outlook Express Address Book object denial of service
20072| [34754] Microsoft Internet Explorer MSHtmlPopupWindow object denial of service
20073| [34743] Microsoft Windows GDI+ denial of service
20074| [34650] Microsoft Internet Explorer Javascript src attribute denial of service
20075| [34639] Microsoft .NET Framework JIT Compiler service buffer overflow
20076| [34637] Microsoft .NET Framework PE Loader service buffer overflow
20077| [34599] Microsoft Windows Server 2003 terminal server security bypass
20078| [34418] Microsoft Internet Information Server (IIS) AUX/.aspx denial of service
20079| [33890] Microsoft Exchange IMAP command denial of service
20080| [33888] Microsoft Exchange iCal MODPROPS denial of service
20081| [33715] Microsoft Internet Explorer unspecified JavaScript denial of service
20082| [33713] Microsoft Word 2007 multiple unspecified denial of service
20083| [33399] Microsoft Windows Vista LLTD Mapper denial of service
20084| [33393] Microsoft Windows Vista ARP denial of service
20085| [33300] Microsoft Windows Vista atikmdag.sys slideshow denial of service
20086| [33258] Microsoft Windows GDI WMF image denial of service
20087| [33118] Microsoft Windows XP winmm.dll denial of service
20088| [33086] Microsoft Windows Ndistapi.sys driver denial of service
20089| [33041] Microsoft Excel XML and XLS file denial of service
20090| [33039] Microsoft Office WMF file denial of service
20091| [33037] Microsoft Windows Explorer WMF file denial of service
20092| [32939] Microsoft Internet Explorer resizeTo denial of service
20093| [32921] Microsoft Windows ole32.dll library denial of service
20094| [32831] Microsoft Internet Explorer BrowseDialog ActiveX control denial of service
20095| [32647] Microsoft Internet Explorer onUnload handler denial of service
20096| [32631] Microsoft SQL Server 2000 Service Pack 2 update is not installed
20097| [32457] Microsoft Internet Explorer getElementById denial of service
20098| [32454] Microsoft Visual Studio time functions denial of service
20099| [32394] Microsoft Windows Mobile Internet Explorer WML page denial of service
20100| [32280] Microsoft Windows Image Acquisition service buffer overflow
20101| [32071] Microsoft Windows Explorer AVI file denial of service
20102| [32002] Microsoft Windows Mobile Pictures and Videos JPEG denial of service
20103| [32001] Microsoft Windows Mobile Internet Explorer unspecified denial of service
20104| [31867] Microsoft Internet Explorer ActiveX multiple properties denial of service
20105| [31814] Microsoft Internet Explorer IFRAME file URI denial of service
20106| [31675] Microsoft Internet Explorer BrowseDialog ActiveX control denial of service
20107| [31642] Microsoft IIS Web server service.cnf file detected
20108| [31630] Microsoft Internet Information Services IISAdmin directory detected
20109| [31549] Microsoft Internet Explorer CCRP Folder Treeview ActiveX control denial of service
20110| [31358] Microsoft XML Core Services IFRAME code execution
20111| [31187] Microsoft Outlook email long header denial of service
20112| [31085] Microsoft Windows Workstation service NetrWkstaUserEnum denial of service
20113| [31015] Microsoft Windows Explorer WMV file denial of service
20114| [31014] Microsoft Windows Media Player MIDI file denial of service
20115| [31011] Microsoft Internet Information Services IUSR_Machine command execution
20116| [30959] Microsoft Outlook ole32.dll ActiveX denial of service
20117| [30756] Microsoft Windows Remote Installation Service code execution
20118| [30717] Microsoft Windows Print Spooler denial of service
20119| [30605] Microsoft Windows SNMP service buffer overflow
20120| [30553] Microsoft Windows Live Messenger emoticon denial of service
20121| [29953] Microsoft Windows Client Service for NetWare (CSNW) denial of service
20122| [29952] Microsoft Windows Client Service for NetWare (CSNW) buffer overflow
20123| [29948] Microsoft Windows Workstation service NetpManageIPCConnect buffer overflow
20124| [29917] Microsoft Windows XP NAT Helper ipnathlp.dll denial of service
20125| [29507] Microsoft Office 2003 unspecified PowerPoint NULL pointer dereference denial of service
20126| [29400] Microsoft Windows drmstor.dll denial of service
20127| [29373] Microsoft Windows SMB rename denial of service
20128| [29210] Microsoft XML Core Services XLST buffer overflow
20129| [29206] Microsoft XML Core Services XMLHTTP information disclosure
20130| [29135] Microsoft Internet Explorer CSS HTML INPUT DIV element denial of service
20131| [28651] Microsoft Indexing Service cross-site scripting
20132| [28608] Microsoft Internet Explorer daxctle.ocx denial of service
20133| [28516] Microsoft Internet Explorer multiple COM object color property denial of service
20134| [28512] Microsoft Internet Explorer multiple Windows 2000 COM object denial of service
20135| [28511] Microsoft Internet Explorer multiple Visual Studio COM object denial of service
20136| [28474] Microsoft Windows PNG IHDR block denial of service
20137| [28444] Microsoft Internet Explorer tsuserex.dll COM object denial of service
20138| [28439] Microsoft Internet Explorer msoe.dll COM object denial of service
20139| [28438] Microsoft Internet Explorer chtskdic.dll COM object denial of service
20140| [28436] Microsoft Internet Explorer imskdic.dll COM object denial of service
20141| [28281] Microsoft Windows WMF gdi32.dll denial of service
20142| [28183] Microsoft Windows gdiplus.dll denial of service
20143| [28068] Microsoft Internet Explorer deleted frame access denial of service
20144| [28066] Microsoft Internet Explorer ADODB.Recordset ActiveX object denial of service
20145| [28046] Microsoft Internet Explorer NDFXArtEffects ActiveX object denial of service
20146| [28002] Microsoft Windows Server service buffer overflow
20147| [27999] Microsoft Windows SMB malformed PIPE denial of service
20148| [27932] Microsoft Internet Explorer native function iteration denial of service
20149| [27931] Microsoft Internet Explorer Forms.ListBox.1 and Forms.ComboBox.1 ActiveX object denial of service
20150| [27930] Microsoft Internet Explorer ASFSourceMediaDescription ActiveX object denial of service
20151| [27929] Microsoft Internet Explorer Internet.HHCtrl ActiveX object denial of service
20152| [27900] Microsoft Internet Explorer wininet.dll denial of service
20153| [27890] Microsoft Internet Explorer href title denial of service
20154| [27884] Microsoft Internet Explorer CEnroll ActiveX object denial of service
20155| [27845] Microsoft Internet Explorer OVCtl ActiveX object denial of service
20156| [27803] Microsoft Internet Explorer DataSourceControl ActiveX object denial of service
20157| [27795] Microsoft Works wksss.exe denial of service
20158| [27762] Microsoft Internet Explorer DXImageTransform.Microsoft.Gradient ActiveX object denial of service
20159| [27761] Microsoft Internet Explorer MHTMLFile ActiveX object denial of service
20160| [27760] Microsoft Internet Explorer FolderItem control denial of service
20161| [27713] Microsoft Internet Explorer RevealTrans ActiveX object denial of service
20162| [27675] Microsoft Internet Explorer TriEditDocument ActiveX object denial of service
20163| [27649] Microsoft Internet Explorer HtmlDlgSafeHelper ActiveX object denial of service
20164| [27623] Microsoft Internet Explorer Object.Microsoft.DXTFilter ActiveX object denial of service
20165| [27622] Microsoft Internet Explorer DirectAnimation.DAUserData ActiveX object denial of service
20166| [27621] Microsoft Internet Explorer RDS.DataControl ActiveX object denial of service
20167| [27617] Microsoft Office mso.dll LsCreateLine() denial of service
20168| [27599] Microsoft Internet Explorer OutlookExpress.AddressBook ActiveX object denial of service
20169| [27596] Microsoft Internet Explorer ADODB.Recordset ActiveX object denial of service
20170| [27592] Microsoft Internet Explorer table.frameset appendChild() denial of service
20171| [27567] Microsoft Windows explorer.exe Internet Shortcut (.url) denial of service
20172| [27565] Microsoft Internet Explorer StructuredGraphicsControl SourceURL denial of service
20173| [27417] Microsoft Windows Live Messenger contact list denial of service
20174| [26971] Microsoft NetMeeting unspecified memory corruption denial of service
20175| [26830] Microsoft Windows SMB invalid handle denial of service
20176| [26820] Microsoft Windows SMB Server service information disclosure
20177| [26817] Microsoft Internet Explorer CSS position denial of service
20178| [26808] Microsoft Internet Explorer HTML tag parsing denial of service
20179| [26796] Microsoft Internet Information Services (IIS) ASP buffer overflow
20180| [25852] Microsoft Internet Explorer CSS scrollbar denial of service
20181| [25844] Microsoft Dynamics GP magic number denial of service
20182| [25392] Microsoft ASP.NET COM and COM+ w3wp.exe denial of service
20183| [25369] Microsoft Windows DNS recursive query denial of service
20184| [25284] Microsoft Internet Explorer HTML CSS null dereference denial of service
20185| [25256] Microsoft Internet Explorer Java VM denial of service
20186| [25011] Microsoft Internet Explorer display adapter JPEG image denial of service
20187| [24846] Microsoft Internet Explorer window.status memory leak denial of service
20188| [24788] Microsoft Internet Explorer Script Engine stack denial of service
20189| [24629] BlackBerry Enterprise Server Attachment Service Microsoft Word file buffer overflow
20190| [24491] Microsoft Windows MSRPC WebClient service message buffer overflow
20191| [24489] Microsoft Windows IGMP v3 denial of service
20192| [24488] Microsoft Windows Media Player BMP image parsing service buffer overflow
20193| [24346] Microsoft Office \BaseNamedObjects\Mso97SharedDg denial of service
20194| [24162] Microsoft Internet Explorer invalid IMG and XML element denial of service
20195| [24044] Microsoft Windows GRE ExtCreateRegion() and ExtEscape() WMF denial of service
20196| [23895] Microsoft Internet Explorer HTML denial of service
20197| [23706] Microsoft MSN Messenger and Internet Explorer image denial of service
20198| [23284] Microsoft Windows SynAttackProtect denial of service
20199| [23066] Microsoft Windows XP and 2000 Server MSRPC memory allocation denial of service
20200| [22852] Microsoft Internet Explorer mshtmled.dll denial of service
20201| [22524] Microsoft Windows XP Wireless Zero Configuration service information disclosure
20202| [22476] Microsoft Windows Distributed Transaction Coordinator message denial of service
20203| [22475] Microsoft Windows Distributed Transaction Coordinator TIP denial of service
20204| [22318] Microsoft SQL Server 2000 Service Pack 4 update is not installed
20205| [22183] Microsoft Exchange Server 2003 public folder denial of service
20206| [21978] Microsoft Windows user32.dll component denial of service
20207| [21930] Microsoft Internet Explorer URL restricted zone denial of service
20208| [21700] Microsoft Windows Client Service for NetWare code execution
20209| [21658] Microsoft ActiveSync multiple request denial of service
20210| [21625] Microsoft Windows kerberos message denial of service
20211| [21599] Microsoft Windows telephony service buffer overflow
20212| [21553] Microsoft Internet Explorer AJAX denial of service
20213| [21537] Microsoft FrontPage style tag denial of service
20214| [21455] MSN (Microsoft Network) Messenger .pif denial of service
20215| [21407] Microsoft Windows RDP request denial of service
20216| [21355] Microsoft Windows Network Connection Manager denial of service
20217| [21352] Microsoft ASP.NET RCP/encoded denial of service
20218| [21345] Microsoft Windows 2000 Update Rollup 1 for Service Pack 4 has not been installed
20219| [21071] Microsoft Internet Explorer BMP memory denial of service
20220| [21025] Microsoft ISA Server SecureNAT client configuration denial of service
20221| [20818] Microsoft Windows WebClient Service buffer overflow
20222| [20629] Multiple Microsoft Windows IPv6 LAND denial of service
20223| [20408] Microsoft ASP.NET Framework _VIEWSTATE denial of service
20224| [19969] Multiple Microsoft Windows Server 2003 Edition printer driver denial of service
20225| [19965] Multiple Microsoft Windows Server 2003 Editions SMB redirector denial of service
20226| [19727] Microsoft Windows 2000 GDI32.DLL denial of service
20227| [19629] Microsoft Exchange Server 2003 folder denial of service
20228| [19593] Microsoft Windows LAND denial of service
20229| [19220] Microsoft Windows registry key connection denial of service
20230| [19103] Multiple Microsoft Windows TCP/IP denial of service
20231| [19101] Microsoft Windows Servers License Logging service code execution
20232| [19091] Microsoft Windows SharePoint Services and SharePoint Team Services cross-site scripting
20233| [18758] Microsoft Windows Indexing Service allows code execution
20234| [18667] Microsoft Windows ANI file zero rate number overflow denial of service
20235| [18341] Microsoft Windows NT DHCP MachineName denial of service
20236| [18336] Microsoft Windows HyperTerminal session file buffer overflow
20237| [17931] Microsoft Internet Explorer mshtml.dll denial of service
20238| [17911] Microsoft Internet Explorer FONT tags denial of service
20239| [17864] Microsoft Windows XP Explorer WAV file denial of service
20240| [17739] Microsoft FrontPage and Internet Explorer asycpict.dll JPEG denial of service
20241| [17645] Microsoft Internet Information Server WebDAV multiple attributes per XML elements cause denial of service
20242| [17621] Microsoft Windows 2003 SMTP service code execution
20243| [17560] Microsoft Windows 2000 and XP GDI library denial of service
20244| [17542] Microsoft SQL Server data buffer denial of service
20245| [17521] Microsoft Windows 2000 Service Pack 4 is not installed
20246| [17457] Microsoft Windows XP Explorer.exe TIFF denial of service
20247| [17004] Microsoft Windows XP Service Pack 2 is not installed on the system
20248| [16913] Microsoft Windows 2003 users with Synchronize directory service data privilege
20249| [16912] Microsoft Windows 2003 groups with Synchronize directory service data privilege
20250| [16851] Microsoft Windows 2003 and XP WinKey and U key denial of service
20251| [16709] Microsoft Internet Explorer JavaScript denial of service
20252| [16696] Microsoft Systems Management Server (SMS) Remote Control Client service denial of service
20253| [16678] Microsoft Internet Explorer text file denial of service
20254| [16585] Microsoft Outlook Express malformed email header denial of service
20255| [16582] Microsoft Windows Server 2003 kernel CPU denial of service
20256| [16448] Microsoft MN-500 Web administration denial of service
20257| [16420] Microsoft Internet Explorer null pointer denial of service
20258| [16384] Microsoft ISA Server Web Proxy redirect denial of service
20259| [16380] Microsoft ISA Server Web Proxy SSL denial of service
20260| [16306] Microsoft DirectX DirectPlay denial of service
20261| [16211] Microsoft Windows Service Host buffer overflow exploit attempt detected
20262| [16210] Microsoft Windows Service Host buffer overflow exploit attempt detected
20263| [16208] Microsoft Windows RPC Locator Service buffer overflow exploit attempt detected
20264| [16201] Microsoft Internet Information Services buffer overflow exploit attempt detected
20265| [16189] Microsoft Internet Explorer CSS denial of service
20266| [16160] Microsoft Internet Explorer MSHTM.DLL http-equiv META tag denial of service
20267| [16154] Microsoft Windows NT 4.0 TSE Security Patch denial of service
20268| [15859] Microsoft Outlook email ASCII NUL denial of service
20269| [15832] Microsoft Internet Explorer IFRAME denial of service
20270| [15709] Microsoft Windows COM Internet Service and RPC over HTTP denial of service
20271| [15708] Microsoft Windows RPCSS Service RPC message can cause denial of service
20272| [15700] Microsoft Windows 2000 Domain Controller LSASS LDAP message denial of service
20273| [15591] Microsoft Visual Studio and Microsoft Visual C++ denial of service
20274| [15544] Microsoft Internet Explorer shell: command denial of service
20275| [15507] Microsoft Windows XP Explorer wmf denial of service
20276| [15394] Microsoft Windows service running under non-built-in accounts has been detected
20277| [15326] Microsoft Internet Explorer Perfect Nav plugin denial of service
20278| [15127] Microsoft Internet Explorer and Outlook null character in host name denial of service
20279| [15057] Microsoft Windows XP and Windows Server 2003 smbmount Linux client denial of service
20280| [15038] Microsoft Windows 2000 Server Windows Media Services denial of service
20281| [15037] Microsoft Windows Server 2003 WINS /GS flag denial of service
20282| [14422] MSMediaservice attaches to processes of Microsoft Internet Explorer and could allow an attacker to execute code
20283| [13809] Microsoft Internet Explorer scrollbar-base-color attribute denial of service
20284| [13680] Microsoft FrontPage Server Extensions SmartHTML Interpreter denial of service
20285| [13501] Microsoft Internet Explorer position: absolute denial of service
20286| [13453] Microsoft Internet Information Server 404 error message determines service pack level
20287| [13444] Microsoft Windows Non-English patched with MS03-045 denial of service in Sophos Anti-Virus
20288| [13433] Microsoft Exchange SMTP extended verb request denial of service
20289| [13413] Microsoft Windows Messenger Service popup buffer overflow
20290| [13344] Microsoft Windows 98 flood of fragmented UDP packets causes denial of service
20291| [13183] Microsoft Windows service pack detected
20292| [13089] Microsoft Windows NetBIOS Name Service information disclosure
20293| [13088] Microsoft IIS running RealSecure Server Sensor ISAPI plug-in denial of service
20294| [13029] Microsoft Internet Explorer input type tag denial of service
20295| [12872] Microsoft NetMeeting malformed packet denial of service
20296| [12762] Microsoft Windows NT 4.0 Q823803i patch RRAS denial of service
20297| [12701] Microsoft Windows NT 4.0 Server file management function denial of service
20298| [12700] Microsoft SQL Server named pipe denial of service
20299| [12684] Microsoft Exchange Server OWA Outlook 2003 denial of service
20300| [12679] Microsoft Windows RPC DCOM denial of service
20301| [12620] Microsoft Windows 2000 Server SMTP FILETIME denial of service
20302| [12538] Microsoft Internet Explorer C:\aux URL denial of service
20303| [12187] Microsoft Windows XP gethostbyaddr() denial of service
20304| [12100] Microsoft IIS long WebDAV requests containing XML denial of service
20305| [12099] Microsoft IIS Response.AddHeader denial of service
20306| [12043] Microsoft Internet Explorer Script Engine denial of service
20307| [11946] Microsoft Internet Explorer anchorClick behavior denial of service
20308| [11873] Microsoft Internet Explorer, Outlook, and FrontPage shlwapi.dll library denial of service
20309| [11824] Microsoft Windows XP Service Control Manager (SCM) race condition
20310| [11810] Microsoft Windows win2k.sys EngTextOut denial of service
20311| [11805] Microsoft Internet Explorer OBJECT tag denial of service
20312| [11752] Microsoft ISA and Proxy Server Firewall and Winsock Proxy service denial of service
20313| [11576] Microsoft ISA DNS intrusion detection application filter denial of service
20314| [11537] Microsoft IIS WebDAV service is running on the system
20315| [11430] Microsoft Locator service is running on the system
20316| [11415] Multiple vendor terminal emulator DEC UDK denial of service
20317| [11274] Microsoft Windows 2000 NetBIOS continuation packets denial of service
20318| [11273] Microsoft Windows 2000 RPC service could allow an attacker to gain elevated privileges
20319| [11216] Microsoft Windows NT and 2000 command prompt denial of service
20320| [11132] Microsoft Windows Locator service buffer overflow
20321| [11030] Microsoft Windows OpenType font (.otf) fontview denial of service
20322| [10763] Microsoft Outlook malformed email header denial of service
20323| [10588] Microsoft VM HTML Applet tag denial of service
20324| [10587] Microsoft VM passed HTML object denial of service
20325| [10583] Microsoft VM INativeServices could be used to access clipboard contents
20326| [10582] Microsoft VM INativeServices could allow unauthorized memory access
20327| [10503] Microsoft IIS WebDAV memory allocation denial of service
20328| [10431] Microsoft Windows 2000 SNMP LANMAN Extension memory leak denial of service
20329| [10400] Microsoft Windows 2000 RPC TCP port 135 denial of service
20330| [10370] Microsoft IIS HTTP HOST header denial of service
20331| [10259] Microsoft Services for Unix (SFU) invalid RPC packet denial of service
20332| [10258] Microsoft Services for Unix (SFU) RPC parameter size buffer overflow could crash the server
20333| [10194] Microsoft FrontPage Server Extensions (FPSE) 2000 SmartHTML Interpreter denial of service
20334| [10184] Microsoft IIS 5.0 resource utilization denial of service
20335| [10120] Microsoft Windows XP Remote Desktop malformed PDU Confirm Active packet denial of service
20336| [10117] Microsoft Internet Explorer FTP URL denial of service
20337| [10031] Microsoft SQL Server Resolution Service stack buffer overflow
20338| [9883] Microsoft Internet Explorer Google Toolbar search request denial of service
20339| [9791] Microsoft Exchange IIS license exhaustion denial of service
20340| [9789] Microsoft Exchange MSRPC denial of service
20341| [9752] Microsoft Windows 2000 Service Pack 3 is not installed
20342| [9662] Microsoft SQL Server Resolution Service keep-alive function denial of service
20343| [9661] Microsoft SQL Server Resolution Service heap buffer overflow
20344| [9657] Microsoft Metadirectory Services (MMS) could allow unauthorized access to the data repository
20345| [9617] Microsoft Internet Explorer JavaScript page transitions denial of service
20346| [9580] Microsoft IIS SMTP service encapsulated addresses could allow mail relaying
20347| [9531] Microsoft Internet Explorer CLASSID denial of service
20348| [9523] Microsoft SQL Server service account insecure registry permissions
20349| [9423] Microsoft Commerce Server Profile Service API buffer overflow
20350| [9421] Microsoft Windows Media Player WMDM service invalid resource connection could allow elevated privileges
20351| [9367] Microsoft Internet Explorer Cascading Style-Sheet (CSS) bold font denial of service
20352| [9195] Microsoft Exchange message attribute denial of service
20353| [9159] Microsoft Active Directory zero page length denial of service
20354| [9122] Microsoft Internet Explorer JavaScript self.location refresh denial of service
20355| [9087] Microsoft Internet Explorer and Outlook Express BGSOUND DOS device reference could cause a denial of service
20356| [8969] Microsoft Internet Explorer and Outlook Express malformed XBM file denial of service
20357| [8941] Microsoft Internet Explorer JavaScript recursive onError event denial of service
20358| [8904] Microsoft Internet Explorer self-referenced OBJECT directive denial of service
20359| [8867] Microsoft Windows 2000 LanMan denial of service
20360| [8815] Microsoft VBScript ActiveX Word object denial of service
20361| [8801] Microsoft IIS FTP session status request denial of service
20362| [8800] Microsoft IIS FrontPage Server Extensions and ASP.NET ISAPI filter error handling denial of service
20363| [8488] Microsoft Internet Explorer JavaScript location.replace loop denial of service
20364| [8356] Microsoft Outlook X-UIDL: header denial of service
20365| [8341] Microsoft Internet Explorer 4.0 long OBJECT CLASSID denial of service
20366| [8307] Microsoft Windows 2000, Windows XP, and Exchange 2000 SMTP data transfer command denial of service
20367| [8304] Microsoft Windows 2000 and Exchange 5.5 SMTP service unauthorized mail privileges
20368| [8209] Microsoft Windows XP CIFS port denial of service
20369| [8207] Microsoft Windows XP UDP port denial of service
20370| [8087] Microsoft Office v. X for Mac OS X PID Checker denial of service
20371| [8037] Microsoft Windows 2000 empty TCP packet denial of service
20372| [7947] BadBlue Microsoft Office file viewing script non-existent file request denial of service
20373| [7938] Microsoft Internet Explorer HTML form denial of service
20374| [7826] Microsoft Internet Explorer showModelessDialog() denial of service
20375| [7722] Microsoft Windows XP, Me, 98, and 98SE UPnP spoofed UDP packet with SSDP announcement denial of service attack
20376| [7709] Microsoft Windows multiple vendor Web browser high image count denial of service
20377| [7667] Microsoft Windows 2000 IKE UDP packet flood denial of service
20378| [7542] Microsoft Windows 95 and 98 with multiple TCP/IP stacks ICMP packet denial of service
20379| [7533] Microsoft Windows 2000 RunAs service denial of service
20380| [7532] Microsoft Windows 2000 RunAs service allows local attacker to bypass pipe authentication
20381| [7531] Microsoft Windows 2000 RunAs service reveals sensitive information
20382| [7528] Microsoft Windows NT and Windows 2000 malformed RPC request denial of service
20383| [7527] Microsoft SQL Server malformed RPC request denial of service
20384| [7526] Microsoft Exchange Server malformed RPC request denial of service
20385| [7446] Microsoft ISA Server fragmented UDP packet flood denial of service
20386| [7428] Microsoft Windows Me and XP UPnP denial of service
20387| [7421] Microsoft Windows NT GetThreadContext/SetThreadContext denial of service
20388| [7409] Microsoft Windows 2000 and Windows XP GDI denial of service
20389| [7405] Microsoft Windows NT NonPagedPool denial of service
20390| [7403] Microsoft Windows NT Win32k.sys denial of service
20391| [7402] Microsoft Windows NT kernel mode handle-closing denial of service
20392| [7369] Microsoft Windows CSRSS.EXE denial of service
20393| [7329] Microsoft Windows NT WINS malformed packet flood denial of service
20394| [7318] Microsoft Windows ME SSDP service denial of service
20395| [7224] Microsoft Windows NT smbmount request from Linux client denial of service
20396| [7168] Microsoft Exchange OWA deeply-nested folder request denial of service
20397| [7107] Microsoft Windows NT Xenroll denial of service
20398| [7105] Microsoft Windows RPC endpoint mapper malformed request denial of service
20399| [7039] Microsoft Exchange OWA denial of service
20400| [7008] Microsoft Windows 2000 IrDA device denial of service
20401| [6990] Microsoft ISA Server Proxy Service memory leak denial of service
20402| [6989] Microsoft ISA Server H.323 Gatekeeper Service memory leak denial of service
20403| [6983] Microsoft IIS invalid MIME header denial of service
20404| [6982] Microsoft IIS WebDAV long invalid request denial of service
20405| [6981] Microsoft IIS URL redirection denial of service
20406| [6977] Microsoft Windows NT and 2000 NNTP memory leak denial of service
20407| [6943] Microsoft Windows NT NT4ALL denial of service
20408| [6931] Microsoft Windows 2000 without Service Pack 2
20409| [6924] Microsoft Windows 98 ARP packet flooding denial of service
20410| [6914] Multiple Microsoft products malformed RPC request denial of service
20411| [6883] Microsoft SFU Telnet denial of service
20412| [6882] Microsoft SFU NFS denial of service
20413| [6858] Microsoft IIS cross-site scripting patch denial of service
20414| [6803] Microsoft Windows 2000 SMTP service allows mail relaying
20415| [6669] Microsoft Windows 2000 Telnet system call denial of service
20416| [6668] Microsoft Windows 2000 Telnet handle leak denial of service
20417| [6667] Microsoft Windows 2000 Telnet multiple idle sessions denial of service
20418| [6666] Microsoft Windows 2000 Telnet username denial of service
20419| [6665] Microsoft Windows 2000 Telnet service weak domain authentication
20420| [6664] Microsoft Windows 2000 Telnet service predictable pipe names could allow elevation of privileges
20421| [6651] Microsoft ISA Server Web Proxy denial of service caused by embedded code in HTML email
20422| [6549] Microsoft IIS WebDAV lock method memory leak can cause a denial of service
20423| [6535] Microsoft IIS FTP wildcard processing function denial of service
20424| [6506] Microsoft Windows 2000 Server Kerberos denial of service
20425| [6383] Microsoft ISA Server Web Proxy denial of service
20426| [6205] Microsoft IIS WebDAV denial of service
20427| [6172] Microsoft Exchange malformed URL request denial of service
20428| [6171] Microsoft IIS and Exchange malformed URL request denial of service
20429| [6136] Microsoft Windows 2000 domain controller denial of service
20430| [6103] Microsoft Windows NT PPTP denial of service
20431| [6070] Microsoft Windows UDP socket denial of service
20432| [6035] Microsoft Windows 2000 Server RDP denial of service
20433| [6006] Microsoft Windows NT mutex denial of service
20434| [5938] Microsoft Internet Explorer mshtml.dll denial of service
20435| [5936] Microsoft Windows 2000 Server Directory Service Restore Mode allows user to login with blank password
20436| [5823] Microsoft IIS Web form submission denial of service
20437| [5800] Microsoft Windows 2000 Index Service ActiveX controls allow unauthorized access to file information
20438| [5785] Microsoft Media Services dropped connection denial of service
20439| [5746] Microsoft Windows NT MSTask.exe denial of service
20440| [5623] Microsoft Windows NT and 2000 Phone Book service buffer overflow
20441| [5598] Microsoft Windows 2000 Telnet daemon could allow a denial of service
20442| [5573] Microsoft Windows NT SynAttackProtect denial of service
20443| [5510] Microsoft Internet Information Service (IIS) ISAPI buffer overflow
20444| [5502] Microsoft Windows 2000 Indexing Services ixsso.query
20445| [5489] Microsoft Windows NT Terminal Server GINA RegAPI.DLL buffer overflow
20446| [5470] Microsoft Internet Information Service (IIS) invalid executable filename passing
20447| [5417] Microsoft Windows NT MSIEXEC service uses the msi.dll registery key that has weak permissions
20448| [5411] Microsoft Windows File Share service denial of service
20449| [5387] Microsoft Windows HyperTerminal Telnet buffer overflow
20450| [5370] Microsoft Windows 9x NetBIOS invalid driver type denial of service
20451| [5357] Microsoft Windows 9x malformed NWLink NMPI packet denial of service
20452| [5222] Microsoft Windows 2000 malformed RPC packet denial of service
20453| [5203] Microsoft Windows 2000 still image service
20454| [5202] Microsoft IIS invalid URL allows attackers to crash service
20455| [5193] Microsoft Windows Media Services Unicast Service denial of service
20456| [5124] Microsoft FrontPage Server Extensions device name denial of service
20457| [5079] Microsoft Windows 95/98 malformed IPX ping packet denial of service
20458| [5033] Microsoft Windows 2000 without Service Pack 1
20459| [5031] Microsoft Windows 2000 Service Control Manager named pipe could allow a unauthorized user to gain privileges
20460| [4899] Microsoft FrontPage Extensions shtml.dll multiple access denial of service
20461| [4893] Microsoft mail clients denial of service
20462| [4823] Microsoft Windows 2000 Telnet server binary stream denial of service
20463| [4790] Microsoft IIS \mailroot\pickup directory denial of service
20464| [4698] Microsoft Windows EventLog service started
20465| [4648] Microsoft Windows NT malformed remote registry request denial of service
20466| [4600] Microsoft Windows NT denial of service caused by unacknowledged SMB requests
20467| [4585] Microsoft Windows Encoder denial of service
20468| [4552] Microsoft Windows Browser service can be shutdown by an unauthorized remote user
20469| [4430] Microsoft IIS malformed URL extension data denial of service
20470| [4279] Microsoft IIS escape characters denial of service
20471| [4203] Microsoft Windows TCP/IP Printing Service denial of service
20472| [4140] Microsoft Windows Telnet service authentication may expose user passwords
20473| [4117] Microsoft IIS chunked encoding post or put denial of service
20474| [4108] Microsoft Windows Media Technologies malformed license request denial of service
20475| [4107] Microsoft Windows path names containing DOS devices denial of service
20476| [4034] Microsoft Windows Media Services handshake packets denial of service
20477| [3993] Microsoft Windows Trin00 Distributed Denial of Service (DDoS) tool found
20478| [3959] Microsoft Direct Access Object (DAO) or JET method denial of service
20479| [3694] Microsoft Windows NT malformed resource enumeration denial of service
20480| [3534] Microsoft Windows NT 4.0 without Service Pack 6
20481| [3391] Microsoft FrontPage Extensions service.pwd file could reveal encrypted passwords
20482| [3328] Microsoft Windows ARP packet denial of service
20483| [3246] Microsoft HTML table form Denial of Service
20484| [3115] Microsoft IIS and SiteServer denial of service caused by malformed HTTP requests
20485| [3104] Microsoft Windows NT TSE denial of service can consume all available memory
20486| [2299] Microsoft Windows NT CSRSS denial of service
20487| [2229] Microsoft IIS ExAir sample site denial of service
20488| [2201] Microsoft Windows NT 4.0 without Service Pack 5
20489| [2095] Microsoft SQL Server OLE Automation extended stored procedures were found that can be used to reconfigure the security of other services
20490| [2093] The account under which the Microsoft SQL Server service is running is not in compliance with policy
20491| [1977] Microsoft Windows NT RPC services can be used to deplete system resources
20492| [1969] Microsoft Exchange LDAP denial of service
20493| [1823] Microsoft IIS long GET request denial of service
20494| [1769] Latest Microsoft SQL Server Service Packs are not installed
20495| [1394] Microsoft Windows NT 4.0 without Service Pack 4
20496| [1376] Microsoft Proxy 2.0 denial of service
20497| [1296] Microsoft Windows service user
20498| [1295] Microsoft Windows NT service user password found
20499| [1223] Microsoft Exchange Server SMTP and NNTP denial of service
20500| [530] Microsoft Windows NT RAS service packet filtering rules can be bypassed
20501| [342] Microsoft Windows NT SMB logon denial of service
20502| [186] Microsoft Windows NT DNS denial of service
20503| [140] Microsoft Windows telnet service installed
20504| [120] Microsoft Windows schedule service running
20505| [114] Microsoft Windows NT rsh service Running
20506| [102] Microsoft Windows NT rexec service running
20507| [98] Microsoft Windows NT rcmd service running
20508| [92] Microsoft Windows NT rlogin service installed
20509| [17] Microsoft Windows NT RPC locator denial of service
20510| [16] Microsoft Windows Remote Access Service
20511| [14] Microsoft Windows NT 4.0 without Service Pack 3
20512|
20513| Exploit-DB - https://www.exploit-db.com:
20514| [21123] Microsoft Windows 2000/NT Terminal Server Service RDP DoS Vulnerability
20515| [18606] Microsoft Terminal Services Use After Free (MS12-020)
20516| [30756] Microsoft Forms 2.0 ActiveX Control 2.0 Memory Access Violation Denial of Service Vulnerabilities
20517| [30749] Microsoft Office 2003 Web Component Memory Access Violation Denial of Service Vulnerability
20518| [30619] Microsoft Windows Explorer PNG Image - Local Denial Of Service Vulnerability
20519| [30493] Microsoft XML Core Services <= 6.0 SubstringData Integer Overflow Vulnerability
20520| [30462] Microsoft Windows Media Player 11 - AU Divide-By-Zero Denial of Service Vulnerability
20521| [30455] Microsoft Internet Explorer 6.0 Position:Relative Denial of Service Vulnerability
20522| [30160] Microsoft Windows XP - GDI+ ICO File Remote Denial of Service Vulnerability
20523| [29813] Microsoft Windows Vista ARP Table Entries Denial of Service Vulnerability
20524| [29800] Microsoft Internet Explorer 7.0 HTML Denial of Service Vulnerability
20525| [29738] Microsoft Windows XP/2000 WinMM.DLL - WAV Files Remote Denial of Service (DoS) Vulnerability
20526| [29664] Microsoft Office Publisher 2007 - Remote Denial of Service (DoS) Vulnerability
20527| [29660] Microsoft Office 2003 - Denial of Service (DoS) Vulnerability
20528| [29659] Microsoft Windows XP/2003 Explorer WMF File Handling Denial of Service Vulnerability
20529| [29536] Microsoft Internet Explorer 5.0.1 - Multiple ActiveX Controls Denial of Service Vulnerabilities
20530| [29295] Microsoft Outlook ActiveX Control Remote Internet Explorer Denial of Service Vulnerability
20531| [29236] Microsoft Internet Explorer 7.0 CSS Width Element Denial of Service Vulnerability
20532| [29229] Microsoft Internet Explorer 6.0 Frame Src Denial of Service Vulnerability
20533| [29172] Microsoft Office 97 HTMLMARQ.OCX Library Denial of Service Vulnerability
20534| [28897] Microsoft Internet Explorer 7.0 MHTML Denial of Service Vulnerability
20535| [28880] Microsoft Internet Explorer 6.0/7.0 RemoveChild Denial of Service Vulnerability
20536| [28500] Microsoft Indexing Service Query Validation Cross-Site Scripting Vulnerability
20537| [28421] Microsoft Internet Explorer 6.0 - Multiple COM Object Color Property Denial of Service Vulnerabilities
20538| [28401] Microsoft Internet Explorer 6.0 Visual Studio COM Object Instantiation Denial of Service Vulnerability
20539| [28389] Microsoft Internet Explorer 6.0 MSOE.DLL Denial of Service Vulnerability
20540| [28387] Microsoft Internet Explorer 6.0 IMSKDIC.DLL Denial of Service Vulnerability
20541| [28343] Microsoft Internet Explorer 6.0/7.0 IFrame Refresh Denial of Service Vulnerability
20542| [28301] Microsoft Internet Explorer 6.0 Deleted Frame Object Denial of Service Vulnerability
20543| [28299] Microsoft Windows XP/2000/2003 Graphical Device Interface Plus Library Denial of Service Vulnerability
20544| [28265] Microsoft Internet Explorer 6.0 Native Function Iterator Denial of Service Vulnerability
20545| [28263] Microsoft Windows XP/2000/2003 Remote Denial of Service Vulnerability
20546| [28258] Microsoft Internet Explorer 6.0 - Multiple Object ListWidth Property Denial of Service Vulnerability
20547| [28256] Microsoft Internet Explorer 6.0 Internet.HHCtrl Click Denial of Service Vulnerability
20548| [28252] Microsoft Internet Explorer 6.0 String To Binary Function Denial of Service Vulnerability
20549| [28246] Microsoft Internet Explorer 6.0 OVCtl Denial of Service Vulnerability
20550| [28244] Microsoft Internet Explorer 6.0 DataSourceControl Denial of Service Vulnerability
20551| [28227] Microsoft Windows 2000/XP Registry Access Local Denial of Service Vulnerability
20552| [28213] Microsoft Internet Explorer 6.0 RevealTrans Denial of Service Vulnerability
20553| [28207] Microsoft Internet Explorer 6.0 TriEditDocument Denial of Service Vulnerability
20554| [28202] Microsoft Internet Explorer 6.0 HtmlDlgSafeHelper Remote Denial of Service Vulnerability
20555| [28197] Microsoft Internet Explorer 6.0 Object.Microsoft.DXTFilter Denial of Service Vulnerability
20556| [28196] Microsoft Internet Explorer 6.0 DirectAnimation.DAUserData Denial of Service Vulnerability
20557| [28194] Microsoft Internet Explorer 6 RDS.DataControl Denial of Service Vulnerability
20558| [28169] Microsoft Internet Explorer 5.0.1/6.0 Structured Graphics Control Denial of Service Vulnerability
20559| [28164] Microsoft Internet Explorer 6.0 Href Title Denial of Service Vulnerability
20560| [28145] Microsoft Internet Explorer 6.0 ADODB.Recordset Filter Property Denial of Service Vulnerability
20561| [28144] Microsoft Internet Explorer 6.0 OutlookExpress.AddressBook Denial of Service Vulnerability
20562| [28001] Microsoft SMB Driver Local Denial of Service Vulnerability
20563| [27906] Microsoft Internet Explorer 6.0 Malformed HTML Parsing Denial of Service Vulnerability
20564| [27082] Microsoft Internet Explorer 5.0.1 Malformed IMG and XML Parsing Denial of Service Vulnerability
20565| [26985] Microsoft Internet Explorer 5.0.1 HTML Parsing Denial of Service Vulnerabilities
20566| [26690] Microsoft Windows 2000/2003/XP CreateRemoteThread Local Denial of Service Vulnerability
20567| [26457] Microsoft Internet Explorer 6.0 Malformed HTML Parsing Denial of Service Vulnerability
20568| [26341] Microsoft Windows 2000/2003/XP MSDTC TIP Denial of Service Vulnerability
20569| [26323] Microsoft Windows XP Wireless Zero Configuration Service Information Disclosure Vulnerability
20570| [26292] Microsoft Internet Explorer 5.2.3 for Mac OS Denial of Service Vulnerability
20571| [25992] Microsoft Internet Explorer 5.0.1 JPEG Image Rendering CMP Fencepost Denial of Service Vulnerability
20572| [25962] Microsoft ASP.NET 1.0/1.1 RPC/Encoded Remote Denial of Service Vulnerability
20573| [25737] Microsoft Windows 98SE User32.DLL Icon Handling Denial of Service Vulnerability
20574| [25268] Microsoft Windows XP TSShutdn.exe Remote Denial of Service Vulnerability
20575| [25259] Microsoft Windows XP Local Denial of Service Vulnerability
20576| [25231] Microsoft Windows 2000/2003/XP Graphical Device Interface Library Denial of Service Vulnerability
20577| [24775] Microsoft Internet Explorer 6.0 Infinite Array Sort Denial of Service Vulnerability
20578| [24705] Microsoft Internet Explorer 6.0 Font Tag Denial of Service Vulnerability
20579| [24699] Microsoft Windows XP WAV File Handler Denial of Service Vulnerability
20580| [24640] Microsoft SQL Server 7.0 - Remote Denial of Service Vulnerability (2)
20581| [24639] Microsoft SQL Server 7.0 - Remote Denial of Service Vulnerability (1)
20582| [24605] Microsoft Windows XP Explorer.EXE TIFF Image Denial of Service Vulnerability
20583| [24281] Microsoft Systems Management Server 1.2/2.0 - Remote Denial of Service Vulnerability
20584| [24267] Microsoft Internet Explorer 6.0 JavaScript Null Pointer Exception Denial of Service Vulnerability
20585| [24211] Microsoft Internet Explorer 6.0 HREF Save As Denial of Service Vulnerability
20586| [24119] Microsoft Internet Explorer 5.0.1 http-equiv Meta Tag Denial of Service Vulnerability
20587| [24112] Microsoft Internet Explorer 6.0 XML Parsing Denial of Service Vulnerability
20588| [24002] Microsoft Outlook Express 6.0 - Remote Denial of Service Vulnerability
20589| [23912] Microsoft Internet Explorer 6.0 Macromedia Flash Player Plug-in Remote Denial of Service Vulnerability
20590| [23911] Microsoft Internet Explorer 6.0 MSWebDVD Object Denial of Service Vulnerability
20591| [23850] Microsoft Windows XP Explorer.EXE Remote Denial of Service Vulnerability
20592| [23273] Microsoft Internet Explorer 6.0 Scrollbar-Base-Color Partial Denial of Service Vulnerability
20593| [23247] Microsoft Windows XP/2000 Messenger Service Buffer Overrun Vulnerability
20594| [23229] Microsoft Windows XP/2000/2003 Message Queuing Service Heap Overflow Vulnerability
20595| [23216] Microsoft Word 97/98/2002 Malformed Document Denial of Service Vulnerability
20596| [23215] Microsoft Internet Explorer 6 Absolute Position Block Denial of Service Vulnerability
20597| [23101] Microsoft Windows 98 Fragmented UDP Flood Denial of Service Vulnerability
20598| [22957] Microsoft SQL Server 7.0/2000,MSDE Named Pipe Denial of Service Vulnerability
20599| [22837] Microsoft Windows 2000/NT 4 Media Services NSIISlog.DLL Remote Buffer Overflow
20600| [22670] Microsoft IIS 5 WebDAV PROPFIND and SEARCH Method Denial of Service Vulnerability
20601| [22390] Microsoft ActiveSync 3.5 Null Pointer Dereference Denial of Service Vulnerability
20602| [22194] Microsoft Windows XP/2000/NT 4 Locator Service Buffer Overflow Vulnerability
20603| [22132] Microsoft Windows XP/2000 Fontview Denial of Service Vulnerability
20604| [22119] Microsoft Pocket Internet Explorer 3.0 - Denial of Service Vulnerability
20605| [21954] Microsoft Windows XP/2000/NT 4 RPC Service Denial of Service Vulnerability (4)
20606| [21953] Microsoft Windows XP/2000/NT 4 RPC Service Denial of Service Vulnerability (3)
20607| [21952] Microsoft Windows XP/2000/NT 4 RPC Service Denial of Service Vulnerability (2)
20608| [21951] Microsoft Windows XP/2000/NT 4 RPC Service Denial of Service Vulnerability (1)
20609| [21652] Microsoft SQL Server 2000 Resolution Service Heap Overflow Vulnerability
20610| [21613] Microsoft IIS 4/5 SMTP Service Encapsulated SMTP Address Vulnerability
20611| [21556] Microsoft Internet Explorer 5/6 CSSText Bold Font Denial of Service
20612| [21481] Microsoft MSN Messenger 1-4 Malformed Invite Request Denial of Service
20613| [21419] Microsoft Outlook Express 5.5 DoS Device Denial of Service Vulnerability
20614| [21404] Microsoft Internet Explorer 5/6 Self-Referential Object Denial of Service Vulnerability
20615| [21389] Microsoft Windows 2000 Lanman Denial of Service Vulnerability (2)
20616| [21388] Microsoft Windows 2000 Lanman Denial of Service Vulnerability (1)
20617| [21240] Microsoft Windows XP .Manifest Denial of Service Vulnerability
20618| [21131] Microsoft Windows 2000/XP GDI Denial of Service Vulnerability
20619| [21099] Microsoft Windows 2000 RunAs Service Denial of Services Vulnerability
20620| [21069] Microsoft Windows 2000 RunAs Service Named Pipe Hijacking Vulnerability
20621| [20846] Microsoft IIS 4.0/5.0 FTP Denial of Service Vulnerability
20622| [20802] Microsoft IIS 2.0/3.0 Long URL Denial of Service Vulnerability
20623| [20664] Microsoft IIS 5.0 WebDAV Denial of Service Vulnerability
20624| [20508] Microsoft NT 4.0 RAS/PPTP Malformed Control Packet Denial of Service Attack
20625| [20399] Microsoft Indexing Services for Windows 2000 File Verification Vulnerability
20626| [20335] Microsoft Indexing Services for Windows 2000/NT 4.0 .htw Cross-Site Scripting Vulnerability
20627| [20209] Microsoft Windows 2000 Still Image Service Privilege Escalation Vulnerability
20628| [19974] Microsoft Windows Media Services 4.0/4.1 DoS Vulnerability
20629| [19759] Microsoft Windows Media Services 4.0/4.1 Handshake Sequence DoS
20630| [19731] microsoft index server 2.0/indexing services for windows 2000 - Directory Traversal
20631| [19578] Microsoft Windows NT 4.0/SP1/SP2/SP3/SP4/SP5/SP6 Services.exe Denial of Service (2)
20632| [19577] Microsoft Windows NT 4.0/SP1/SP2/SP3/SP4/SP5/SP6 Services.exe Denial of Service (1)
20633| [19516] Microsoft MSN Messenger Service 1.0 Setup BBS ActiveX Control Buffer Overflow
20634| [19207] Microsoft Outlook Express 4.27.3110/4.72.3120 POP Denial of Service Vulnerability
20635| [19197] "Microsoft Windows NT <= 4.0 SP5,Terminal Server 4.0 ""Pass the Hash"" with Modified SMB Client Vulnerability"
20636| [19186] Microsoft XML Core Services MSXML Uninitialized Memory Corruption
20637| [17830] Microsoft WINS Service <= 5.2.3790.4520 Memory Corruption
20638| [16750] Microsoft Message Queueing Service DNS Name Path Overflow
20639| [16748] Microsoft DNS RPC Service extractQuotedChar() Overflow (TCP)
20640| [16747] Microsoft Message Queueing Service Path Overflow
20641| [16378] Microsoft Workstation Service NetAddAlternateComputerName Overflow
20642| [16375] Microsoft RRAS Service RASMAN Registry Overflow
20643| [16373] Microsoft Services MS06-066 nwapi32.dll
20644| [16372] Microsoft Workstation Service NetpManageIPCConnect Overflow
20645| [16371] Microsoft NetDDE Service Overflow
20646| [16369] Microsoft Services MS06-066 nwwks.dll
20647| [16368] Microsoft LSASS Service DsRolerUpgradeDownlevelServer Overflow
20648| [16367] Microsoft Server Service NetpwPathCanonicalize Overflow
20649| [16366] Microsoft DNS RPC Service extractQuotedChar() Overflow (SMB)
20650| [16365] Microsoft Plug and Play Service Overflow
20651| [16364] Microsoft RRAS Service Overflow
20652| [16362] Microsoft Server Service Relative Path Stack Corruption
20653| [16361] Microsoft Print Spooler Service Impersonation Vulnerability
20654| [16359] Microsoft WINS Service Memory Overwrite
20655| [16357] Microsoft IIS Phone Book Service Overflow
20656| [16095] Terminal Server Client .rdp Denial of Service
20657| [15839] Microsoft Windows Fax Services Cover Page Editor (.cov) Memory Corruption
20658| [15167] Microsoft IIS 6.0 ASP Stack Overflow (Stack Exhaustion) Denial of Service (MS10-065)
20659| [14705] Microsoft Windows (IcmpSendEcho2Ex interrupting) Denial of Service Vulnerability
20660| [14179] Microsoft Internet Information Services (IIS) 5 Authentication Bypass Vulnerability (MS10-065)
20661| [12079] Microsoft Office (2010 beta) Communicator SIP Denial of Service Exploit
20662| [9587] Microsoft IIS 5.0/6.0 FTP Server (Stack Exhaustion) Denial of Service
20663| [8466] Microsoft GDI Plugin .png Infinite Loop Denial of Service PoC
20664| [8465] Microsoft Media Player - (quartz.dll .mid) Denial of Service Exploit
20665| [7262] Microsoft Office Communicator (SIP) Remote Denial of Service Exploit
20666| [7196] Microsoft XML Core Services DTD Cross-Domain Scripting PoC MS08-069
20667| [5460] Microsoft Works 7 WkImgSrv.dll ActiveX Denial of Service PoC
20668| [3965] Microsoft IIS 6.0 (/AUX/.aspx) Remote Denial of Service Exploit
20669| [1488] Microsoft HTML Help Workshop (.hhp file) Denial of Service
20670|
20671| OpenVAS (Nessus) - http://www.openvas.org:
20672| [902914] Microsoft IIS GET Request Denial of Service Vulnerability
20673| [902909] Microsoft Windows Service Pack Missing Multiple Vulnerabilities
20674| [902908] Microsoft Windows DirectWrite Denial of Service Vulnerability (2665364)
20675| [902906] Microsoft Windows DNS Server Denial of Service Vulnerability (2647170)
20676| [902782] MicroSoft Windows Server Service Remote Code Execution Vulnerability (921883)
20677| [902708] Microsoft Remote Desktop Protocol Denial of Service Vulnerability (2570222)
20678| [902694] Microsoft Windows IIS FTP Service Information Disclosure Vulnerability (2761226)
20679| [902580] Microsoft Host Integration Server Denial of Service Vulnerabilities (2607670)
20680| [902290] Microsoft Windows Active Directory SPN Denial of Service (2478953)
20681| [902277] Microsoft Windows Netlogon Service Denial of Service Vulnerability (2207559)
20682| [902227] Microsoft Windows LSASS Denial of Service Vulnerability (975467)
20683| [902183] Microsoft Internet Explorer 'IFRAME' Denial Of Service Vulnerability
20684| [902151] Microsoft Internet Explorer Denial of Service Vulnerability - Mar10
20685| [902115] Microsoft Kerberos Denial of Service Vulnerability (977290)
20686| [902033] Microsoft Windows '.ani' file Denial of Service vulnerability
20687| [901301] Microsoft Windows Kerberos Denial of Service Vulnerability (2743555)
20688| [901164] Microsoft Windows SChannel Denial of Service Vulnerability (2207566)
20689| [901151] Microsoft Internet Information Services Remote Code Execution Vulnerabilities (2267960)
20690| [901150] Microsoft Windows Print Spooler Service Remote Code Execution Vulnerability(2347290)
20691| [901102] Microsoft Windows Media Services Remote Code Execution Vulnerability (980858)
20692| [901063] Microsoft Windows LSASS Denial of Service Vulnerability (975467)
20693| [901048] Microsoft Windows Active Directory Denial of Service Vulnerability (973309)
20694| [900891] Microsoft Internet Denial Of Service Vulnerability - Nov09
20695| [900881] Microsoft Windows Indexing Service ActiveX Vulnerability (969059)
20696| [900877] Microsoft Windows LSASS Denial of Service Vulnerability (975467)
20697| [900874] Microsoft IIS FTP Service Remote Code Execution Vulnerabilities (975254)
20698| [900461] Microsoft MSN Live Messneger Denial of Service Vulnerability
20699| [900337] Microsoft Internet Explorer Denial of Service Vulnerability - Apr09
20700| [900314] Microsoft XML Core Service Information Disclosure Vulnerability
20701| [900297] Microsoft Windows Kernel Denial of Service Vulnerability (2556532)
20702| [900296] Microsoft Windows TCP/IP Stack Denial of Service Vulnerability (2563894)
20703| [900240] Microsoft Exchange and Windows SMTP Service Denial of Service Vulnerability (981832)
20704| [900131] Microsoft Internet Explorer Denial of Service Vulnerability
20705| [900058] Microsoft XML Core Services Remote Code Execution Vulnerability (955218)
20706| [802888] Microsoft Windows Media Service Handshake Sequence DoS Vulnerability
20707| [802864] Microsoft XML Core Services Remote Code Execution Vulnerability (2719615)
20708| [802462] Microsoft ActiveSync Null Pointer Dereference Denial Of Service Vulnerability
20709| [801721] Microsoft Active Directory Denial of Service Vulnerability (953235)
20710| [801715] Microsoft XML Core Services Remote Code Execution Vulnerability (936227)
20711| [801705] Microsoft Windows TCP/IP Denial of Service Vulnerability (946456)
20712| [801704] Microsoft Internet Information Services Privilege Elevation Vulnerability (942831)
20713| [801701] Microsoft Windows DNS Client Service Response Spoofing Vulnerability (945553)
20714| [801485] Microsoft Pragmatic General Multicast (PGM) Denial of Service Vulnerability (950762)
20715| [801482] Microsoft Windows ASP.NET Denial of Service Vulnerability(970957)
20716| [801481] Microsoft Wireless LAN AutoConfig Service Remote Code Execution Vulnerability (970710)
20717| [801480] Microsoft Web Services on Devices API Remote Code Execution Vulnerability (973565)
20718| [801349] Microsoft Internet Explorer 'IFRAME' Denial Of Service Vulnerability (June-10)
20719| [801348] Microsoft Internet Explorer 'IFRAME' Denial Of Service Vulnerability -june 10
20720| [800968] Microsoft SharePoint Team Services Information Disclosure Vulnerability
20721| [800669] Microsoft Internet Explorer Denial Of Service Vulnerability - July09
20722| [800504] Microsoft Windows XP SP3 denial of service vulnerability
20723| [800310] Microsoft Windows Media Services nskey.dll ActiveX BOF Vulnerability
20724| [800218] Microsoft Money 'prtstb06.dll' Denial of Service vulnerability
20725| [100607] Microsoft SMTP Service and Exchange Routing Engine Buffer Overflow Vulnerability
20726| [100596] Microsoft Windows SMTP Server MX Record Denial of Service Vulnerability
20727| [13752] Denial of Service (DoS) in Microsoft SMS Client
20728| [11433] Microsoft ISA Server DNS - Denial Of Service (MS03-009)
20729| [903041] Microsoft Windows Kernel Privilege Elevation Vulnerability (2724197)
20730| [903037] Microsoft JScript and VBScript Engines Remote Code Execution Vulnerability (2706045)
20731| [903036] Microsoft Windows Networking Components Remote Code Execution Vulnerabilities (2733594)
20732| [903035] Microsoft Windows Kernel-Mode Drivers Privilege Elevation Vulnerability (2731847)
20733| [903033] Microsoft Windows Kernel-Mode Drivers Privilege Elevation Vulnerabilities (2718523)
20734| [903028] Zebedee Allowed Redirection Port Denial of Service Vulnerability
20735| [903026] Microsoft Office Remote Code Execution Vulnerabilities (2663830)
20736| [903024] Wireshark Denial of Service Vulnerability (Mac OS X)
20737| [903022] Wireshark X.509if Dissector Denial of Service Vulnerability (Mac OS X)
20738| [903017] Microsoft Office Remote Code Execution Vulnerability (2639185)
20739| [903000] Microsoft Expression Design Remote Code Execution Vulnerability (2651018)
20740| [902936] Microsoft Windows Kernel-Mode Drivers Remote Code Execution Vulnerabilities (2783534)
20741| [902934] Microsoft .NET Framework Remote Code Execution Vulnerability (2745030)
20742| [902933] Microsoft Windows Shell Remote Code Execution Vulnerabilities (2727528)
20743| [902932] Microsoft Internet Explorer Multiple Use-After-Free Vulnerabilities (2761451)
20744| [902931] Microsoft Office Remote Code Execution Vulnerabilities - 2720184 (Mac OS X)
20745| [902930] Microsoft Office Remote Code Execution Vulnerabilities (2720184)
20746| [902929] hMailServer IMAP Remote Denial of Service Vulnerability
20747| [902923] Microsoft Internet Explorer Multiple Vulnerabilities (2722913)
20748| [902922] Microsoft Remote Desktop Protocol Remote Code Execution Vulnerability (2723135)
20749| [902921] Microsoft Office Visio/Viewer Remote Code Execution Vulnerability (2733918)
20750| [902920] Microsoft Office Remote Code Execution Vulnerability (2731879)
20751| [902919] Microsoft SharePoint Privilege Elevation Vulnerabilities (2663841)
20752| [902918] WinRadius Server Access Request Packet Parsing Denial of Service Vulnerability
20753| [902916] Microsoft Windows Kernel Privilege Elevation Vulnerabilities (2711167)
20754| [902913] Microsoft Office Remote Code Execution Vulnerabilities-2663830 (Mac OS X)
20755| [902912] Microsoft Office Word Remote Code Execution Vulnerability-2680352 (Mac OS X)
20756| [902911] Microsoft Office Word Remote Code Execution Vulnerability (2680352)
20757| [902910] Microsoft Office Visio Viewer Remote Code Execution Vulnerability (2597981)
20758| [902900] Microsoft Windows SSL/TLS Information Disclosure Vulnerability (2643584)
20759| [902846] Microsoft Windows TLS Protocol Information Disclosure Vulnerability (2655992)
20760| [902845] Microsoft Windows Shell Remote Code Execution Vulnerability (2691442)
20761| [902842] Microsoft Lync Remote Code Execution Vulnerabilities (2707956)
20762| [902841] Microsoft .NET Framework Remote Code Execution Vulnerability (2706726)
20763| [902839] Microsoft FrontPage Server Extensions MS-DOS Device Name DoS Vulnerability
20764| [902833] Microsoft .NET Framework Remote Code Execution Vulnerability (2693777)
20765| [902832] MS Security Update For Microsoft Office, .NET Framework, and Silverlight (2681578)
20766| [902829] Microsoft Windows Common Controls Remote Code Execution Vulnerability (2664258)
20767| [902828] Microsoft .NET Framework Remote Code Execution Vulnerability (2671605)
20768| [902826] KnFTP Server 'FEAT' Command Remote Denial of Service Vulnerability
20769| [902825] at32 Reverse Proxy Multiple HTTP Header Fields Denial Of Service Vulnerability
20770| [902824] Epson EventManager 'x-protocol-version' Denial of Service Vulnerability
20771| [902822] PHP Built-in WebServer 'Content-Length' Denial of Service Vulnerability
20772| [902820] Tiny Server HTTP HEAD Request Remote Denial of Service Vulnerability
20773| [902819] Telnet-FTP Server 'RETR' Command Remote Denial of Service Vulnerability
20774| [902818] Microsoft Remote Desktop Protocol Remote Code Execution Vulnerabilities (2671387)
20775| [902817] Microsoft Visual Studio Privilege Elevation Vulnerability (2651019)
20776| [902815] TCP Sequence Number Approximation Reset Denial of Service Vulnerability
20777| [902811] Microsoft .NET Framework and Microsoft Silverlight Remote Code Execution Vulnerabilities (2651026)
20778| [902807] Microsoft Windows Media Could Allow Remote Code Execution Vulnerabilities (2636391)
20779| [902803] FreeSSHd Remote Denial of Service Vulnerability
20780| [902798] Microsoft SMB Signing Enabled and Not Required At Server
20781| [902797] Microsoft SMB Signing Information Disclosure Vulnerability
20782| [902796] Microsoft IIS IP Address/Internal Network Name Disclosure Vulnerability
20783| [902785] Microsoft AntiXSS Library Information Disclosure Vulnerability (2607664)
20784| [902784] Microsoft Windows Object Packager Remote Code Execution Vulnerability (2603381)
20785| [902783] Microsoft Windows Kernel Security Feature Bypass Vulnerability (2644615)
20786| [902781] Windows Media Player Denial Of Service Vulnerability
20787| [902780] Putty Denial of Service Vulnerability
20788| [902776] Mozilla Products DOM Frame Denial of Service Vulnerability (MAC OS X)
20789| [902766] Microsoft Windows Kernel Privilege Elevation Vulnerability (2633171)
20790| [902760] ClamAV Recursion Level Handling Denial of Service Vulnerability (Windows)
20791| [902757] Zoho ManageEngine ADSelfService Plus Cross Site Scripting Vulnerability
20792| [902746] Microsoft Active Accessibility Remote Code Execution Vulnerability (2623699)
20793| [902727] Microsoft Office Excel Remote Code Execution Vulnerabilities (2587505)
20794| [902726] ClamAV Hash Manager Off-By-One Denial of Service Vulnerability (Win)
20795| [902722] Wireshark IKE Packet Denial of Service Vulnerability (Win)
20796| [902721] Wireshark ANSI A MAP Files Denial of Service Vulnerability (Win)
20797| [902696] Microsoft Internet Explorer Multiple Vulnerabilities (2761465)
20798| [902693] Microsoft Windows Kernel-Mode Drivers Remote Code Execution Vulnerabilities (2761226)
20799| [902692] Microsoft Office Excel ReadAV Arbitrary Code Execution Vulnerability
20800| [902689] Microsoft SQL Server Report Manager Cross Site Scripting Vulnerability (2754849)
20801| [902688] Microsoft System Center Configuration Manager XSS Vulnerability (2741528)
20802| [902687] Microsoft Windows Data Access Components Remote Code Execution Vulnerability (2698365)
20803| [902686] Microsoft Internet Explorer Multiple Vulnerabilities (2719177)
20804| [902684] Wireshark Multiple Denial of Service Vulnerabilities June-11 (Mac OS X)
20805| [902683] Microsoft Remote Desktop Protocol Remote Code Execution Vulnerability (2685939)
20806| [902682] Microsoft Internet Explorer Multiple Vulnerabilities (2699988)
20807| [902678] Microsoft Silverlight Code Execution Vulnerabilities - 2681578 (Mac OS X)
20808| [902677] Microsoft Windows Prtition Manager Privilege Elevation Vulnerability (2690533)
20809| [902676] Microsoft Windows TCP/IP Privilege Elevation Vulnerabilities (2688338)
20810| [902670] Microsoft Internet Explorer Multiple Vulnerabilities (2675157)
20811| [902664] Apache Traffic Server HTTP Host Header Denial of Service Vulnerability
20812| [902663] Microsoft Remote Desktop Protocol Remote Code Execution Vulnerabilities (2671387)
20813| [902662] MicroSoft SMB Server Trans2 Request Remote Code Execution Vulnerability
20814| [902660] Microsoft SMB Transaction Parsing Remote Code Execution Vulnerability
20815| [902658] Microsoft RDP Server Private Key Information Disclosure Vulnerability
20816| [902650] Pidgin XMPP And SILC Protocols Denial of Service Vulnerabilities (Win)
20817| [902649] Microsoft Internet Explorer Multiple Vulnerabilities (2647516)
20818| [902642] Microsoft Internet Explorer Multiple Vulnerabilities (2618444)
20819| [902626] Microsoft SharePoint SafeHTML Information Disclosure Vulnerabilities (2412048)
20820| [902625] Microsoft SharePoint Multiple Privilege Escalation Vulnerabilities (2451858)
20821| [902613] Microsoft Internet Explorer Multiple Vulnerabilities (2559049)
20822| [902609] Microsoft Windows CSRSS Privilege Escalation Vulnerabilities (2507938)
20823| [902598] Microsoft Windows Time Component Remote Code Execution Vulnerability (2618451)
20824| [902597] Microsoft Windows Media Remote Code Execution Vulnerability (2648048)
20825| [902596] Microsoft Windows OLE Remote Code Execution Vulnerability (2624667)
20826| [902588] Microsoft Windows Internet Protocol Validation Remote Code Execution Vulnerability
20827| [902581] Microsoft .NET Framework and Silverlight Remote Code Execution Vulnerability (2604930)
20828| [902570] Colasoft Capsa Malformed SNMP V1 Packet Remote Denial of Service Vulnerability
20829| [902569] MetaServer RT Multiple Remote Denial of Service Vulnerabilities
20830| [902567] Microsoft Office Remote Code Execution Vulnerabilites (2587634)
20831| [902566] Microsoft Windows WINS Local Privilege Escalation Vulnerability (2571621)
20832| [902558] Ruby Random Number Generation Local Denial Of Service Vulnerability
20833| [902555] Finger Service Unused Account Disclosure Vulnerability
20834| [902552] Microsoft .NET Framework Chart Control Information Disclosure Vulnerability (2567943)
20835| [902551] Microsoft .NET Framework Information Disclosure Vulnerability (2567951)
20836| [902527] ejabberd XML Parsing Denial of Service Vulnerability (Windows)
20837| [902523] Microsoft .NET Framework and Silverlight Remote Code Execution Vulnerability (2514842)
20838| [902522] Microsoft .NET Framework Remote Code Execution Vulnerability (2538814)
20839| [902518] Microsoft .NET Framework Security Bypass Vulnerability
20840| [902516] Microsoft Windows WINS Remote Code Execution Vulnerability (2524426)
20841| [902502] Microsoft .NET Framework Remote Code Execution Vulnerability (2484015)
20842| [902501] Microsoft JScript and VBScript Scripting Engines Remote Code Execution Vulnerability (2514666)
20843| [902496] Microsoft Office IME (Chinese) Privilege Elevation Vulnerability (2652016)
20844| [902495] Microsoft Office Remote Code Execution Vulnerability (2590602)
20845| [902494] Microsoft Office Excel Remote Code Execution Vulnerability (2640241)
20846| [902493] Microsoft Publisher Remote Code Execution Vulnerabilities (2607702)
20847| [902492] Microsoft Office PowerPoint Remote Code Execution Vulnerabilities (2639142)
20848| [902487] Microsoft Windows Active Directory LDAPS Authentication Bypass Vulnerability (2630837)
20849| [902484] Microsoft Windows TCP/IP Remote Code Execution Vulnerability (2588516)
20850| [902476] ASAS Server End User Self Service (EUSS) SQL Injection Vulnerability
20851| [902469] ManageEngine ServiceDesk Plus Multiple Stored XSS Vulnerabilities
20852| [902464] Microsoft Visio Remote Code Execution Vulnerabilities (2560978)
20853| [902463] Microsoft Windows Client/Server Run-time Subsystem Privilege Escalation Vulnerability (2567680)
20854| [902460] Ciscokits TFTP Server Long Filename Denial Of Service Vulnerability
20855| [902455] Microsoft Visio Remote Code Execution Vulnerability (2560847)
20856| [902453] Smallftpd FTP Server Multiple Requests Denial of Service Vulnerability
20857| [902445] Microsoft XML Editor Information Disclosure Vulnerability (2543893)
20858| [902443] Microsoft Internet Explorer Multiple Vulnerabilities (2530548)
20859| [902440] Microsoft Windows SMB Server Remote Code Execution Vulnerability (2536275)
20860| [902430] Microsoft Office PowerPoint Remote Code Execution Vulnerabilities (2545814)
20861| [902425] Microsoft Windows SMB Accessible Shares
20862| [902423] Microsoft Office Visio Viewer Remote Code Execution Vulnerabilities (2663510)
20863| [902411] Microsoft Office PowerPoint Remote Code Execution Vulnerabilities (2489283)
20864| [902410] Microsoft Office Excel Remote Code Execution Vulnerabilities (2489279)
20865| [902403] Microsoft Windows Fraudulent Digital Certificates Spoofing Vulnerability
20866| [902396] JustSystems Ichitaro Products Denial of Service Vulnerability
20867| [902395] Microsoft Bluetooth Stack Remote Code Execution Vulnerability (2566220)
20868| [902378] Microsoft Office Excel Remote Code Execution Vulnerabilities (2537146)
20869| [902377] Microsoft Windows OLE Automation Remote Code Execution Vulnerability (2476490)
20870| [902365] Microsoft GDI+ Remote Code Execution Vulnerability (2489979)
20871| [902364] Microsoft Office Remote Code Execution Vulnerabilites (2489293)
20872| [902358] Google Chrome 'SPDY' Denial Of Service Vulnerability
20873| [902357] Google Chrome 'SPDY' Denial Of Service Vulnerability
20874| [902351] Microsoft Groove Remote Code Execution Vulnerability (2494047)
20875| [902337] Microsoft Windows Kernel Elevation of Privilege Vulnerability (2393802)
20876| [902336] Microsoft JScript and VBScript Scripting Engines Information Disclosure Vulnerability (2475792)
20877| [902325] Microsoft Internet Explorer 'CSS Import Rule' Use-after-free Vulnerability
20878| [902324] Microsoft SharePoint Could Allow Remote Code Execution Vulnerability (2455005)
20879| [902319] Microsoft Foundation Classes Could Allow Remote Code Execution Vulnerability (2387149)
20880| [902297] Terminal Server Client RDP File Processing BOF Vulnerabilities
20881| [902291] Novell eDirectory NCP Request Remote Denial of Service Vulnerability
20882| [902289] Microsoft Windows LSASS Privilege Escalation Vulnerability (2478960)
20883| [902288] Microsoft Kerberos Privilege Escalation Vulnerabilities (2496930)
20884| [902287] Microsoft Visio Remote Code Execution Vulnerabilities (2451879)
20885| [902285] Microsoft Internet Explorer Information Disclosure Vulnerability (2501696)
20886| [902281] Microsoft Windows Data Access Components Remote Code Execution Vulnerabilities (2451910)
20887| [902280] Microsoft Windows BranchCache Remote Code Execution Vulnerability (2385678)
20888| [902276] Microsoft Windows Task Scheduler Elevation of Privilege Vulnerability (2305420)
20889| [902274] Microsoft Publisher Remote Code Execution Vulnerability (2292970)
20890| [902269] Microsoft Windows SMB Server NTLM Multiple Vulnerabilities (971468)
20891| [902265] Microsoft Office Word Remote Code Execution Vulnerabilities (2293194)
20892| [902264] Microsoft Office Excel Remote Code Execution Vulnerabilities (2293211)
20893| [902263] Microsoft Windows Media Player Network Sharing Remote Code Execution Vulnerability (2281679)
20894| [902262] Microsoft Windows Shell and WordPad COM Validation Vulnerability (2405882)
20895| [902256] Microsoft Windows win32k.sys Driver 'CreateDIBPalette()' BOF Vulnerability
20896| [902255] Microsoft Visual Studio Insecure Library Loading Vulnerability
20897| [902254] Microsoft Office Products Insecure Library Loading Vulnerability
20898| [902250] Microsoft Word 2003 'MSO.dll' Null Pointer Dereference Vulnerability
20899| [902246] Microsoft Internet Explorer 'toStaticHTML()' Cross Site Scripting Vulnerability
20900| [902244] MS Local Security Authority Subsystem Service Privilege Elevation Vulnerability (983539)
20901| [902243] Microsoft Outlook TNEF Remote Code Execution Vulnerability (2315011)
20902| [902232] Microsoft Windows TCP/IP Privilege Elevation Vulnerabilities (978886)
20903| [902231] Microsoft Windows Tracing Feature Privilege Elevation Vulnerabilities (982799)
20904| [902230] Microsoft .NET Common Language Runtime Remote Code Execution Vulnerability (2265906)
20905| [902229] Microsoft Window MPEG Layer-3 Remote Code Execution Vulnerability (2115168)
20906| [902228] Microsoft Office Word Remote Code Execution Vulnerabilities (2269638)
20907| [902226] Microsoft Windows Shell Remote Code Execution Vulnerability (2286198)
20908| [902217] Microsoft Outlook SMB Attachment Remote Code Execution Vulnerability (978212)
20909| [902210] Microsoft IE cross-domain IFRAME gadgets keystrokes steal Vulnerability
20910| [902197] Wireshark SMB PIPE Dissector Denial of Service Vulnerability (Windows)
20911| [902196] Wireshark SMB dissector Denial of Service Vulnerability (Windows)
20912| [902193] Microsoft .NET Framework XML HMAC Truncation Vulnerability (981343)
20913| [902192] Microsoft Office COM Validation Remote Code Execution Vulnerability (983235)
20914| [902191] Microsoft Internet Explorer Multiple Vulnerabilities (982381)
20915| [902189] ClamAV 'cli_pdf()' and 'cli_scanicon()' Denial of Service Vulnerabilities (Win
20916| [902186] Mozilla Firefox Multiple Denial Of Service vulnerabilities (Windows)
20917| [902185] Mozilla Products 'IFRAME' Denial Of Service vulnerability (Windows)
20918| [902184] Google Chrome 'IFRAME' Denial Of Service Vulnerability
20919| [902182] Opera Browser Multiple Denial Of Service Vulnerability (Windows)
20920| [902178] Microsoft Visual Basic Remote Code Execution Vulnerability (978213)
20921| [902176] Microsoft SharePoint '_layouts/help.aspx' Cross Site Scripting Vulnerability
20922| [902173] VMware Authorization Service Denial of Service Vulnerability (Win) -Apr10
20923| [902166] Microsoft Internet Explorer 'neutering' Mechanism XSS Vulnerability
20924| [902159] Microsoft VBScript Scripting Engine Remote Code Execution Vulnerability (980232)
20925| [902158] Microsoft Office Publisher Remote Code Execution Vulnerability (981160)
20926| [902157] Microsoft 'ISATAP' Component Spoofing Vulnerability (978338)
20927| [902156] Microsoft SMB Client Remote Code Execution Vulnerabilities (980232)
20928| [902155] Microsoft Internet Explorer Multiple Vulnerabilities (980182)
20929| [902143] Mozilla Products Denial Of Service Vulnerability (Linux)
20930| [902142] Mozilla Products Denial Of Service Vulnerability (Win)
20931| [902133] Microsoft Office Excel Multiple Vulnerabilities (980150)
20932| [902117] Microsoft DirectShow Remote Code Execution Vulnerability (977935)
20933| [902116] Microsoft Client/Server Run-time Subsystem Privilege Elevation Vulnerability (978037)
20934| [902114] Microsoft Office PowerPoint Remote Code Execution Vulnerabilities (975416)
20935| [902112] Microsoft SMB Client Remote Code Execution Vulnerabilities (978251)
20936| [902095] Microsoft Office Excel Remote Code Execution Vulnerability (2269707)
20937| [902094] Microsoft Windows Kernel Mode Drivers Privilege Elevation Vulnerabilities (2160329)
20938| [902093] Microsoft Windows Kernel Privilege Elevation Vulnerabilities (981852)
20939| [902080] Microsoft Help and Support Center Remote Code Execution Vulnerability (2229593)
20940| [902069] Microsoft SharePoint Privilege Elevation Vulnerabilities (2028554)
20941| [902068] Microsoft Office Excel Remote Code Execution Vulnerabilities (2027452)
20942| [902067] Microsoft Windows Kernel Mode Drivers Privilege Escalation Vulnerabilities (979559)
20943| [902039] Microsoft Visio Remote Code Execution Vulnerabilities (980094)
20944| [902038] Microsoft MPEG Layer-3 Codecs Remote Code Execution Vulnerability (977816)
20945| [902015] Microsoft Paint Remote Code Execution Vulnerability (978706)
20946| [901305] Microsoft Windows IP-HTTPS Component Security Feature Bypass Vulnerability (2765809)
20947| [901304] Microsoft Windows File Handling Component Remote Code Execution Vulnerability (2758857)
20948| [901212] Microsoft Windows DirectPlay Remote Code Execution Vulnerability (2770660)
20949| [901211] Microsoft Windows Common Controls Remote Code Execution Vulnerability (2720573)
20950| [901210] Microsoft Office Privilege Elevation Vulnerability - 2721015 (Mac OS X)
20951| [901209] Microsoft Windows Media Center Remote Code Execution Vulnerabilities (2604926)
20952| [901208] Microsoft Internet Explorer Multiple Vulnerabilities (2586448)
20953| [901206] Check RPC rstatd Service Running
20954| [901205] Microsoft Windows Components Remote Code Execution Vulnerabilities (2570947)
20955| [901203] Apache httpd Web Server Range Header Denial of Service Vulnerability
20956| [901202] Check rlogin Service Running
20957| [901193] Microsoft Windows Media Remote Code Execution Vulnerabilities (2510030)
20958| [901183] Internet Information Services (IIS) FTP Service Remote Code Execution Vulnerability (2489256)
20959| [901180] Microsoft Internet Explorer Multiple Vulnerabilities (2482017)
20960| [901176] Kingsoft Antivirus 'KisKrnl.sys' Driver Denial of Service Vulnerability
20961| [901169] Microsoft Windows Address Book Remote Code Execution Vulnerability (2423089)
20962| [901166] Microsoft Office Remote Code Execution Vulnerabilites (2423930)
20963| [901163] Microsoft Windows Media Player Remote Code Execution Vulnerability (2378111))
20964| [901162] Microsoft Internet Explorer Multiple Vulnerabilities (2360131)
20965| [901161] Microsoft ASP.NET Information Disclosure Vulnerability (2418042)
20966| [901142] FreeType Multiple denial of service vulnerabilities (Windows)
20967| [901140] Microsoft Windows SMB Code Execution and DoS Vulnerabilities (982214)
20968| [901139] Microsoft Internet Explorer Multiple Vulnerabilities (2183461)
20969| [901137] Pidgin 'X-Status' Message Denial of Service Vulnerability (Win)
20970| [901136] OpenTTD 'NetworkSyncCommandQueue()' Denial of Service Vulnerability
20971| [901132] SasCAM Request Processing Denial of Service Vulnerability
20972| [901124] SolarWinds TFTP Server Write Request Denial Of Service Vulnerability
20973| [901120] Microsoft IIS Authentication Remote Code Execution Vulnerability (982666)
20974| [901119] Microsoft Windows OpenType Compact Font Format Driver Privilege Escalation Vulnerability (980218)
20975| [901104] Tembria Server Monitor HTTP Request Denial of Service Vulnerability
20976| [901103] Memcached Denial of service vulnerability
20977| [901097] Microsoft Internet Explorer Multiple Vulnerabilities (978207)
20978| [901095] Microsoft Embedded OpenType Font Engine Remote Code Execution Vulnerabilities (972270)
20979| [901081] IBM DB2 db2pd Denial Of Service Vulnerability (Linux)
20980| [901080] IBM DB2 db2pd Denial Of Service Vulnerability (Win)
20981| [901069] Microsoft Office Project Remote Code Execution Vulnerability (967183)
20982| [901065] Microsoft Windows IAS Remote Code Execution Vulnerability (974318)
20983| [901064] Microsoft Windows ADFS Remote Code Execution Vulnerability (971726)
20984| [901057] UseBB BBcode Parsing Remote Denial Of Service Vulnerability
20985| [901055] Sun VirtualBox or xVM VirtualBox Denial Of Service Vulnerability (Linux)
20986| [901054] Sun VirtualBox or xVM VirtualBox Denial Of Service Vulnerability (Win)
20987| [901043] SystemTap Unprivileged Mode Multiple Denial Of Service Vulnerabilities
20988| [901041] Microsoft Internet Explorer Multiple Code Execution Vulnerabilities (974455)
20989| [901033] Wireshark Multiple Denial of Service Vulnerabilities (Linux)
20990| [901031] Wireshark Multiple Denial of Service Vulnerabilities (Win)
20991| [901030] Wireshark OpcUa Dissector Denial of Service Vulnerability (Win)
20992| [901012] Microsoft Windows Media Format Remote Code Execution Vulnerability (973812)
20993| [900993] PHP 'unserialize()' Function Denial of Service Vulnerability
20994| [900989] Wireshark Daintree SNA File Parser Denial of Service Vulnerability (Linux)
20995| [900988] Wireshark IPMI Dissector Denial of Service Vulnerability (Win)
20996| [900977] COWON Media Center JetAudio .wav File Denial Of Service Vulnerability
20997| [900973] Microsoft Office Word Remote Code Execution Vulnerability (976307)
20998| [900965] Microsoft Windows SMB2 Negotiation Protocol Remote Code Execution Vulnerability
20999| [900964] Microsoft .NET Common Language Runtime Code Execution Vulnerability (974378)
21000| [900963] Microsoft Windows Kernel Privilege Escalation Vulnerability (971486)
21001| [900957] Microsoft Windows Patterns & Practices EntLib DOS Vulnerability
21002| [900956] Microsoft Windows Patterns & Practices EntLib Version Detection
21003| [900944] Microsoft IIS FTP Server 'ls' Command DOS Vulnerability
21004| [900940] Pidgin Multiple Denial Of Service Vulnerabilities (Win)
21005| [900929] Microsoft JScript Scripting Engine Remote Code Execution Vulnerability (971961)
21006| [900925] PHP dba_replace Denial of Service Vulnerability
21007| [900922] TheGreenBow IPSec VPN Client Denial Of Service Vulnerability
21008| [900919] Pidgin MSN SLP Packets Denial Of Service Vulnerability (Win)
21009| [900908] Microsoft Windows Message Queuing Privilege Escalation Vulnerability (971032)
21010| [900907] Microsoft Windows AVI Media File Parsing Vulnerabilities (971557)
21011| [900903] KDE Konqueror Select Object Denial of Service Vulnerability
21012| [900898] Microsoft Internet Explorer 'XSS Filter' XSS Vulnerabilities - Nov09
21013| [900897] Microsoft Internet Explorer PDF Information Disclosure Vulnerability - Nov09
21014| [900887] Microsoft Office Excel Multiple Vulnerabilities (972652)
21015| [900886] Microsoft Windows Kernel-Mode Drivers Multiple Vulnerabilities (969947)
21016| [900880] Microsoft Windows ATL COM Initialization Code Execution Vulnerability (973525)
21017| [900879] Microsoft Windows Media Player ASF Heap Overflow Vulnerability (974112)
21018| [900878] Microsoft Products GDI Plus Code Execution Vulnerabilities (957488)
21019| [900876] Microsoft Windows CryptoAPI X.509 Spoofing Vulnerabilities (974571)
21020| [900873] Microsoft Windows DNS Devolution Third-Level Domain Name Resolving Weakness (971888)
21021| [900872] PHP 'tsrm_win32.c' Denial Of Service Vulnerability (Win)
21022| [900866] Mozilla Firefox 'window.print()' Denial Of Service Vulnerability (Linux)
21023| [900865] Mozilla Firefox 'window.print()' Denial Of Service Vulnerability (Win)
21024| [900864] Internet Explorer 'KEYGEN' Element Denial Of Service Vulnerability
21025| [900863] Microsoft Internet Explorer 'window.print()' DOS Vulnerability
21026| [900862] Google Chrome 'KEYGEN' Element Denial Of Service Vulnerability
21027| [900859] Google Chrome Denial Of Service Vulnerability - Sep09
21028| [900856] FreeRADIUS Tunnel-Password Denial Of Service Vulnerability
21029| [900850] Mozilla Firefox Denial Of Service Vulnerability - Sep09 (Linux)
21030| [900848] Mozilla Firefox Multiple Denial Of Service Vulnerabilities - Sep09 (Linux)
21031| [900846] Mozilla Firefox Denial Of Service Vulnerability - Sep09 (Win)
21032| [900844] Mozilla Firefox Multiple Denial Of Service Vulnerabilities - Sep09 (Win)
21033| [900841] Apache 'mod_proxy_ftp' Module Denial Of Service Vulnerability (Linux)
21034| [900838] Microsoft Windows TCP/IP Remote Code Execution Vulnerability (967723)
21035| [900837] Microsoft DHTML Editing Component ActiveX Remote Code Execution Vulnerability (956844)
21036| [900836] Microsoft Internet Explorer Address Bar Spoofing Vulnerability
21037| [900834] Asterisk SIP Channel Driver Denial Of Service Vulnerability (Linux)
21038| [900833] Google Chrome 'chromehtml: URI' Denial Of Service Vulnerability
21039| [900831] Mozilla Firefox 'document.location' Denial Of Service Vulnerability
21040| [900828] Neon Certificate Spoofing and Denial of Service Vulnerability
21041| [900826] Microsoft Internet Explorer 'location.hash' DOS Vulnerability
21042| [900825] Google Chrome 'tooltip_manager.cc' Denial Of Service Vulnerability
21043| [900824] Google Chrome 'location.hash' Denial Of Service Vulnerability
21044| [900814] Microsoft Windows WINS Remote Code Execution Vulnerability (969883)
21045| [900813] Microsoft Remote Desktop Connection Remote Code Execution Vulnerability (969706)
21046| [900812] Asterisk RTP Text Frames Denial Of Service Vulnerability
21047| [900809] Microsoft Visual Studio ATL Remote Code Execution Vulnerability (969706)
21048| [900808] Microsoft Visual Products Version Detection
21049| [900805] Google Chrome Unicode String Denial Of Service Vulnerability
21050| [900804] Opera Unicode String Denial Of Service Vulnerability (Linux)
21051| [900803] Opera Unicode String Denial Of Service Vulnerability (Win)
21052| [900757] Microsoft Windows Media Player '.AVI' File DOS Vulnerability
21053| [900741] Microsoft Internet Explorer Information Disclosure Vulnerability Feb10
21054| [900740] Microsoft Windows Kernel Could Allow Elevation of Privilege (977165)
21055| [900711] Microsoft IIS WebDAV Remote Authentication Bypass Vulnerability
21056| [900690] Microsoft Virtual PC/Server Privilege Escalation Vulnerability (969856)
21057| [900689] Microsoft Embedded OpenType Font Engine Remote Code Execution Vulnerabilities (961371))
21058| [900683] Foxit Reader Multiple Denial of Service Vulnerabilities - Jun09
21059| [900682] GUPnP Message Handling Denial Of Service Vulnerability
21060| [900670] Microsoft Office Excel Remote Code Execution Vulnerabilities (969462)
21061| [900648] PumpKIN TFTP Server Denial of Service Vulnerability
21062| [900634] Trend Micro OfficeScan Client Denial Of Service Vulnerability
21063| [900594] Wireshark AFS Dissector Denial of Service Vulnerability (Win)
21064| [900593] Wireshark Infiniband Dissector Denial of Service Vulnerability (Linux)
21065| [900592] Wireshark Infiniband Dissector Denial of Service Vulnerability (Win)
21066| [900589] Microsoft ISA Server Privilege Escalation Vulnerability (970953)
21067| [900588] Microsoft DirectShow Remote Code Execution Vulnerability (961373)
21068| [900580] VicFTPS LIST Command Denial of Service Vulnerability
21069| [900573] Apache APR-Utils XML Parser Denial of Service Vulnerability
21070| [900572] Apache APR-Utils Multiple Denial of Service Vulnerabilities
21071| [900570] Ruby BigDecimal Library Denial of Service Vulnerability (Linux)
21072| [900568] Microsoft Windows Search Script Execution Vulnerability (963093)
21073| [900567] Microsoft IIS Security Bypass Vulnerability (970483)
21074| [900566] Microsoft Active Directory LDAP Remote Code Execution Vulnerability (969805)
21075| [900559] Wireshark PCNFSD Dissector Denial of Service Vulnerability (Win)
21076| [900546] ClamAV Denial of Service Vulnerability (Win)
21077| [900545] ClamAV Denial of Service Vulnerability (Linux)
21078| [900538] mpg123 Player Denial of Service Vulnerability (Linux)
21079| [900511] RaidenFTPD Server CWD and MLST Command Denial of Service Vulnerability
21080| [900480] PostgreSQL Denial of Service Vulnerability (Linux)
21081| [900476] Microsoft Excel Remote Code Execution Vulnerabilities (968557)
21082| [900465] Microsoft Windows DNS Memory Corruption Vulnerability - Mar09
21083| [900463] NoticeWare Mail Server Denial of Service Vulnerability
21084| [900450] WinFTP Server PASV Command Denial of Service Vulnerability
21085| [900445] Microsoft Autorun Arbitrary Code Execution Vulnerability (08-038)
21086| [900443] MikMod Module Player Denial of Service Vulnerability (Linux)
21087| [900417] Konqueror in KDE Denial of Service Vulnerability
21088| [900415] Avahi Denial of Service Vulnerability
21089| [900413] MailScanner Infinite Loop Denial of Service Vulnerability
21090| [900404] Microsoft Windows RTCP Unspecified Remote DoS Vulnerability
21091| [900400] Microsoft Internet Explorer Unicode String DoS Vulnerability
21092| [900395] Netscape 'select()' Object Denial Of Service Vulnerability (Linux)
21093| [900393] Netscape 'select()' Object Denial Of Service Vulnerability (Win)
21094| [900391] Microsoft Office Publisher Remote Code Execution Vulnerability (969516)
21095| [900386] StrongSwan/Openswan Denial Of Service Vulnerability June-09
21096| [900366] Microsoft Internet Explorer Web Script Execution Vulnerabilites
21097| [900365] Microsoft Office Word Remote Code Execution Vulnerabilities (969514)
21098| [900336] Microsoft Windows Media Player MID File Integer Overflow Vulnerability
21099| [900328] Microsoft Internet Explorer Remote Code Execution Vulnerability (963027)
21100| [900303] Microsoft Internet Explorer HTML Form Value DoS Vulnerability
21101| [900299] Microsoft Report Viewer Information Disclosure Vulnerability (2578230)
21102| [900298] MS Windows Remote Access Service NDISTAPI Driver Privilege Elevation Vulnerability (2566454)
21103| [900295] Microsoft Windows DNS Server Remote Code Execution Vulnerability (2562485)
21104| [900294] Microsoft Data Access Components Remote Code Execution Vulnerabilities (2560656)
21105| [900291] HP Data Protector Manager RDS Service Denial of Service Vulnerability
21106| [900289] Active Directory Certificate Services Web Enrollment Elevation of Privilege Vulnerability (2518295)
21107| [900288] Microsoft Distributed File System Remote Code Execution Vulnerabilities (2535512)
21108| [900287] Microsoft SMB Client Remote Code Execution Vulnerabilities (2536276)
21109| [900285] Microsoft Foundation Class (MFC) Library Remote Code Execution Vulnerability (2500212)
21110| [900282] Microsoft DNS Resolution Remote Code Execution Vulnerability (2509553)
21111| [900281] Microsoft IE Developer Tools WMITools and Windows Messenger ActiveX Control Vulnerability (2508272)
21112| [900280] Microsoft Windows SMB Server Remote Code Execution Vulnerability (2508429)
21113| [900279] Microsoft SMB Client Remote Code Execution Vulnerabilities (2511455)
21114| [900278] Microsoft Internet Explorer Multiple Vulnerabilities (2497640)
21115| [900276] IGSS ODBC Server Multiple Uninitialized Pointer Denial of Service Vulnerability
21116| [900274] SpoonFTP 'RETR' Command Remote Denial of Service Vulnerability
21117| [900273] Microsoft Remote Desktop Client Remote Code Execution Vulnerability (2508062)
21118| [900272] ActFax LPD/LPR Server Denial of Service Vulnerability
21119| [900271] ActFax FTP Server Post Auth 'RETR' Command Denial of Service Vulnerability
21120| [900270] Objectivity/DB Lock Server Denial of Service Vulnerability
21121| [900269] Objectivity/DB Advanced Multithreaded Server Denial of Service Vulnerability
21122| [900268] Mongoose Webserver Content-Length Denial of Service Vulnerability
21123| [900267] Microsoft Media Decompression Remote Code Execution Vulnerability (2447961)
21124| [900266] Microsoft Windows Movie Maker Could Allow Remote Code Execution Vulnerability (2424434)
21125| [900263] Microsoft Windows OpenType Compact Font Format Driver Privilege Escalation Vulnerability (2296199)
21126| [900262] Microsoft Internet Explorer Multiple Vulnerabilities (2416400)
21127| [900261] Microsoft Office PowerPoint Remote Code Execution Vulnerabilities (2293386)
21128| [900248] Microsoft Windows Movie Maker Could Allow Remote Code Execution Vulnerability (981997)
21129| [900246] Microsoft Media Decompression Remote Code Execution Vulnerability (979902)
21130| [900245] Microsoft Data Analyzer and IE Developer Tools ActiveX Control Vulnerability (980195)
21131| [900241] Microsoft Outlook Express and Windows Mail Remote Code Execution Vulnerability (978542)
21132| [900237] Microsoft Windows Authentication Verification Remote Code Execution Vulnerability (981210)
21133| [900236] Microsoft Windows Kernel Could Allow Elevation of Privilege (979683)
21134| [900235] Microsoft Windows Media Player Could Allow Remote Code Execution (979402)
21135| [900232] Microsoft Windows Movie Maker Could Allow Remote Code Execution Vulnerability (975561)
21136| [900230] Microsoft Windows SMB Server Multiple Vulnerabilities (971468)
21137| [900229] Microsoft Data Analyzer ActiveX Control Vulnerability (978262)
21138| [900228] Microsoft Office (MSO) Remote Code Execution Vulnerability (978214)
21139| [900227] Microsoft Windows Shell Handler Could Allow Remote Code Execution Vulnerability (975713)
21140| [900223] Microsoft Ancillary Function Driver Elevation of Privilege Vulnerability (956803)
21141| [900211] HP OpenView Network Node Manager Denial of Service Vulnerabilities
21142| [900192] Microsoft Internet Explorer Information Disclosure Vulnerability
21143| [900187] Microsoft Internet Explorer Argument Injection Vulnerability
21144| [900178] Microsoft Windows 'UnhookWindowsHookEx' Local DoS Vulnerability
21145| [900173] Microsoft Windows Media Player Version Detection
21146| [900172] Microsoft Windows Media Player 'MIDI' or 'DAT' File DoS Vulnerability
21147| [900170] Microsoft iExplorer '&NBSP
21148| [900127] Personal FTP Server RETR Command Remote Denial of Service Vulnerability
21149| [900125] Microsoft SQL Server 2000 sqlvdir.dll ActiveX Buffer Overflow Vulnerability
21150| [900120] Microsoft Organization Chart Remote Code Execution Vulnerability
21151| [900119] Softalk Mail Server IMAP Denial of Service Vulnerability
21152| [900117] ClamAV Invalid Memory Access Denial Of Service Vulnerability
21153| [900113] RhinoSoft Serv-U SFTP Remote Denial of Service Vulnerability
21154| [900109] hMailServer IMAP Denial of Service Vulnerability
21155| [900108] Microsoft Windows NSlookup.exe Remote Code Execution Vulnerability
21156| [900104] MailEnable IMAP Denial of Service Vulnerability
21157| [900097] Vulnerability in Microsoft DirectShow Could Allow Remote Code Execution
21158| [900095] Microsoft ISA Server and Forefront Threat Management Gateway DoS Vulnerability (961759)
21159| [900093] Microsoft DirectShow Remote Code Execution Vulnerability (961373)
21160| [900092] Windows HTTP Services Could Allow Remote Code Execution Vulnerabilities (960803)
21161| [900080] Vulnerabilities in Microsoft Office Visio Could Allow Remote Code Execution (957634)
21162| [900079] Vulnerabilities in Microsoft Exchange Could Allow Remote Code Execution (959239)
21163| [900077] OpenOffice Denial of Service Vulnerability (Win)
21164| [900076] OpenOffice Denial of Service Vulnerability (Linux)
21165| [900064] Vulnerability in Microsoft Office SharePoint Server Could Cause Elevation of Privilege (957175)
21166| [900063] Vulnerabilities in Microsoft Office Word Could Allow Remote Code Execution (957173)
21167| [900061] Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (959070)
21168| [900056] Vulnerability in Server Service Could Allow Remote Code Execution (958644)
21169| [900055] Server Service Could Allow Remote Code Execution Vulnerability (958644)
21170| [900052] Windows Internet Printing Service Allow Remote Code Execution Vulnerability (953155)
21171| [900049] Host Integration Server RPC Service Remote Code Execution Vulnerability (956695)
21172| [900048] Microsoft Excel Remote Code Execution Vulnerability (956416)
21173| [900047] Microsoft Office nformation Disclosure Vulnerability (957699)
21174| [900046] Microsoft Office Remote Code Execution Vulnerabilities (955047)
21175| [900033] Microsoft PowerPoint Could Allow Remote Code Execution Vulnerabilities (949785)
21176| [900029] Microsoft Office Filters Could Allow Remote Code Execution Vulnerabilities (924090)
21177| [900028] Microsoft Excel Could Allow Remote Code Execution Vulnerabilities (954066)
21178| [900025] Microsoft Office Version Detection
21179| [900017] AVG Anti-Virus UPX Processing Denial of Service Vulnerability
21180| [900006] Microsoft Word Could Allow Remote Code Execution Vulnerability
21181| [900004] Microsoft Access Snapshot Viewer ActiveX Control Vulnerability
21182| [864524] Fedora Update for accountsservice FEDORA-2012-10120
21183| [861438] Fedora Update for Terminal FEDORA-2007-1620
21184| [861265] Fedora Update for Terminal FEDORA-2007-4385
21185| [861044] Fedora Update for Terminal FEDORA-2007-4368
21186| [855802] Solaris Update for Native LDAP, PAM, name-service-switch 138874-05
21187| [855724] Solaris Update for Native LDAP, PAM, name-service-switch 138875-05
21188| [855605] Solaris Update for Federated Naming Service (FNS) X500 116997-01
21189| [855343] Solaris Update for Federated Naming Service (FNS) X500 116998-01
21190| [855043] Solaris Update for vgatext and terminal-emulator 109155-01
21191| [841208] Ubuntu Update for remote-login-service USN-1624-1
21192| [841066] Ubuntu Update for accountsservice USN-1485-1
21193| [840946] Ubuntu Update for accountsservice USN-1351-1
21194| [840094] Ubuntu Update for xfce4-terminal vulnerability USN-497-1
21195| [835127] HP-UX Update for MC/ServiceGuard HPSBUX00129
21196| [835108] HP-UX Update for HP WEBM Services HPSBUX00288
21197| [830221] Mandriva Update for gnome-terminal MDKA-2007:016 (gnome-terminal)
21198| [803104] Oracle VM VirtualBox Unspecified Denial of Service Vulnerability (Mac OS X)
21199| [803103] Oracle VM VirtualBox Unspecified Denial of Service Vulnerability (Windows)
21200| [803091] OpenBSD Portmap Remote Denial of Service Vulnerability
21201| [803065] LibreOffice Import Files Denial of Service Vulnerabilities (Mac OS X)
21202| [803064] LibreOffice Import Files Denial of Service Vulnerabilities (Windows)
21203| [803037] Optima PLC APIFTP Server Denial of Service Vulnerabilities
21204| [803028] Microsoft Internet Explorer Remote Code Execution Vulnerability (2757760)
21205| [803007] Microsoft Windows Minimum Certificate Key Length Spoofing Vulnerability (2661254)
21206| [803000] Citrix Provisioning Services SoapServer Buffer Overflow Vulnerability
21207| [802996] Mozilla Firefox 'WebSockets' Denial of Service Vulnerability (Windows)
21208| [802993] Mozilla Firefox 'WebSockets' Denial of Service Vulnerability (Mac OS X)
21209| [802921] VLC Media Player 'MP4' Denial of Service Vulnerability (Mac OS X)
21210| [802920] VLC Media Player 'MP4' Denial of Service Vulnerability (Windows)
21211| [802914] MailEnable SMTP HELO Command Denial of Service Vulnerability
21212| [802913] freeFTPD PORT Command Denial of Service Vulnerability
21213| [802912] Microsoft Unauthorized Digital Certificates Spoofing Vulnerability (2728973)
21214| [802908] Wireshark Multiple Denial of Service Vulnerabilities - July 12 (Mac OS X)
21215| [802907] Wireshark Multiple Denial of Service Vulnerabilities - July 12 (Windows)
21216| [802906] Pidgin MSN and XMPP Denial of Service Vulnerabilities (Windows)
21217| [802905] PowerNet Twin Client 'RFSynC' Denial of Service Vulnerability
21218| [802902] Wireshark Denial of Service Vulnerability-02 March 11 (Mac OS X)
21219| [802900] Wireshark Denial of Service Vulnerability March-11 (Mac OS X)
21220| [802899] Wireshark PPP And NFS Dissector Denial of Service Vulnerabilities (Mac OS X)
21221| [802898] Wireshark PPP And NFS Dissector Denial of Service Vulnerabilities (Windows)
21222| [802886] Microsoft Sidebar and Gadgets Remote Code Execution Vulnerability (2719662)
21223| [802877] Wireshark 'bytes_repr_len' Denial of Service Vulnerability (Mac OS X)
21224| [802870] Mozilla Products 'jsinfer.cpp' Denial of Service Vulnerability (Mac OS X)
21225| [802869] Mozilla Products 'jsinfer.cpp' Denial of Service Vulnerability (Windows)
21226| [802867] Mozilla Products Updater Service Privilege Escalation Vulnerabilities (Win)
21227| [802850] Google Chrome Multiple Denial of Service Vulnerabilities - May 12 (Mac OS X)
21228| [802849] Google Chrome Multiple Denial of Service Vulnerabilities - May 12 (Linux)
21229| [802848] Google Chrome Multiple Denial of Service Vulnerabilities - May 12 (Windows)
21230| [802846] Wireshark ZigBee ZCL Dissector Denial of Service Vulnerability (Mac OS X)
21231| [802844] Wireshark Lucent/Ascend File Parser Denial of Service Vulnerability (Mac OS X)
21232| [802831] EMC NetWorker 'nsrexecd' RPC Packet Denial of Service Vulnerability
21233| [802829] Opera Large Integer Argument Denial of Service Vulnerability (Linux)
21234| [802827] EMC Data Protection Advisor NULL Pointer Dereference Denial of Service Vulnerability
21235| [802826] RealNetworks RealPlayer MP4 File Handling Denial of Service Vulnerability (Win)
21236| [802825] Jabber Studio Jabberd Server SASL Negotiation Denial of Service Vulnerability
21237| [802809] Google Chrome Multiple Denial of Service Vulnerabilities - March12 (Mac OS X)
21238| [802808] Google Chrome Multiple Denial of Service Vulnerabilities - March12 (Linux)
21239| [802807] Google Chrome Multiple Denial of Service Vulnerabilities - March12 (Windows)
21240| [802806] Microsoft IIS Default Welcome Page Information Disclosure Vulnerability
21241| [802799] Wireshark Denial of Service Vulnerability-01 March 11 (Mac OS X)
21242| [802774] Microsoft VPN ActiveX Control Remote Code Execution Vulnerability (2695962)
21243| [802768] Wireshark CSN.1 Dissector Denial of Service Vulnerability (Mac OS X)
21244| [802767] Wireshark Heap Based BOF and Denial of Service Vulnerabilities (Mac OS X)
21245| [802766] Wireshark ANSI A MAP Files Denial of Service Vulnerability (Mac OS X)
21246| [802765] Wireshark IEEE 802.11 Dissector Denial of Service Vulnerability (Mac OS X)
21247| [802763] Wireshark Multiple Denial of Service Vulnerabilities (Mac OS X)
21248| [802760] Wireshark IEEE 802.11 Dissector Denial of Service Vulnerability (Windows)
21249| [802759] Wireshark Multiple Denial of Service Vulnerabilities - April 12 (Windows)
21250| [802757] Opera Browser 'SRC' Denial of Service Vulnerability (Mac OS X)
21251| [802754] Opera Web Browser Select Object Denial Of Service Vulnerability (Mac OS X)
21252| [802742] Opera Browser 'SRC' Denial of Service Vulnerability (Linux)
21253| [802726] Microsoft SMB Signing Disabled
21254| [802713] Pidgin Multiple Denial of Service Vulnerabilities (Windows)
21255| [802708] Microsoft Internet Explorer Code Execution and DoS Vulnerabilities
21256| [802685] IBM RBD Web Services Information Disclosure Vulnerability (Win)
21257| [802677] CA ARCserve Backup RPC Services Multiple Vulnerabilities (Windows)
21258| [802665] Wireshark ASN.1 BER Dissector Denial of Service Vulnerability (Mac OS X)
21259| [802651] Opera Multiple Denial of Service Vulnerabilities - June12 (Linux)
21260| [802650] Opera Multiple Denial of Service Vulnerabilities - June12 (Mac OS X)
21261| [802649] Opera Multiple Denial of Service Vulnerabilities - June12 (Windows)
21262| [802635] xArrow Multiple Denial of Service Vulnerabilities
21263| [802634] Microsoft Windows Unauthorized Digital Certificates Spoofing Vulnerability (2718704)
21264| [802627] LAN Messenger Malformed Initiation Request Remote Denial of Service Vulnerability
21265| [802626] Wireshark Code Execution and Denial of Service Vulnerabilities (Mac OS X)
21266| [802625] Wireshark Multiple Denial of Service Vulnerabilities (Mac OS X)
21267| [802617] NetDecision HTTP Server Long HTTP Request Remote Denial of Service Vulnerability
21268| [802614] Tiny HTTP Server Remote Denial of Service Vulnerability
21269| [802613] Core FTP Server 'Type' Command Remote Denial of Service Vulnerability
21270| [802605] TYPSoft FTP Server Multiple Commands Remote Denial of Service Vulnerabilities
21271| [802566] PHP Multiple Denial of Service Vulnerabilities (Windows)
21272| [802557] LibreOffice 'DOC' File Denial of Service Vulnerability (Windows)
21273| [802539] Oracle Database Server 'RDBMS' component Denial of Service Vulnerability
21274| [802523] Oracle Database Server MDSYS.MD Buffer Overflows and Denial of Service Vulnerabilities
21275| [802510] Mozilla Products Browser Engine Denial of Service Vulnerabilities (Windows)
21276| [802506] Investintech Products Denial of Service Vulnerabilities
21277| [802503] Wireshark CSN.1 Dissector Denial of Service Vulnerability (Windows)
21278| [802502] Wireshark Heap Based BOF and Denial of Service Vulnerabilities (Windows)
21279| [802500] Microsoft Windows TrueType Font Parsing Privilege Elevation Vulnerability
21280| [802489] VLC Media Player 'libpng_plugin' Denial of Service Vulnerability (Mac OS X)
21281| [802488] VLC Media Player 'libpng_plugin' Denial of Service Vulnerability (Windows)
21282| [802468] Compatibility Issues Affecting Signed Microsoft Binaries (2749655)
21283| [802426] Microsoft Windows ActiveX Control Multiple Vulnerabilities (2647518)
21284| [802420] VLC Media Player '.amr' File Denial of Service Vulnerability (Windows)
21285| [802409] Oracle GlassFish Server Hash Collision Denial of Service Vulnerability
21286| [802408] PHP Web Form Hash Collision Denial of Service Vulnerability (Win)
21287| [802406] Hillstone Software TFTP Write/Read Request Server Denial Of Service Vulnerability
21288| [802396] Opera Large Integer Argument Denial of Service Vulnerability (Mac OS X)
21289| [802395] Opera Large Integer Argument Denial of Service Vulnerability (Windows)
21290| [802386] HP Diagnostics Server 'magentservice.exe' Buffer Overflow Vulnerability
21291| [802384] Apache Tomcat Parameter Handling Denial of Service Vulnerability (Win)
21292| [802383] Microsoft Windows Color Control Panel Privilege Escalation Vulnerability
21293| [802382] Wibu-Systems CodeMeter Runtime TCP Packets Denial of Service Vulnerability
21294| [802379] Microsoft Windows Kernel 'win32k.sys' Memory Corruption Vulnerability
21295| [802378] Apache Tomcat Hash Collision Denial Of Service Vulnerability
21296| [802376] Google Chrome Multiple Denial of Service Vulnerabilities - January12 (Mac OS X)
21297| [802375] Google Chrome Multiple Denial of Service Vulnerabilities - January12 (Linux)
21298| [802374] Google Chrome Multiple Denial of Service Vulnerabilities - January12 (Windows)
21299| [802372] WinMount 'WMDrive.sys' Driver IOCTL Handling Denial of Service Vulnerability
21300| [802370] TomatoSoft Free Mp3 Player '.mp3' File Denial of Service Vulnerability
21301| [802349] PHP EXIF Header Denial of Service Vulnerability (Windows)
21302| [802340] EtherApe RPC Packet Processing Denial of Service Vulnerability
21303| [802339] Google Chrome Mozilla Network Security Services Privilege Escalation Vulnerability (Mac OS X)
21304| [802338] Google Chrome Mozilla Network Security Services Privilege Escalation Vulnerability (Windows)
21305| [802331] Pidgin Libpurple Protocol Plugins Denial of Service Vulnerabilities (Win)
21306| [802308] Wireshark Lucent/Ascend File Parser Denial of Service Vulnerability (Win)
21307| [802300] Tor Directory Authority 'policy_summarize' Denial of Service Vulnerability (Windows)
21308| [802295] Linux Kernel IGMP Remote Denial of Service Vulnerability
21309| [802287] Microsoft Internet Explorer Cache Objects History Information Disclosure Vulnerability
21310| [802286] Microsoft Internet Explorer Multiple Information Disclosure Vulnerabilities
21311| [802260] Microsoft Windows WINS Remote Code Execution Vulnerability (2524426)
21312| [802248] Wireshark Multiple Denial of Service Vulnerabilities (Windows)
21313| [802236] Finger Service Remote Information Disclosure Vulnerability
21314| [802232] CiscoKits CCNA TFTP Server 'Write' Command Denial Of Service Vulnerability
21315| [802231] Finger Redirection Remote Denial of Service Vulnerability
21316| [802223] Shibboleth XML Security Signature Key Parsing Denial of Service Vulnerability (Win)
21317| [802221] Citrix Provisioning Services 'streamprocess.exe' Component Remote Code Execution Vulnerability
21318| [802214] Mozilla Products Multiple Denial of Service Vulnerabilities July-11 (Windows)
21319| [802203] Microsoft Internet Explorer Cookie Hijacking Vulnerability
21320| [802202] Microsoft Internet Explorer Cookie Hijacking Vulnerability
21321| [802201] Wireshark 'bytes_repr_len' Function Denial of Service Vulnerability (Windows)
21322| [802200] Wireshark Multiple Denial of Service Vulnerabilities (Windows)
21323| [802198] Apple QuickTime Multiple Denial of Service Vulnerabilities - (Windows)
21324| [802163] Calendar Manager Service rpc.cmsd Service Detection
21325| [802140] Microsoft Explorer HTTPS Sessions Multiple Vulnerabilities (Windows)
21326| [802137] Nfs-utils rpc.rquotad Service Detection
21327| [802136] Microsoft Windows Insecure Library Loading Vulnerability (2269637)
21328| [802129] AzeoTech DAQFactory Denial of Service Vulnerability
21329| [802119] VLC Media Player 'AMV' Denial of Service Vulnerability (Windows)
21330| [802118] VLC Media Player 'AMV' Denial of Service Vulnerability (Linux)
21331| [802113] Opera Browser 'SRC' Denial of Service Vulnerability (Windows)
21332| [802044] Lighttpd Connection header Denial of Service Vulnerability
21333| [802036] Beckhoff TwinCAT 'TCATSysSrv.exe' Network Packet Denial of Service Vulnerability
21334| [802020] Serva32 web server Denial of Service Vulnerability
21335| [802012] Rumble SMTP Server 'MAIL FROM' Command Denial of Service Vulnerability
21336| [802011] Avaya IP Office Manager TFTP Denial of Service Vulnerability
21337| [802007] Hiawatha WebServer 'Content-Length' Denial of Service Vulnerability
21338| [802003] Quick 'n Easy FTP Login Denial of Service Vulnerability
21339| [802002] SolarFTP PASV Command Remote Denial of Service Vulnerability
21340| [802001] SolarFTP USER Command Remote Denial of Service Vulnerability
21341| [801991] Microsoft Windows SMB/NETBIOS NULL Session Authentication Bypass Vulnerability
21342| [801984] ManageEngine ServiceDesk Plus Authentication Bypass Vulnerability
21343| [801983] ManageEngine ServiceDesk Plus 'searchText' XSS Vulnerability
21344| [801968] Adobe Flash Media Server Remote Denial of Service Vulnerability (August-2011)
21345| [801966] Microsoft Windows ActiveX Control Multiple Vulnerabilities (2562937)
21346| [801963] HP Data Protector Media Management Daemon Denial of Service Vulnerability
21347| [801962] ManageEngine ServiceDesk Plus Multiple XSS Vulnerabilities
21348| [801943] Lost Door J-Revolution Denial of Service Vulnerability
21349| [801937] IBM solidDB RPC Test Commands Denial of Service Vulnerabilities
21350| [801935] Microsoft Silverlight Multiple Memory Leak Vulnerabilities
21351| [801934] Microsoft Silverlight Version Detection
21352| [801914] Microsoft Windows IPv4 Default Configuration Security Bypass Vulnerability
21353| [801892] Adobe Flash Media Server XML Data Remote Denial of Service Vulnerability
21354| [801891] Google Chrome Multiple Denial of Service Vulnerabilities - May11 (Linux)
21355| [801890] Google Chrome Multiple Denial of Service Vulnerabilities - May11 (Windows)
21356| [801876] Microsoft Internet Explorer 'msxml.dll' Information Disclosure Vulnerability
21357| [801860] PHP 'grapheme_extract()' NULL Pointer Dereference Denial Of Service Vulnerability
21358| [801854] Citrix Licensing Administration Console Security Bypass And Denial Of Service Vulnerabilities
21359| [801833] Wireshark ASN.1 BER Dissector Denial of Service Vulnerability (Win)
21360| [801831] Microsoft Internet Explorer Incorrect GUI Display Vulnerability
21361| [801830] Microsoft Internet Explorer 'ReleaseInterface()' Remote Code Execution Vulnerability
21362| [801824] IBM Tivoli Directory Proxy Server Denial of Service Vulnerability
21363| [801823] IBM Tivoli Directory Server LDAP BER Denial of Service Vulnerability
21364| [801809] IBM Tivoli Directory Server DIGEST-MD5 Denial of Service Vulnerability
21365| [801790] Perl Denial of Service Vulnerability (Windows)
21366| [801786] Wireshark Denial of Service and Buffer Overflow Vulnerabilities (Windows)
21367| [801785] Wireshark X.509if Dissector Denial of service vulnerability (Windows)
21368| [801772] Rsync Multiple Denial of Service Vulnerabilities (Windows)
21369| [801764] Pidgin Yahoo Protocol 'YMSG' NULL Pointer Dereference Denial of Service Vulnerability (Win)
21370| [801761] Wireshark Denial of Service Vulnerability March-11 (Windows)
21371| [801758] Wireshark Denial of Service Vulnerability March-11 (Windows)
21372| [801756] Wireshark Denial of Service Vulnerability - March-11 (Windows)
21373| [801748] Google Chrome Multiple Denial of Service Vulnerabilities - February 11(Linux)
21374| [801747] Google Chrome Multiple Denial of Service Vulnerabilities - February 11(Windows)
21375| [801742] Wireshark Denial of Service Vulnerability (Windows)
21376| [801725] Microsoft Products GDI Plus Remote Code Execution Vulnerabilities (954593)
21377| [801723] Vulnerability in Windows Services for UNIX Could Allow Elevation of Privilege (939778)
21378| [801719] Microsoft Windows CSRSS CSRFinalizeContext Local Privilege Escalation Vulnerability (930178)
21379| [801718] Microsoft Windows Vista Information Disclosure Vulnerability (931213)
21380| [801717] Microsoft Windows Vista Teredo Interface Firewall Bypass Vulnerability
21381| [801716] Microsoft Outlook Express/Windows Mail MHTML URI Handler Information Disclosure Vulnerability (929123)
21382| [801713] Microsoft Outlook Express And Windows Mail NNTP Protocol Heap Buffer Overflow Vulnerability (941202)
21383| [801712] Vulnerability in RPC Could Allow Denial of Service (933729)
21384| [801707] Microsoft Internet Explorer mshtml.dll Remote Memory Corruption Vulnerability (942615)
21385| [801706] Microsoft Windows TCP/IP Remote Code Execution Vulnerabilities (941644)
21386| [801702] Microsoft Internet Explorer HTML Rendering Remote Memory Corruption Vulnerability (944533)
21387| [801687] TYPSoft FTP Server RETR CMD Denial Of Service Vulnerability
21388| [801677] Microsoft WMI Administrative Tools ActiveX Control Remote Code Execution Vulnerabilities
21389| [801669] Microsoft Windows IIS FTP Server DOS Vulnerability
21390| [801640] ProFTPD Denial of Service Vulnerability
21391| [801638] Apple Safari libxml Denial of Service Vulnerability
21392| [801614] pyftpdlib FTP Server Denial of Service Vulnerability
21393| [801606] Microsoft Internet Explorer 'mshtml.dll' Information Disclosure Vulnerability
21394| [801598] Microsoft Windows2k3 Active Directory 'BROWSER ELECTION' Buffer Overflow Vulnerability
21395| [801597] Microsoft Office Excel 2003 Invalid Object Type Remote Code Execution Vulnerability
21396| [801596] Microsoft Excel 2007 Office Drawing Layer Remote Code Execution Vulnerability
21397| [801595] Microsoft Office Excel Axis and Art Object Parsing Remote Code Execution Vulnerabilities
21398| [801594] Microsoft PowerPoint 2007 OfficeArt Atom Remote Code Execution Vulnerability
21399| [801586] PHP Zend and GD Multiple Denial of Service Vulnerabilities
21400| [801583] PHP 'ext/imap/php_imap.c' Use After Free Denial of Service Vulnerability
21401| [801580] Microsoft Windows Fax Cover Page Editor BOF Vulnerabilities
21402| [801579] HP Data Protector Manager Remote Denial of Service Vulnerability
21403| [801554] Wireshark ZigBee ZCL Dissector Denial of Service Vulnerability (Win)
21404| [801536] Pidgin Libpurple 'purple_base64_decode()' Denial of Service Vulnerabilities (Win)
21405| [801531] IBM solidDB Packets Processing Denial of Service Vulnerabilities
21406| [801527] Microsoft Windows 32-bit Platforms Unspecified vulnerabilities
21407| [801521] Apache APR-util 'buckets/apr_brigade.c' Denial Of Service Vulnerability
21408| [801520] Microsoft IIS ASP Stack Based Buffer Overflow Vulnerability
21409| [801491] Microsoft 'hxvz.dll' ActiveX Control Memory Corruption Vulnerability (948881)
21410| [801489] Microsoft Office Graphics Filters Remote Code Execution Vulnerabilities (968095)
21411| [801488] Microsoft Internet Explorer Data Stream Handling Remote Code Execution Vulnerability (947864)
21412| [801487] Microsoft Windows Kernel Usermode Callback Local Privilege Elevation Vulnerability (941693)
21413| [801486] Microsoft Windows Speech Components Voice Recognition Command Execution Vulnerability (950760)
21414| [801484] Microsoft Windows IPsec Policy Processing Information Disclosure Vulnerability (953733)
21415| [801483] Microsoft Windows Search Remote Code Execution Vulnerability (959349)
21416| [801479] Microsoft Windows TCP/IP Could Allow Remote Code Execution (974145)
21417| [801457] Microsoft Windows Address Book Insecure Library Loading Vulnerability
21418| [801456] Microsoft Windows Progman Group Converter Insecure Library Loading Vulnerability
21419| [801440] Adersoft VbsEdit '.vbs' File Denial Of Service Vulnerability
21420| [801435] Wireshark 'IPMI dissector' Denial of Service Vulnerability (Win)
21421| [801433] Wireshark 'packet-gsm_a_rr.c' Denial of Service Vulnerability (Win)
21422| [801430] VLC Media Player Meta-Information Denial of Service Vulnerability (Linux)
21423| [801429] VLC Media Player Meta-Information Denial of Service Vulnerability (Windows)
21424| [801347] Mozilla Firefox 'IFRAME' Denial Of Service vulnerability (Windows)
21425| [801345] Microsoft .NET 'ASP.NET' Cross-Site Scripting vulnerability
21426| [801344] Microsoft .NET '__VIEWSTATE' Cross-Site Scripting vulnerability
21427| [801342] Microsoft ASP.NET Cross-Site Scripting vulnerability
21428| [801333] Microsoft Windows Kernel 'win32k.sys' Multiple DOS Vulnerabilities
21429| [801332] Apple Safari 'webkit' Denial Of Service Vulnerability
21430| [801330] Microsoft Internet Explorer Cross Site Data Leakage Vulnerability
21431| [801322] VMware Products USB Service Local Privilege Escalation Vulnerability (Win)
21432| [801305] Adobe Reader PDF Handling Denial Of Service Vulnerability (Linux)
21433| [801245] bozotic HTTP server Denial of Service Vulnerability
21434| [801235] Qt 'QSslSocketBackendPrivate::transmit()' Denial of Service Vulnerability
21435| [801222] Weborf 'Range' Header Denial of Service Vulnerability
21436| [801216] Opera 'IFRAME' Denial Of Service vulnerability (Windows)
21437| [801208] Wireshark DOCSIS Dissector Denial of Service Vulnerability (Win)
21438| [801148] Shibboleth Service Provider Multiple XSS Vulnerabilities (Win)
21439| [801141] Opera Denial Of Service Vulnerability - Nov09 (Linux)
21440| [801139] Snort 'IPv6' Packet Denial Of Service Vulnerability (Linux)
21441| [801135] Mozilla Firefox Denial Of Service Vulnerability Nov-09 (Linux)
21442| [801134] Mozilla Firefox Denial Of Service Vulnerability Nov-09 (Win)
21443| [801129] Gpg4Win Denial Of Service Vulnerability
21444| [801118] Rhino Software Serv-U 'SITE SET' Command Denial Of Service vulnerability
21445| [801116] Shibboleth Service Provider NULL Character Spoofing Vulnerability (Win)
21446| [801115] Shibboleth Service Provider Version Detection
21447| [801109] Microsoft IE CA SSL Certificate Security Bypass Vulnerability - Oct09
21448| [801104] Adobe Acrobat PDF File Denial Of Service Vulnerability
21449| [801090] Microsoft Windows Indeo Codec Multiple Vulnerabilities
21450| [801039] HTML-Parser 'decode_entities()' Denial of Service Vulnerability
21451| [801033] Wireshark Multiple Denial Of Service Vulnerability - Nov09 (Linux)
21452| [801032] Wireshark Multiple Denial Of Service Vulnerabilities - Nov09 (Win)
21453| [801030] Pidgin Oscar Protocol Denial of Service Vulnerability (Win)
21454| [801027] VMware Authorization Service Denial of Service Vulnerability (Win)
21455| [800963] ZoIPer Empty Call-Info Denial of Service Vulnerability
21456| [800922] Opera Web Browser Select Object Denial Of Service Vulnerability (Linux)
21457| [800921] Opera Web Browser Select Object Denial Of Service Vulnerability (Win)
21458| [800910] Microsoft Internet Explorer Buffer Overflow Vulnerability - Jul09
21459| [800902] Microsoft Internet Explorer XSS Vulnerability - July09
21460| [800872] Microsoft Internet Explorer 'li' Element DoS Vulnerability - Sep09
21461| [800866] Sun Java System Web Proxy Server Denial Of Service Vulnerability (Linux)
21462| [800865] Sun Java System Web Proxy Server Denial Of Service Vulnerability (Win)
21463| [800863] Microsoft Internet Explorer XML Document DoS Vulnerability - Aug09
21464| [800862] Microsoft Windows Kernel win32k.sys Privilege Escalation Vulnerability
21465| [800861] Microsoft Internet Explorer 'findText()' Unicode Parsing DoS Vulnerability
21466| [800852] Firebird SQL 'op_connect_request' Denial Of Service Vulnerability (Win)
21467| [800849] Mozilla Products 'select()' Denial Of Service Vulnerability (Linux)
21468| [800848] Mozilla Products 'select()' Denial Of Service Vulnerability (Win)
21469| [800845] Microsoft Office Web Components ActiveX Control Code Execution Vulnerability
21470| [800841] Tor Denial Of Service Vulnerability - July09 (Linux)
21471| [800839] Tor Denial Of Service Vulnerability - July09 (Win)
21472| [800837] Apache 'mod_deflate' Denial Of Service Vulnerability - July09
21473| [800829] Microsoft Video ActiveX Control 'msvidctl.dll' BOF Vulnerability
21474| [800827] Apache 'mod_proxy_http.c' Denial Of Service Vulnerability
21475| [800823] Pidgin OSCAR Protocol Denial Of Service Vulnerability (Win)
21476| [800751] Mozilla Products 'nsTreeSelection' Denial of Service vulnerability (Windows)
21477| [800750] Mozilla Products Denial of Service Vulnerability (Windows)
21478| [800744] Apple Safari Nested 'object' Tag Remote Denial Of Service vulnerability
21479| [800742] Microsoft Internet Explorer Unspecified vulnerability
21480| [800726] XM Easy Personal FTP Server File/Folder Denial of Service Vulnerability
21481| [800711] Samba winbind Daemon Denial of Service Vulnerability
21482| [800710] Quagga Denial of Service Vulnerability
21483| [800708] IPSec Tools Denial of Service Vulnerability
21484| [800706] Adobe Reader/Acrobat Denial of Service Vulnerability (May09)
21485| [800701] Adobe Reader Denial of Service Vulnerability (May09)
21486| [800700] Microsoft GDIPlus PNG Infinite Loop Vulnerability
21487| [800687] Microsoft Windows Server 2003 OpenType Font Engine DoS Vulnerability
21488| [800673] strongSwan Denial Of Service Vulnerability - Aug09
21489| [800656] Apple Safari Denial Of Service Vulnerability - Jul09
21490| [800626] ModSecurity Multiple Remote Denial of Service Vulnerabilities
21491| [800600] PGP Desktop Local Denial of Service Vulnerability
21492| [800597] ClamAV LZH File Unpacking Denial of Service Vulnerability (Linux)
21493| [800596] ClamAV LZH File Unpacking Denial of Service Vulnerability (Win)
21494| [800584] CUPS Denial of Service Vulnerability - Jun09
21495| [800581] CUPS IPP Packets Processing Denial of Service Vulnerability
21496| [800577] Microsoft Windows Server 2003 win32k.sys DoS Vulnerability
21497| [800566] Google Chrome Denial of Service Vulnerability
21498| [800551] Opera Web Browser XML Denial Of Service Vulnerability (Linux)
21499| [800550] Opera Web Browser XML Denial Of Service Vulnerability (Win)
21500| [800549] Apple Safari Denial of Service Vulnerability (Win) - Apr09
21501| [800544] JustSystems Ichitaro Products Denial Of Service Vulnerability
21502| [800541] Qip ICQ Message Denial Of Service Vulnerability
21503| [800505] Microsoft HTML Help Workshop buffer overflow vulnerability
21504| [800503] AyeView GIF Image Handling Denial of Service Vulnerability
21505| [800494] Apple QuickTime Multiple Denial Of Service Vulnerabilities (Win)
21506| [800490] OpenSSL 'kssl_keytab_is_available()' Denial Of Service Vulnerability (Win)
21507| [800487] CUPS 'scheduler/select.c' Denial Of Service Vulnerability
21508| [800486] Apple Safari 'SRC' Remote Denial Of Service Vulnerability
21509| [800485] Apple Safari 'background' Remote Denial Of Service Vulnerability
21510| [800481] Microsoft SharePoint Cross Site Scripting Vulnerability
21511| [800480] Microsoft Windows Media Player '.mpg' Buffer Overflow Vulnerability
21512| [800479] Aast! Antivirus 'aavmker4.sys' Denial Of Service Vulnerability (Win)
21513| [800473] Squid HTCP Packets Processing Denial of Service Vulnerability
21514| [800466] Microsoft Windows TLS/SSL Spoofing Vulnerability (977377)
21515| [800463] Asterisk T.38 Negotiation Remote Denial Of Service Vulnerability
21516| [800461] Microsoft Internet Explorer Information Disclosure Vulnerability (980088)
21517| [800460] Squid 'lib/rfc1035.c' Denial Of Service Vulnerability
21518| [800442] Microsoft Windows GP Trap Handler Privilege Escalation Vulnerability
21519| [800441] Kerberos5 KDC Cross Realm Referral Denial of Service Vulnerability
21520| [800429] Microsoft Internet Explorer Remote Code Execution Vulnerability (979352)
21521| [800423] Pidgin MSN Protocol Plugin Denial Of Service Vulnerability (Win)
21522| [800410] VMware Products vmware-authd Denial of Service Vulnerability (Win)
21523| [800395] Denial of Service vulnerability in AVG Anti-Virus (Linux)
21524| [800393] Denial Of Service Vulnerability in PHP April-09
21525| [800390] Firefox XUL Parsing Denial of Service Vulnerability (Linux)
21526| [800389] Firefox XUL Parsing Denial of Service Vulnerability (Win)
21527| [800382] Microsoft PowerPoint File Parsing Remote Code Execution Vulnerability (967340)
21528| [800374] Wireshark Denial of Service Vulnerability (Win)
21529| [800347] Microsoft Internet Explorer Clickjacking Vulnerability
21530| [800343] Microsoft Word 2007 Sensitive Information Disclosure Vulnerability
21531| [800337] Microsoft Internet Explorer NULL Pointer DoS Vulnerability
21532| [800332] Microsoft Windows Live Messenger Information Disclosure Vulnerability
21533| [800331] Microsoft Windows Live Messenger Client Version Detection
21534| [800328] Integer Overflow vulnerability in Microsoft Windows Media Player
21535| [800327] BreakPoint Software Hex Workshop Denial of Service vulnerability
21536| [800325] F-PROT AV 'ELF' Header Denial of Service Vulnerability
21537| [800321] Norton Internet Security Denial of Service Vulnerability
21538| [800306] MyServer Remote Denial of Service Vulnerability
21539| [800305] Sami FTP Server Multiple Commands Denial of Service Vulnerability
21540| [800267] Microsoft GDIPlus Library File Integer Overflow Vulnerability
21541| [800237] TitanFTP Server Denial of Service Vulnerability
21542| [800217] Microsoft Money Version Detection
21543| [800216] PGP Desktop Denial of Service Vulnerability
21544| [800213] VirusBlokAda Personal AV Denial of Service Vulnerability
21545| [800211] XM Easy Personal FTP Server Denial of Service Vulnerability
21546| [800209] Microsoft Internet Explorer Version Detection (Win)
21547| [800208] Microsoft Internet Explorer Anti-XSS Filter Vulnerabilities
21548| [800203] NOD32 Email Message Denial of Service Vulnerability
21549| [800195] A-V Tronics InetServ POP3 Denial Of Service Vulnerability
21550| [800194] Blackmoon FTP PORT Command Denial Of Service Vulnerability
21551| [800190] SolarFTP Server Multiple Commands Denial of Service Vulnerability
21552| [800187] MinaliC Webserver Denial of Service Vulnerability
21553| [800185] Zope Object Database ZEO Server Denial of Service Vulnerability
21554| [800184] OpenTTD Multiple use-after-free Denial of Service vulnerability
21555| [800183] Adobe Flash Media Server Multiple Denial of Service Vulnerabilities
21556| [800182] CUPS IPP Use-After-Free Denial of Service Vulnerability
21557| [800175] Xerver HTTP Server Web Administration Denial of Service Vulnerability
21558| [800161] Sun Java System Web Server Denial of Service Vulnerability (Win)
21559| [800139] K-Lite Mega Codec Pack vsfilter.dll Denial Of Service Vulnerability
21560| [800101] CA eTrust SCM Multiple HTTP Gateway Service Vulnerabilities
21561| [800083] Microsoft Outlook Express Malformed MIME Message DoS Vulnerability
21562| [800082] Microsoft SQL Server sp_replwritetovarbin() BOF Vulnerability
21563| [800079] ClamAV Remote Denial of Service Vulnerability
21564| [800074] Wireshark SMTP Processing Denial of Service Vulnerability (Win)
21565| [800064] Zope Python Scripts Local Denial of Service Vulnerability
21566| [800023] Microsoft Windows Image Color Management System Code Execution Vulnerability (952954)
21567| [103609] VMSA-2012-0016: VMware security updates for vSphere API and ESX Service Console
21568| [103512] Atlassian Crowd XML Parsing Denial of Service Vulnerability
21569| [103468] VMSA-2010-0009: ESXi utilities and ESX Service Console third party updates
21570| [103455] VMSA-2011-0012.3 VMware ESXi and ESX updates to third party libraries and ESX Service Console
21571| [103453] VMSA-2011-0004.3 VMware ESX/ESXi SLPD denial of service vulnerability and ESX third party updates for Service Console packages bind, pam, and rpm.
21572| [103450] VMSA-2011-0007 VMware ESXi and ESX Denial of Service and third party updates for Likewise components and ESX Service Console
21573| [103449] VMSA-2010-0016 VMware ESXi and ESX third party updates for Service Console and Likewise components
21574| [103448] VMSA-2012-0001 VMware ESXi and ESX updates to third party library and ESX Service Console
21575| [103411] Samba Memory Leak Local Denial Of Service Vulnerability
21576| [103383] PowerDNS Authoritative Server Remote Denial of Service Vulnerability
21577| [103370] Unbound Multiple Denial of Service Vulnerabilities
21578| [103369] ejabberd 'mod_pubsub' Module Denial of Service Vulnerability
21579| [103367] VxWorks Debugging Service Security-Bypass Vulnerability
21580| [103333] Apache HTTP Server 'ap_pregsub()' Function Local Denial of Service Vulnerability
21581| [103320] Squid Proxy Caching Server CNAME Denial of Service Vulnerability
21582| [103298] Samba 'etc/mtab' File Appending Local Denial of Service Vulnerability
21583| [103283] Samba 'mtab' Lock File Handling Local Denial of Service Vulnerability
21584| [103254] Microsoft SharePoint Server 2007 '_layouts/help.aspx' Cross Site Scripting Vulnerability
21585| [103209] Ingate SIParator SIP Module Remote Denial of Service Vulnerability
21586| [103208] Ingate Firewall SIP Module Remote Denial of Service Vulnerability
21587| [103192] Adobe Flash Media Server Memory Corruption Remote Denial of Service Vulnerability
21588| [103184] ManageEngine ServiceDesk Plus 'FILENAME' Parameter Directory Traversal Vulnerability
21589| [103183] ManageEngine ServiceDesk Plus Detection
21590| [103170] Unbound DNS Resolver Remote Denial of Service Vulnerability
21591| [103160] Serva32 Directory Traversal and Denial of Service Vulnerabilities
21592| [103159] LDAP Account Manager 'selfserviceSaveOk' Parameter Cross Site Scripting Vulnerability
21593| [103101] vsftpd FTP Server 'ls.c' Remote Denial of Service Vulnerability
21594| [103091] VicFTPS 'LIST' Command Remote Denial of Service Vulnerability
21595| [103090] ISC BIND 9 IXFR Transfer/DDNS Update Remote Denial of Service Vulnerability
21596| [103072] XM Easy Personal FTP Server 'TYPE' Command Remote Denial of Service Vulnerability
21597| [103065] Escortservice 'custid' Parameter SQL Injection Vulnerability
21598| [103050] Weborf 'get_param_value()' Function HTTP Header Handling Denial Of Service Vulnerability
21599| [103040] A-V Tronics InetServ SMTP Denial of Service Vulnerability
21600| [103037] Golden FTP Server Malformed Message Denial Of Service Vulnerability
21601| [103030] ISC BIND 9 'RRSIG' Record Type Negative Cache Remote Denial of Service Vulnerability
21602| [103020] PHP 'zend_strtod()' Function Floating-Point Value Denial of Service Vulnerability
21603| [103004] Mongoose 'Content-Length' HTTP Header Remote Denial Of Service Vulnerability
21604| [102059] Microsoft Windows Vector Markup Language Buffer Overflow (938127)
21605| [102055] Microsoft Windows GDI Multiple Vulnerabilities (925902)
21606| [102053] Microsoft Windows Vector Markup Language Vulnerabilities (929969)
21607| [102051] Kaspersky Antivirus UPX Denial of Service vulnerability
21608| [102050] Avast! Zoo Denial of Service Vulnerability
21609| [102049] Panda AntiVirus Zoo Denial of Service Vulnerability
21610| [102019] FileZilla Server Port Command Denial of Service
21611| [102016] SMB Enumerate Services
21612| [102015] Microsoft RPC Interface Buffer Overrun (KB824146)
21613| [101102] Vulnerability in Workstation Service Could Allow Elevation of Privilege (971657)
21614| [101100] Vulnerabilities in Microsoft ATL Could Allow Remote Code Execution (973908)
21615| [101025] Leap CMS service detection
21616| [101021] Opentaps ERP + CRM service detection
21617| [101019] Apache Open For Business service detection
21618| [101018] Windows SharePoint Services detection
21619| [101017] Microsoft MS03-018 security check
21620| [101016] Microsoft MS03-022 security check
21621| [101015] Microsoft MS03-034 security check
21622| [101014] Microsoft MS00-078 security check
21623| [101012] Microsoft MS03-051 security check
21624| [101010] Microsoft Security Bulletin MS05-004
21625| [101009] Microsoft Security Bulletin MS06-033
21626| [101007] Microsoft dotNET version grabber
21627| [101006] Microsoft Security Bulletin MS06-056
21628| [101005] Microsoft Security Bulletin MS07-040
21629| [101004] Microsoft MS04-017 security check
21630| [101003] Microsoft MS00-058 security check
21631| [101000] Microsoft MS00-060 security check
21632| [100952] Microsoft IIS FTPd NLST stack overflow
21633| [100950] Microsoft DNS server internal hostname disclosure detection
21634| [100949] HttpBlitz Server HTTP Request Remote Denial of Service Vulnerability
21635| [100918] NCH Software Office Intercom SIP Invite Remote Denial of Service Vulnerability
21636| [100904] IBM WebSphere Application Server JAX-WS Denial Of Service Vulnerability
21637| [100878] Weborf HTTP Request Denial Of Service Vulnerability
21638| [100872] MinaliC Directory Traversal and Denial of Service Vulnerabilities
21639| [100861] IBM solidDB Multiple Denial of Service Vulnerabilities
21640| [100834] Novell eDirectory Server Malformed Index Denial Of Service Vulnerability
21641| [100831] ISC BIND Denial Of Service and Security Bypass Vulnerability
21642| [100830] ClamAV 'find_stream_bounds()' PDF File Processing Denial Of Service Vulnerability
21643| [100821] OTRS Core System Multiple Cross-Site Scripting and Denial of Service Vulnerabilities
21644| [100798] MailEnable 'MESMTRPC.exe' SMTP Service Multiple Remote Denial of Service Vulnerabilities
21645| [100789] Squid Proxy String Processing NULL Pointer Dereference Denial Of Service Vulnerability
21646| [100779] Zope Unspecified Denial Of Service Vulnerability
21647| [100777] Wing FTP Server HTTP Request Denial Of Service Vulnerability
21648| [100767] Serv-U Denial of Service and Security Bypass Vulnerabilities
21649| [100759] SquirrelMail Remote Denial of Service Vulnerability
21650| [100758] ZNC Multiple Denial Of Service Vulnerabilities
21651| [100731] Wing FTP Server Denial of Service Vulnerability and Information Disclosure Vulnerability
21652| [100725] Apache HTTP Server Multiple Remote Denial of Service Vulnerabilities
21653| [100717] ISC BIND 9 'RRSIG' Record Type Remote Denial of Service Vulnerability
21654| [100703] Sun Java System Web Server Admin Interface Denial of Service Vulnerability
21655| [100691] Weborf HTTP Header Processing Denial Of Service Vulnerability
21656| [100690] Wing FTP Server 'PORT' Command Denial Of Service Vulnerability
21657| [100683] ZNC NULL Pointer Dereference Denial Of Service Vulnerability
21658| [100676] nginx Remote Source Code Disclosure and Denial of Service Vulnerabilities
21659| [100656] ClamAV 'parseicon()' Denial Of Service Vulnerability
21660| [100653] SolarWinds TFTP Server 'Read' Request (Opcode 0x01) Denial Of Service Vulnerability
21661| [100652] ClamAV 'cli_pdf()' PDF File Processing Denial Of Service Vulnerability
21662| [100644] Samba Multiple Remote Denial of Service Vulnerabilities
21663| [100642] SmallFTPD 'DELE' Command Remote Denial Of Service Vulnerability
21664| [100641] TYPSoft FTP Server 'RETR' Command Remote Denial Of Service Vulnerability
21665| [100633] Xitami '/AUX' Request Remote Denial Of Service Vulnerability
21666| [100626] ddrLPD Remote Denial of Service Vulnerability
21667| [100624] Microsoft Windows SMTP Server DNS spoofing vulnerability
21668| [100622] RealVNC 4.1.3 'ClientCutText' Message Remote Denial of Service Vulnerability
21669| [100612] NovaStor NovaNET Multiple Code Execution, Denial of Service, Information Disclosure Vulnerabilities
21670| [100588] OpenSSL 'dtls1_retrieve_buffered_fragment()' Remote Denial of Service Vulnerability
21671| [100587] OpenSSL 'ssl3_get_record()' Remote Denial of Service Vulnerability
21672| [100585] HTTP File Server Security Bypass and Denial of Service Vulnerabilities
21673| [100582] PHP FastCGI Module File Extension Denial Of Service Vulnerabilities
21674| [100581] PHP 'exif_read_data()' JPEG Image Processing Denial Of Service Vulnerability
21675| [100554] JINAIS IRC Message Remote Denial Of Service Vulnerability
21676| [100548] Remote Help HTTP GET Request Format String Denial Of Service Vulnerability
21677| [100534] httpdx Multiple Remote Denial Of Service Vulnerabilities
21678| [100532] FreeBSD and OpenBSD 'ftpd' NULL Pointer Dereference Denial Of Service Vulnerability
21679| [100531] Unbound 'sock_list' Structure Allocation Remote Denial Of Service Vulnerability
21680| [100529] PHP xmlrpc Extension Multiple Remote Denial of Service Vulnerabilities
21681| [100525] httpdx PNG File Handling Remote Denial of Service Vulnerability
21682| [100510] Sun Java System Directory Server LDAP Search Request Denial of Service Vulnerability
21683| [100499] Samba 'client/mount.cifs.c' Remote Denial of Service Vulnerability
21684| [100492] Novell eDirectory eMBox SOAP Request Denial Of Service Vulnerability
21685| [100487] ejabberd 'client2server' Message Remote Denial of Service Vulnerability
21686| [100480] lighttpd Slow Request Handling Remote Denial Of Service Vulnerability
21687| [100471] ircd-ratbox 'HELP' Command Denial Of Service Vulnerability
21688| [100447] Acme thttpd and mini_httpd Terminal Escape Sequence in Logs Command Injection Vulnerability
21689| [100446] Yaws Terminal Escape Sequence in Logs Command Injection Vulnerability
21690| [100445] Ruby WEBrick Terminal Escape Sequence in Logs Command Injection Vulnerability
21691| [100444] Orion Application Server Terminal Escape Sequence in Logs Command Injection Vulnerability
21692| [100443] Boa Webserver Terminal Escape Sequence in Logs Command Injection Vulnerability
21693| [100442] AOLServer Terminal Escape Sequence in Logs Command Injection Vulnerability
21694| [100441] nginx Terminal Escape Sequence in Logs Command Injection Vulnerability
21695| [100440] Cherokee Terminal Escape Sequence in Logs Command Injection Vulnerability
21696| [100438] Sun Java System Directory Server 'core_get_proxyauth_dn' Denial of Service Vulnerability
21697| [100412] Squid Header-Only Packets Remote Denial of Service Vulnerability
21698| [100399] NTP mode 7 MODE_PRIVATE Packet Remote Denial of Service Vulnerability
21699| [100397] Monkey HTTP Daemon Invalid HTTP 'Connection' Header Denial Of Service Vulnerability
21700| [100369] CUPS File Descriptors Handling Remote Denial Of Service Vulnerability
21701| [100366] Asterisk RTP Comfort Noise Processing Remote Denial of Service Vulnerability
21702| [100357] Cisco VPN Client for Windows 'StartServiceCtrlDispatche' Local Denial of Service Vulnerability
21703| [100351] Home FTP Server 'SITE INDEX' Command Remote Denial of Service Vulnerability
21704| [100347] ngIRCd SSL/TLS Support MOTD Request Multiple Denial Of Service Vulnerabilities
21705| [100342] XM Easy Personal FTP Server 'NLST' Command Remote Denial of Service Vulnerability
21706| [100340] Novell eDirectory NULL Base DN Denial Of Service Vulnerability
21707| [100338] Serv-U 'SITE SET TRANSFERPROGRESS ON' Command Remote Denial of Service Vulnerability
21708| [100320] Bftpd Unspecified Remote Denial of Service Vulnerability
21709| [100318] Cherokee Web Server Malformed Packet Remote Denial of Service Vulnerability
21710| [100305] Dopewars Server 'REQUESTJET' Message Remote Denial of Service Vulnerability
21711| [100298] Code-Crafters Ability Mail Server IMAP FETCH Request Remote Denial Of Service Vulnerability
21712| [100296] Xlpd Remote Denial of Service Vulnerability
21713| [100293] DataWizard FtpXQ Remote Denial of Service Vulnerability
21714| [100287] Mozilla Bugzilla 'Bug.create()' WebService Function SQL Injection Vulnerability
21715| [100286] Mozilla Bugzilla 'Bug.search()' WebService Function SQL Injection Vulnerability
21716| [100284] Cerberus FTP Server Long Command Remote Denial of Service Vulnerability
21717| [100283] Microsoft Windows SMB2 '_Smb2ValidateProviderCallback()' Remote Code Execution Vulnerability
21718| [100264] SolarWinds TFTP Server Option Acknowledgement Request Denial Of Service Vulnerability
21719| [100251] ISC BIND 9 Remote Dynamic Update Message Denial of Service Vulnerability
21720| [100249] Squid Multiple Remote Denial of Service Vulnerabilities
21721| [100207] Eggdrop 'ctcpbuf' Remote Denial Of Service Vulnerability
21722| [100198] TYPSoft FTP Server 'ABORT' Command Remote Denial of Service Vulnerability
21723| [100185] Quick 'n Easy Mail Server SMTP Request Remote Denial Of Service Vulnerability
21724| [100171] Apache Web Server Linefeed Memory Allocation Denial Of Service Vulnerability
21725| [100167] Zervit HTTP Server Malformed URI Remote Denial Of Service Vulnerability
21726| [100163] Home Web Server Graphical User Interface Remote Denial Of Service Vulnerability
21727| [100162] Mod_Perl Path_Info Remote Denial Of Service Vulnerability
21728| [100116] Horde Turba 'services/obrowser/index.php' HTML Injection Vulnerability
21729| [100111] Check for rexecd Service
21730| [100084] Squid Proxy Cache ICAP Adaptation Denial of Service Vulnerability
21731| [100081] Check for ident Service
21732| [100080] Check for rsh Service
21733| [100075] Check for echo Service
21734| [100062] Microsoft Remote Desktop Protocol Detection
21735| [90024] Windows Vulnerability in Microsoft Jet Database Engine
21736| [80056] ELOG Web LogBook global Denial of Service
21737| [80030] Packeteer PacketShaper Web Denial of Service
21738| [80007] Microsoft MS00-06 security check
21739| [80006] Sybase Enterprise Application Server service detection
21740| [80004] Firebase/Interbase database Server service detection
21741| [80003] FileMaker service detection
21742| [69366] avahi -- denial of service
21743| [66286] Identify unknown services with nmap
21744| [66063] django -- denial-of-service attack
21745| [66041] Fedora Core 11 FEDORA-2009-10466 (drupal-service_links)
21746| [66040] Fedora Core 10 FEDORA-2009-10445 (drupal-service_links)
21747| [64120] wireshark -- PCNFSD Dissector Denial of Service Vulnerability
21748| [62851] wireshark -- SMTP Processing Denial of Service Vulnerability
21749| [60229] FreeBSD Ports: ircservices
21750| [60016] Gentoo Security Advisory GLSA 200712-12 (ircservices)
21751| [58690] Debian Security Advisory DSA 1393-1 (xfce4-terminal)
21752| [58542] Gentoo Security Advisory GLSA 200708-07 (terminal)
21753| [54667] Gentoo Security Advisory GLSA 200409-10 (multi-gnome-terminal)
21754| [53941] Slackware Advisory SSA:2004-108-01 tcpdump denial of service
21755| [20890] Lotus Domino LDAP Server Denial of Service Vulnerability
21756| [20377] Windows Server Update Services detection
21757| [19777] Malformed ICMP Packets May Cause a Denial of Service (SCTP)
21758| [19304] Allegro Software RomPager 2.10 Denial of Service
21759| [18650] Sambar Search Results Buffer Overflow Denial of Service
21760| [18185] Kerio Winroute Firewall Admin Service
21761| [18184] Kerio Mailserver Admin Service
21762| [18183] Kerio Personal Firewall Admin Service
21763| [17975] Identify unknown services with GET
21764| [17602] FTPD glob (too many *) denial of service
21765| [17348] Jetty < 4.2.19 Denial of Service
21766| [17307] CA License Service Multiple Vulnerabilities
21767| [17296] Kill service with random data
21768| [15852] MailEnable IMAP Service Remote Buffer Overflows
21769| [15753] Multiple Vendor DNS Response Flooding Denial Of Service
21770| [15613] Hummingbird Connectivity FTP service XCWD Overflow
21771| [15487] MailEnable IMAP Service Search DoS Vulnerability
21772| [15467] Vulnerability in RPC Runtime Library Could Allow Information Disclosure and Denial of Service (873350)
21773| [15463] Squid remote denial of service
21774| [14838] myServer POST Denial of Service
21775| [14773] Identifies services like FTP, SMTP, NNTP...
21776| [14772] Service Detection (2nd pass)
21777| [14712] MailEnable SMTP Connector Service DNS Lookup DoS Vulnerability
21778| [14682] eZ/eZphotoshare Denial of Service
21779| [14664] external services identification
21780| [14656] MailEnable HTTPMail Service GET Overflow Vulnerability
21781| [14655] MailEnable HTTPMail Service Content-Length Overflow Vulnerability
21782| [14654] MailEnable HTTPMail Service Authorization Header DoS Vulnerability
21783| [14646] Xedus Denial of Service
21784| [14353] Music Daemon Denial of Service
21785| [14249] Opera web browser news url denial of service vulnerability
21786| [12280] Apache Connection Blocking Denial of Service
21787| [12267] Vulnerability in DirectPlay Could Allow Denial of Service (839643)
21788| [12105] Use LDAP search request to retrieve information from NT Directory Services
21789| [11992] Vulnerability in Microsoft ISA Server 2000 H.323 Filter(816458)
21790| [11905] Checkpoint Firewall-1 UDP denial of service
21791| [11896] DB2 discovery service DOS
21792| [11891] LinkSys EtherFast Router Denial of Service Attack
21793| [11888] Buffer Overrun in Messenger Service (828035)
21794| [11874] IIS Service Pack - 404
21795| [11825] Polycom ViaVideo denial of service
21796| [11808] Microsoft RPC Interface Buffer Overrun (823980)
21797| [11773] Linksys Gozila CGI denial of service
21798| [11517] Leafnode denials of service
21799| [11443] Microsoft IIS UNC Mapped Virtual Host Vulnerability
21800| [11217] Microsoft's SQL Version Query
21801| [11184] vxworks ftpd buffer overflow Denial of Service
21802| [11177] Flaw in Microsoft VM Could Allow Code Execution (810030)
21803| [11162] WebSphere Edge caching proxy denial of service
21804| [11159] MS RPC Services null pointer reference DoS
21805| [11154] Unknown services banners
21806| [11153] Identify unknown services with 'HELP'
21807| [11150] Tomcat servlet engine MS/DOS device names denial of service
21808| [11146] Microsoft RDP flaws could allow sniffing and DOS(Q324380)
21809| [11119] SMB Registry : XP Service Pack version
21810| [11089] Webseal denial of service
21811| [11067] Microsoft's SQL Hello Overflow
21812| [11059] Trend Micro OfficeScan Denial of service
21813| [10990] FTP Service Allows Any Username
21814| [10943] Cumulative Patch for Internet Information Services (Q327696)
21815| [10939] MSDTC denial of service by flooding with nul bytes
21816| [10866] XML Core Services patch (Q318203)
21817| [10862] Microsoft's SQL Server Brute Force
21818| [10848] Oracle 9iAS Dynamic Monitoring Services
21819| [10798] Unprotected PC Anywhere Service
21820| [10778] Unprotected SiteScope Service
21821| [10755] Microsoft Exchange Public Folders Information Leak
21822| [10736] DCE Services Enumeration
21823| [10680] Test Microsoft IIS Source Fragment Disclosure
21824| [10674] Microsoft's SQL UDP Info Query
21825| [10673] Microsoft's SQL Blank Password
21826| [10491] ASP/ASA source using Microsoft Translate f: bug
21827| [10330] Services
21828| [10326] Yahoo Messenger Denial of Service attack
21829| [10144] Microsoft SQL TCP/IP listener is running
21830| [10102] HotSync Manager Denial of Service attack
21831| [10033] CA Unicenter's Transport Service is running
21832| [10032] CA Unicenter's File Transfer Service is running
21833| [2497] IBM Lotus Domino Notes RPC Authentication Processing Denial of Service Vulnerability
21834|
21835| SecurityTracker - https://www.securitytracker.com:
21836| [1006447] Microsoft Windows Terminal Services RDP Implementation Does Not Validate Server Identity, Allowing Man-in-the-Middle Attacks
21837| [1005120] Microsoft Terminal Services Advanced Client (TSAC) ActiveX Control Buffer Overflow Lets Remote Users Execute Arbitrary Code
21838| [1004927] Microsoft Terminal Services Can Be Crashed By Remote Users Conducting a TCP SYN Scan in Certain Situations
21839| [1003591] Microsoft Windows Terminal Services May Cause the System's Screen Saver Lockout Mechanism to Fail in Certain Situations
21840| [1002754] Terminal Services on Microsoft Windows 2000 and XP Allow Remote Users to Log Bogus IP Addresses Instead of the User's Genuine Address
21841| [1002098] Windows Terminal Services in Microsoft Windows 2000 and NT 4.0 Can Be Crashed By Remote Users Due to a Memory Leak
21842| [1028908] Microsoft Active Directory Federation Services Discloses Account Information to Remote Users
21843| [1028905] (Microsoft Issues Fix for Exchange Server) Oracle Fusion Middleware Bugs Let Remote Users Deny Service and Access and Modify Data
21844| [1028904] (Microsoft Issues Fix for Exchange Server) Oracle PeopleSoft Products Bugs Let Remote Users Partially Access and Modify Data and Partially Deny Service
21845| [1028405] Microsoft Active Directory LDAP Processing Flaw Lets Remote Users Deny Service
21846| [1028278] Microsoft SharePoint Input Validation Flaws Permit Cross-Site Scripting and Denial of Service Attacks
21847| [1027949] Microsoft .NET Open Data (OData) Protocol Bug Lets Remote Users Deny Service
21848| [1027943] Microsoft XML Core Services (MSXML) XML Parsing Flaws Let Remote Users Execute Arbitrary Code
21849| [1027857] Microsoft Exchange Server RSS Feed Bug Lets Remote Users Deny Service
21850| [1027623] Microsoft SQL Server Input Validation Flaw in Reporting Services Permits Cross-Site Scripting Attacks
21851| [1027620] Microsoft Kerberos Null Pointer Dereference Lets Remote Users Deny Service
21852| [1027157] Microsoft XML Core Services (MSXML) Object Access Error Lets Remote Users Execute Arbitrary Code
21853| [1027048] Microsoft .NET Bugs Let Remote Users Execute Arbitrary Code and Deny Service
21854| [1026794] Microsoft DirectWrite Unicode Character Processing Flaw Lets Remote Users Deny Service
21855| [1026789] Microsoft DNS Server Lets Remote Users Deny Service
21856| [1026469] Microsoft ASP.NET Hash Table Collision Bug Lets Remote Users Deny Service
21857| [1026169] Microsoft Forefront Unified Access Gateway Input Validation Flaws Permits Cross-Site Scripting, HTTP Response Splitting, and Denial of Service Attacks
21858| [1026168] Microsoft Host Integration Server Bugs Let Remote Users Deny Service
21859| [1026037] Microsoft Windows Internet Name Service (WINS) Input Validation Flaw in ECommEndDlg() Lets Local Users Gain Elevated Privileges
21860| [1025937] Microsoft Windows DHCPv6 Processing Flaw Lets Remote Denial of Service to RPC Services
21861| [1025894] Microsoft DNS Server Flaws Let Remote Users Execute Arbitrary Code and Deny Service
21862| [1025653] Microsoft Active Directory Input Validation Flaw in Certificate Services Web Enrollment Permits Cross-Site Scripting Attacks
21863| [1025644] Microsoft Hyper-V VMBus Packet Validation Flaw Lets Local Users Deny Service
21864| [1025639] Microsoft Distributed File System Bugs Let Remote Users Deny Service and Execute Arbitrary Code
21865| [1025512] Microsoft Windows Internet Name Service Socket Send Exception Handling Bug Lets Remote Users Execute Arbitrary Code
21866| [1025312] Microsoft Windows Kernel Bug in AFD.sys Lets Local Users Deny Service
21867| [1025049] Microsoft Local Security Authority Subsystem Service (LSASS) Lets Local Users Gain Elevated Privileges
21868| [1025042] Microsoft Active Directory SPN Collosions May Let Remote Authenticated Users Deny Service
21869| [1024921] Microsoft IIS FTP Server Lets Remote Users Deny Service
21870| [1024888] Microsoft Exchange Server RPC Processing Flaw Lets Remote Authenticated Users Deny Service
21871| [1024884] Microsoft Hyper-V Input Validation Flaw Lets Local Guest Operating System Users Deny Service
21872| [1024790] Microsoft Outlook Attachment Processing Flaw Lets Remote Users Deny Service
21873| [1024558] Microsoft Cluster Service Disk Permission Flaw Lets Local Users Gain Elevated Privileges
21874| [1024496] Microsoft Internet Information Server (IIS) Web Server Stack Overflow in Reading POST Data Lets Remote Users Deny Service
21875| [1024443] Microsoft Local Security Authority Subsystem Service (LSASS) Heap Overflow Lets Remote Authenticated Users Execute Arbitrary Code
21876| [1024440] Microsoft Internet Information Services Bugs Let Remote Users Bypass Authentication, Deny Service, and Execute Arbitrary Code
21877| [1024312] Microsoft Windows Tracing Feature for Services Lets Local Users Gain Elevated Privileges
21878| [1024301] Microsoft XML Core Services (MSXML) HTTP Response Processing Flaw Lets Remote Users Execute Arbitrary Code
21879| [1024079] Microsoft Internet Information Services Memory Allocation Error Lets Remote Authenticated Users Execute Arbitrary Code
21880| [1024077] Microsoft SharePoint Help Page Processing Bug Lets Remote Users Deny Service
21881| [1023854] Microsoft Exchange Error in Parsing MX Records Lets Remote Users Deny Service
21882| [1023567] Microsoft Hyper-V Instruction Validation Bug Lets Local Users Deny Service
21883| [1023566] Microsoft Windows Kerberos Ticket-Granting-Ticket Processing Flaw Lets Remote Authenticated Users Deny Service
21884| [1023387] Microsoft Internet Information Services (IIS) Filename Extension Parsing Configuration Error May Let Users Bypass Security Controls
21885| [1023297] Microsoft Local Security Authority Subsystem Service Validation Flaw Lets Remote Users Deny Service
21886| [1023296] Microsoft Active Directory Federation Services Lets Remote Authenticated Users Execute Arbitrary Code and Spoof Web Sites
21887| [1023291] Microsoft Internet Authentication Service Bugs Let Remote Authenticated Users Execute Arbitrary Code or Gain Privileges of the Target User
21888| [1023156] Microsoft Active Directory Stack Memory Consumption Flaw Lets Remote Users Deny Service
21889| [1023154] Microsoft License Logging Service Buffer Overflow Lets Remote Users Execute Arbitrary Code
21890| [1023153] Microsoft Web Services on Devices API (WSDAPI) Validation Error Lets Remote Users Execute Arbitrary Code
21891| [1023011] Microsoft Indexing Service ActiveX Control Lets Remote Users Execute Arbitrary Code
21892| [1023010] Microsoft Local Security Authority Subsystem Service (LSASS) Integer Underflow Lets Local Users Deny Service
21893| [1022846] Microsoft Wireless LAN AutoConfig Service Heap Overflow Lets Remote Wireless Users Execute Arbitrary Code
21894| [1022792] Microsoft Internet Information Server (IIS) FTP Server Buffer Overflows Let Remote Authenticated Users Execute Arbitrary Code and Deny Service
21895| [1022715] Microsoft ASP.NET Request Scheduling Flaw Lets Remote Users Deny Service
21896| [1022710] Microsoft Windows Internet Name Service (WINS) Buffer Overflows Let Remote Users Execute Arbitrary Code
21897| [1022358] Microsoft Internet Information Services WebDAV Bug Lets Remote Users Bypass Authentication
21898| [1022349] Microsoft Active Directory Bugs Let Remote Users Execute Arbitrary Code or Deny Service
21899| [1022330] Microsoft Windows Bug in SETDESKWALLPAPER and GETDESKWALLPAPER Calls Let Local Users Deny Service
21900| [1022045] Microsoft ISA Server TCP State Error Lets Remote Users Deny Service
21901| [1021831] Microsoft DNS Server Bugs Let Remote Users Spoof the DNS Service
21902| [1021701] Microsoft Exchange MAPI Command Literal Processing Bug Lets Remote Users Deny Service
21903| [1021640] Solaris Pseudo-Terminal Driver Race Condition Lets Local Users Deny Service
21904| [1021294] Microsoft Office Communicator VoIP Processing Bugs Let Remote Users Deny Service
21905| [1021164] Microsoft XML Core Services (MSXML) Bugs Let Remote Users Obtain Information and Execute Arbitrary Code
21906| [1021020] Cisco Unity Bug in Microsoft API Lets Remote Users Deny Service
21907| [1020229] Microsoft Active Directory LDAP Validation Bug Lets Remote Users Deny Service
21908| [1020016] Microsoft Malware Protection Engine Lets Remote Users Deny Service
21909| [1019385] Microsoft Internet Information Services Error in Processing ASP Page Input Lets Remote Users Execute Arbitrary Code
21910| [1019384] Microsoft Internet Information Services File Change Notification Bug Lets Local Users Gain Elevated Privileges
21911| [1018942] Microsoft Windows DNS Service Insufficent Entropy Lets Remote Users Spoof the DNS Service
21912| [1018559] Microsoft Core XML Services Memory Corruption Error Lets Remote Users Execute Arbitrary Code
21913| [1018202] Microsoft GDI+ ICO File Divide By Zero Bug Lets Remote Users Deny Service
21914| [1018015] Microsoft Exchange Base64, iCal, IMAP, and Attachment Processing Bugs Let Remote Users Deny Service or Execute Arbitrary Code
21915| [1017910] Microsoft Windows DNS Service RPC Stack Overflow Lets Remote Users Execute Arbitrary Code
21916| [1017736] Microsoft Windows Explorer OLE Parsing Bug Lets Users Deny Service
21917| [1017488] Microsoft Outlook '.iCal', '.oss', and SMTP Header Bugs Let Remote Users Execute Arbitrary Code or Deny Service
21918| [1017441] Microsoft Windows Workstation Service Memory Allocation Error in NetrWkstaUserEnum() Lets Remote Users Deny Service
21919| [1017397] Microsoft Outlook Recipient ActiveX Control Lets Remote Users Deny Service
21920| [1017224] Microsoft Client Service for Netware Buffer Overflows Let Remote Users Execute Arbitrary Code and Crash the System
21921| [1017157] Microsoft XML Core Services ActiveX Control Lets Remote Users Execute Arbitrary Code
21922| [1017133] Microsoft NAT Helper 'ipnathlp.dll' Lets Remote Users Deny Service
21923| [1017033] Microsoft XML Core Services Lets Remote Users Execute Arbitrary Code or Obtain Information
21924| [1016827] Microsoft PGM Implementation Buffer Overflow in MSMQ Service Lets Remote Users Execute Arbitrary Code
21925| [1016047] Microsoft Distributed Transaction Coordinator Bugs Let Remote Users Deny Service
21926| [1015895] Microsoft SharePoint Team Services Input Validation Holes Permit Cross-Site Scripting Attacks
21927| [1015825] Microsoft ASP.NET Incorrect COM Component Reference Lets Remote Users Deny Service
21928| [1015794] (Vendor Issues Fix) Microsoft Internet Explorer 'mshtml.dll' Bug in Processing Multiple Action Handlers Lets Remote Users Deny Service
21929| [1015765] Microsoft Windows Services Have Unsafe Default ACLs That Let Remote Authenticated Users Gain Elevated Privileges
21930| [1015629] Microsoft Windows IGMP Processing Bug Lets Remote Users Deny Service
21931| [1015595] Microsoft Windows UPnP/NetBT/SCardSvr/SSDP Services May Be Incorrectly Configured By 3rd Party Applications, Allowing Local Users to Gain Elevated Privileges
21932| [1015559] Microsoft Internet Explorer Shockwave Flash Scripting Bug Lets Remote Users Deny Service
21933| [1015376] Microsoft IIS Lets Remote Users Deny Service or Execute Arbitrary Code With Malformed HTTP GET Requests
21934| [1015233] Microsoft Windows RPC Service May Let Remote Users Deny Service
21935| [1015049] Microsoft Internet Explorer Drag-and-Drop Timing May Let Remote Users Install Arbitrary Files
21936| [1015043] Microsoft Network Connection Manager Lets Remote Users Deny Service
21937| [1015041] Microsoft Client Service for NetWare Buffer Overflow Lets Remote Users Execute Arbitrary Code
21938| [1014642] Microsoft Windows Kerberos and PKINIT Vulnerabilities Allow Denial of Service, Information Disclosure, and Spoofing
21939| [1014639] Microsoft Windows Telephony Service Remote Code Execution or Local Privilege Escalation
21940| [1014638] Microsoft Windows Print Spooler Service Buffer Overflow Lets Remote Users Execute Arbitrary Code
21941| [1014500] Microsoft Internet Explorer (IE) JPEG Rendering Bugs Let Remote Users Deny Service or Execute Arbitrary Code
21942| [1014498] Microsoft Windows Remote Desktop Protocol Bug Lets Remote Users Deny Service
21943| [1014196] Microsoft Windows Buffer Overflow in Web Client Service Lets Remote Authenticated Users Execute Arbitrary Code
21944| [1013688] Microsoft Windows Kernel and Font Buffer Overflows Let Local Users Deny Service or Obtain System Privileges
21945| [1013686] Microsoft Windows TCP, IP, and ICMP Processing Errors Let Remote Users Deny Service and Execute Arbitrary Code
21946| [1013117] Microsoft Windows License Logging Service Lets Remote Users Execute Arbitrary Code
21947| [1013111] Microsoft SharePoint Services Redirection Query Input Validation Hole Lets Remote Users Conduct Cross-Site Scripting Attacks
21948| [1012683] Microsoft Windows ANI File Parsing Errors Let Remote Users Deny Service
21949| [1012518] Microsoft HyperTerminal Buffer Overflow Lets Remote Users Execute Arbitrary Code
21950| [1011880] Microsoft Windows XP Error in Explorer in Processing WAV Files Lets Remote Users Deny Service
21951| [1011645] Microsoft Various Operating System Flaws Lets Remote Users Execute Code and Local Users Gain Elevated Privileges or Deny Service
21952| [1011636] Microsoft SMTP Service Buffer Overflow in Processing DNS Responses May Let Remote Users Execute Arbitrary Code
21953| [1011633] Microsoft IIS WebDAV XML Message Handler Error Lets Remote Users Deny Service
21954| [1011632] Microsoft NT RPC Runtime Library Buffer Overflow Lets Remote Users Deny Service
21955| [1011200] F-Secure Anti-Virus for Microsoft Exchange Input Validation Bug in Content Scanner Server Lets Remote Users Deny Service
21956| [1009777] Microsoft SSL Library Input Validation Error Lets Remote Users Crash the Service
21957| [1009767] Microsoft Windows 2000 Domain Controller LDAP Flaw May Let Remote Users Restart the Authentication Service
21958| [1009762] Microsoft Windows COM Internet Services and RPC over HTTP Can Be Crashed By Remote Users
21959| [1009758] Microsoft Windows RCP Memory Leak Lets Remote Users Deny Service
21960| [1009751] Microsoft LSASS Service Buffer Overflow Lets Remote Users Execute Arbitrary Code With SYSTEM Privileges
21961| [1009673] Microsoft Windows XP 'mswebdvd.dll' Buffer Overflow Lets Remote Users Deny Service
21962| [1009359] Microsoft Windows Media Services Can Be Crashed By Remote Users
21963| [1009008] Microsoft Windows Internet Naming Service (WINS) Length Validation Flaw Lets Remote Users Deny Service
21964| [1008428] Microsoft ASP.NET Web Services XML Parsing Lets Remote Users Consume CPU Resources With SOAP Requests
21965| [1008324] Microsoft Exchange 2003 With Outlook Web Access and Windows SharePoint Services May Grant Incorrect E-mail Account Access to Remote Authenticated Users
21966| [1008148] Microsoft SharePoint Team Services Buffer Overflow May Let Remote Users Execute Arbitrary Code
21967| [1008146] Microsoft Windows Workstation Service (wkssvc.dll) Buffer Overflow Lets Remote Users Execute Arbitrary Code with System Privileges
21968| [1007933] Microsoft Windows Messenger Service Buffer Overflow Lets Remote Users Execute Arbitrary Code With Local System Privileges
21969| [1007922] Microsoft Windows RPC Multi-threaded Race Condition Lets Remote Users Crash the Service or Execute Arbitrary Code
21970| [1007750] Microsoft BizTalk Server Default Directory Permissions May Let Remote Users Deny Service
21971| [1007615] Microsoft Windows NetBIOS Name Service May Disclose Memory Contents to Remote Users
21972| [1007212] Microsoft Windows Remote Procedure Call (RPC) Service Buffer Overflow in Processing DCOM Requests Allows Remote Code Execution
21973| [1007206] Microsoft SMTP Service Can Be Crashed By Remote Users Sending Mail With an Invalid FILETIME Header
21974| [1007059] Microsoft Windows Media Services (nsiislog.dll) Extension to Internet Information Server (IIS) Has Another Buffer Overflow That Lets Remote Execute Arbitrary Code
21975| [1006867] Microsoft IIS Buffer Overflow Lets Remote Users With Upload Privileges Execute Code - Remote Users Can Also Crash the Service
21976| [1006866] Microsoft Windows Media Services (nsiislog.dll) Extension to Internet Information Server (IIS) Lets Remote Execute Arbitrary Code
21977| [1006534] Microsoft Proxy Service in Proxy Server 2.0 Has Unspecified Flaw That Lets Remote Users Stop Traffic
21978| [1006533] Microsoft Firewall Service in ISA Server Has Unspecified Flaw That Lets Remote Users Stop Traffic
21979| [1005986] Microsoft Windows Terminal Server MSGINA.DLL Flaw Lets Remote Authenticated Users Reboot the Server
21980| [1005964] Microsoft Locator Service Buffer Overflow Lets Remote Users Execute Arbitrary Code with System Level Privileges
21981| [1005674] Microsoft Internet Explorer Buffer Overflow in Processing PNG Images Allows Denial of Service Attacks
21982| [1005455] Microsoft Windows Remote Procedure Call (RPC) Service Null Pointer Dereference Allows Remote Users to Crash the Service
21983| [1005339] Microsoft Services for Unix Interix SDK Bugs May Allow Denial of Service Conditions or May Execute Arbitrary Code
21984| [1005296] Microsoft PPTP Service Buffer Overflow May Let Remote Users Execute Arbitrary Code
21985| [1004831] Microsoft Data Engine (MSDE) Buffer Overflow in Database Consistency Checker May Let Remote Authenticated Users Execute Arbitrary Code with the Privileges of the Database Service
21986| [1004830] Microsoft SQL Server Buffer Overflow in Database Consistency Checker May Let Remote Authenticated Users Execute Arbitrary Code with the Privileges of the Database Service
21987| [1004829] Microsoft SQL Server Resolution Service Buffer Overflows Let Remote Users Execute Arbitrary Code with the Privileges of the SQL Service
21988| [1004827] Microsoft Metadirectory Services Authentication Flaw May Let Remote Users Modify Data and Obtain Elevated Privileges on the System
21989| [1004757] Microsoft IIS SMTP Service Encapsulation Bug Lets Remote Users Relay Mail and Send SPAM Via the Service
21990| [1004542] Lumigent Log Explorer Buffer Overflow May Let Remote Users Crash the Microsoft SQL Server Service or Execute Arbitrary Code on the System
21991| [1004529] Microsoft Remote Access Service (RAS) Phonebook Buffer Overflow May Let Local Users Execute Arbitrary Code with Local System Privileges
21992| [1004486] Microsoft ASP.NET Buffer Overflow in Processing Cookies in StateServer Mode May Let Remote Users Crash the Service or Execute Arbitrary Code on the Server
21993| [1004407] Microsoft Exchange 2000 Flaw in Processing a Certain Malformed SMTP Command Allows Remote Users to Deny Service to the Server
21994| [1004290] Microsoft Internet Explorer Bugs in 'BGSOUND' and 'IFRAME' Tags Let Remote Users Create HTML That Will Cause Denial of Service Conditions or Will Access Special DOS Devices
21995| [1004083] Microsoft Windows 2000 'microsoft-ds' Service Flaw Allows Remote Users to Create Denial of Service Conditions By Sending Malformed Packets
21996| [1004032] Microsoft Internet Information Server (IIS) FTP STAT Command Bug Lets Remote Users Crash Both the FTP and the Web Services
21997| [1004031] Microsoft Internet Information Server (IIS) URL Length Bug Lets Remote Users Crash the Web Service
21998| [1003744] Microsoft SQL Server 'xp_dirtree' Buffer Overflow Lets Users Crash the Database Service
21999| [1003688] Microsoft Exchange Server 2000 Command Processing Bug Lets Remote Users Cause the SMTP Service to Crash
22000| [1003687] Microsoft Windows 2000 and Windows XP SMTP Service Command Processing Bug Lets Remote Users Cause the SMTP Service to Crash
22001| [1003686] Microsoft Windows SMTP Service Lets Remote Users Send or Relay Unauthorized Mail (including SPAM) Via the Server
22002| [1003634] Microsoft XML Core Services in SQL Server 2000 Lets Remote Scripts Access and Send Local Files
22003| [1003633] Microsoft XML Core Services in Microsoft Windows XP Operating System Lets Remote Scripts Access and Send Local Files
22004| [1003415] Microsoft Distributed Transaction Coordinator (MSDTC) Service Can Be Crashed By Remote Users
22005| [1003201] Microsoft Windows 95 Backup Utility Has Buffer Overflow That Could Cause Denial of Service Conditions
22006| [1003033] Microsoft C Runtime Format String Flaw Lets Remote Users Crash the Microsoft SQL Server Service
22007| [1002922] Microsoft Windows 2000 Internet Key Exchange (IKE) Service Can Be Crashed By Remote Users
22008| [1002731] Microsoft Windows 2000 RunAs Service May Disclose Authentication Credentials to Local Users
22009| [1002729] Microsoft Windows 2000 RunAs Service Allows Local Users to Disable the Service
22010| [1002728] Microsoft SQL Server May Disclose Database Passwords When Creating Data Transformation Service (DTS) Packages
22011| [1002581] Microsoft Terminal Servers Can Be Crashed By Remote Users Sending Certain Remote Desktop Protocol (RDP) Packets
22012| [1002394] Microsoft Windows NT Remote Procedure Call (RPC) Services Can Be Crashed With Malformed Packets
22013| [1002201] Microsoft Windows TCP/IP Stack Vulnerable to a Certain Man-in-the-Middle Denial of Service Attack
22014| [1002197] Microsoft Windows NNTP Network News Service Has a Memory Leak That Allows Remote Users to Cause the Server to Crash
22015| [1002105] Microsoft SQL Database Server RPC Input Validation Failure Lets Remote Users Crash the Database Service
22016| [1002104] Microsoft Exchange Server RPC Input Validation Failure Lets Remote Users Crash the Exchange Service
22017| [1002099] Microsoft Windows 2000 Telnet Service Can Be Crashed By Remote Users
22018| [1002075] Microsoft Services for Unix Memory Leak in Telnet and NFS Services Allows Remote Users to Crash the Operating System
22019| [1002028] Microsoft Exchange LDAP Service Can Be Crashed By Remote Users
22020| [1001931] Microsoft Windows 2000 SMTP Service May Allow Unauthorized Remote Users to Relay E-mail via the Service
22021| [1001537] Microsoft's Internet Information Server's FTP Services May Give Remote Users Information About User Account Names on the Server's Domain and Trusted Domains
22022| [1001535] Microsoft's Internet Information Server's FTP Services Can Be Crashed By Remote Users
22023| [1001513] Microsoft Windows 2000 Indexing Service Allows Remote Users to View Include Programming Files
22024| [1001123] Microsoft's FTP Server May Allow Remote Users to Deny Service on the Server
22025| [1001088] Microsoft Internet Explorer with Services for Unix 2.0 Can Create Malicious Files on the User's Host
22026|
22027| OSVDB - http://www.osvdb.org:
22028| [83751] Microsoft Windows Terminal Services LCA Issued Certificates Arbitrary Binary Signing Weakness
22029| [82693] Microsoft Windows Terminal Server Licensing Service MD5 Hash Collision Code Signing Spoofing
22030| [60368] Microsoft Windows Terminal Services msgina.dll Unrestricted Resource Lock Remote DoS
22031| [59733] Microsoft Windows 2000 Terminal Services Screensaver Screen Minimization Locking Weakness
22032| [59730] Microsoft Windows 2000 Terminal Services Disconnect Feature Local Privilege Escalation
22033| [56912] Microsoft Windows Terminal Services Client ActiveX Unspecified Overflow
22034| [36146] Microsoft Windows Terminal Services TLS Downgrade Weakness
22035| [29351] Microsoft Windows Terminal Services tsuserex.dll COM Object Instantiation
22036| [20001] Microsoft Windows 2000 Terminal Service Client Connection IP Logging Failure
22037| [15340] Microsoft Windows Server 2003 Terminal Service Client Print DoS
22038| [4877] Microsoft Windows Terminal Services Kerberos Double Authorization Data Entry
22039| [1990] Microsoft Windows Terminal Services False IP Address
22040| [1975] Microsoft Windows Terminal Server Service RDP Remote DoS
22041| [96181] Microsoft Active Directory Federation Services (AD FS) Open Endpoint Unspecified Account Information Disclosure
22042| [88964] Microsoft .NET Framework System.DirectoryServices.Protocols.SortRequestControl.GetValue() Method this.keys.Length Parameter Heap Buffer Overflow
22043| [88959] Microsoft XML Core Services Integer Truncation XML Handling Memory Corruption
22044| [88958] Microsoft XML Core Services Unspecified XSLT Handling Memory Corruption
22045| [88956] Microsoft Windows Printer Spooler Service Print Job Handling Memory Corruption
22046| [85418] Microsoft Windows Share Service File Handle Request Saturation Remote DoS
22047| [84602] Microsoft Windows Remote Desktop Services Malformed RDP Packet Parsing Remote Code Execution
22048| [84599] Microsoft Windows Print Spooler Service Remote Format String
22049| [83169] Microsoft Windows NT telnetd Service Port Scan Remote DoS
22050| [83126] Microsoft Windows NT Registry Plaintext Service Password Local Disclosure
22051| [82873] Microsoft XML Core Services Uninitalized Memory Object Handling Remote Code Execution
22052| [81903] Microsoft Office X for Macintosh Registration Service Remote Overflow DoS
22053| [80004] Microsoft Windows Remote Desktop Protocol Terminal Server RDP Packet Parsing Remote DoS
22054| [79442] Microsoft Windows Server 2008 DNS Server Service Cache Update Policy Deleted Domain Name Resolving Weakness
22055| [74402] Microsoft Windows Remote Access Service NDISTAPI Driver User Input Validation Weakness Local Privilege Escalation
22056| [74400] Microsoft Windows DNS Service Non-Existent Domain Query Parsing Remote DoS
22057| [74399] Microsoft Windows DNS Service NAPTR Query Parsing Overflow
22058| [72937] Microsoft Windows Active Directory Certificate Services Web Enrollment XSS
22059| [72936] Microsoft Windows Server Service Crafted SMB Request Parsing Remote DoS
22060| [72234] Microsoft Windows WINS Service Failed Response Data Reuse Memory Corruption Remote Code Execution
22061| [71780] Microsoft Windows DNS Client Service LLMNR Query Processing Remote Code Execution
22062| [70834] Microsoft Windows Kerberos Unkeyed Checksum Hashing Mechanism Service Ticket Forgery
22063| [69819] Microsoft Windows Netlogon RPC Service Crafted Request Remote DoS
22064| [68550] Microsoft Windows Media Player Network Sharing Service RTSP Use-after-free Remote Code Execution
22065| [67988] Microsoft Windows Print Spooler Service RPC Impersonation StartDocPrinter Procedure Remote Code Execution
22066| [67083] Microsoft Windows TAPI Server (TAPISRV) Service Isolation Bypass Local Privilege Escalation
22067| [66978] Microsoft Windows Tracing Feature for Services Registry String Handling Memory Corruption Local Privilege Escalation
22068| [66977] Microsoft Windows Tracing Feature for Services Registry Key ACL Local Privilege Escalation
22069| [66973] Microsoft XML Core Services Msxml2.XMLHTTP.3.0 ActiveX HTTP Response Handling Memory Corruption
22070| [63726] Microsoft Windows Media Unicast Service Transport Packet Handling Remote Overflow
22071| [60836] Microsoft Windows Active Directory Federation Services (ADFS) Request Header Handling Remote Code Execution
22072| [60835] Microsoft Windows Active Directory Federation Services (ADFS) Single Sign-on Spoofing
22073| [60833] Microsoft Windows Internet Authentication Service Crafted MS-CHAP v2 Message Remote Authentication Bypass
22074| [60832] Microsoft Windows Internet Authentication Service Protected Extensible Authentication Protocol (PEAP) Message Handling Remote Memory Corruption
22075| [59865] Microsoft Windows Web Services on Devices API (WSDAPI) Message Header Handling Memory Corruption
22076| [59479] Microsoft Office SharePoint Server Team Services _layouts/download.aspx Multiple Parameter ASP.NET Source Disclosure
22077| [58854] Microsoft Windows Indexing Service ActiveX Memory Corruption Arbitrary Code Execution
22078| [57806] Microsoft Windows Wireless LAN AutoConfig Service (wlansvc) Frame Parsing Arbitrary Code Execution
22079| [56902] Microsoft Windows Workstation Service NetrGetJoinInformation Function Local Memory Corruption Arbitrary Code Execution
22080| [56901] Microsoft Windows Message Queuing Service (MSMQ) mqac.sys IOCTL Request Parsing Local Privilege Escalation
22081| [56900] Microsoft Windows Internet Name Service (WINS) Network Packet Handling Remote Integer Overflow
22082| [56899] Microsoft Windows Internet Name Service (WINS) Push Request Handling Remote Overflow
22083| [56438] Microsoft XML Core Services Set-Cookie HTTP Response Header Restriction Weakness
22084| [53667] Microsoft Windows RPCSS Service Isolation Local Privilege Escalation
22085| [53666] Microsoft Windows Management Instrumentation (WMI) Service Isolation Local Privilege Escalation
22086| [53621] Microsoft Windows HTTP Services Digital Certificate Distinguished Name Mismatch Weakness
22087| [53620] Microsoft Windows HTTP Services Web Server Response Unspecified Integer Underflow
22088| [53619] Microsoft Windows HTTP Services NTLM Credential Replay Privileged Code Execution
22089| [52693] Microsoft Windows Mobile Bluetooth Stack OBEX FTP Service Traversal Arbitrary File Manipulation
22090| [50558] Microsoft Windows Media Component Service Principal Name (SPN) Credential Reflection Arbitrary Code Execution
22091| [50533] Microsoft Windows Media Services nskey.dll ActiveX CallHTMLHelp Method Overflow
22092| [50279] Microsoft XML Core Services HTTP Request Header Field Cross-domain Session State Manipulation
22093| [49926] Microsoft XML Core Services DTD Crafted XML Document Handling Cross-Domain Scripting Remote Information Disclosure
22094| [49729] Microsoft Internet Authentication Service (IAS) Helper COM Component ActiveX (iashlpr.dll) PutProperty Method Remote DoS
22095| [49243] Microsoft Windows Server Service Crafted RPC Request Handling Unspecified Remote Code Execution
22096| [49060] Microsoft Windows Message Queuing Service RPC Request Handling Remote Code Execution
22097| [49059] Microsoft IIS IPP Service Unspecified Remote Overflow
22098| [46063] Microsoft Windows Internet Name Service (WINS) Packet Handling Local Privilege Escalation
22099| [45027] Microsoft Malware Protection Engine File Parsing Service DoS
22100| [41092] Microsoft Windows DNS Service Predictable Transaction ID Weakness
22101| [36935] Microsoft Windows Services for UNIX Local Privilege Escalation
22102| [36394] Microsoft XML Core Services (MSXML) Multiple Object Handling Overflow
22103| [35961] Microsoft Windows Active Directory LDAP Service Crafted Request Remote DoS
22104| [35960] Microsoft Windows Active Directory LDAP Service Convertible Attribute Remote Code Execution
22105| [35956] Microsoft .NET Framework Just In Time (JIT) Compiler Service Unspecified Arbitrary Code Execution
22106| [35954] Microsoft .NET Framework PE Loader Service Unspecified Arbitrary Code Execution
22107| [34404] Microsoft IE Media Service Component Arbitrary File Rewrite
22108| [32445] Microsoft Windows Workstation Service NetrWkstaUserEnum RPC Request DoS
22109| [31889] Microsoft Windows XP SP2 Image Aquisition Service Local Privilege Escalation
22110| [30817] Microsoft Windows Remote Installation Service TFTP Arbitrary File Overwrite
22111| [30811] Microsoft Windows SNMP Service Remote Overflow
22112| [30263] Microsoft Windows Workstation Service Crafted Message Remote Overflow
22113| [30261] Microsoft Windows Client Service for NetWare (CSNW) Crafted Message Remote DoS
22114| [30260] Microsoft Windows Client Service for NetWare (CSNW) Crafted Message Remote Code Execution
22115| [29439] Microsoft Windows Server Service Crafted SMB Packet Unspecified Issue
22116| [29426] Microsoft XML Core Services XSLT Processing Overflow
22117| [29425] Microsoft XML Core Services XMLHTTP ActiveX Control Server-side Redirect Information Disclosure
22118| [29412] Microsoft Terminal Server Explorer Error Arbitrary Code Execution
22119| [28729] Microsoft Windows Indexing Service Unspecified XSS
22120| [27845] Microsoft Windows Server Service Crafted RPC Message Remote Overflow
22121| [27844] Microsoft Windows DNS Client Service Record Response Overflow
22122| [27155] Microsoft Windows Server Service SRV.SYS Crafted Request SMB Information Disclosure
22123| [27154] Microsoft Windows Server Service SRV.SYS First-class Mailslot Message Remote Overflow
22124| [27151] Microsoft Windows DHCP Client Service Crafted Response Overflow
22125| [23134] Microsoft Windows Web Client Service Crafted WebDAV Request Overflow
22126| [23047] Microsoft Windows SSDP SERVICE_CHANGE_CONFIG Permission Weakness Privilege Escalation
22127| [23046] Microsoft Windows SCardSvr SERVICE_CHANGE_CONFIG Permission Weakness Privilege Escalation
22128| [23045] Microsoft Windows NetBT SERVICE_CHANGE_CONFIG Permission Weakness Privilege Escalation
22129| [23044] Microsoft Windows UPnP SERVICE_CHANGE_CONFIG Permission Weakness Privilege Escalation
22130| [19994] Microsoft Windows 2000 audit directory service access 565 Event Logging Failure
22131| [19922] Microsoft Windows Client Service for NetWare (CSNW) Remote Overflow
22132| [18607] Microsoft Windows Print Spooler Service Remote Overflow
22133| [18605] Microsoft Windows Plug-and-Play Service Remote Overflow
22134| [17885] Microsoft Windows Network Connections Service netman.dll Remote DoS
22135| [17859] Microsoft Windows NULL Session svcctl MSRPC Interface SCM Service Enumeration
22136| [15338] Microsoft Windows Server 2003 Terminal Session Close DoS
22137| [14509] Microsoft Services for Unix Malformed RPC Client Fragment Packet DoS
22138| [14497] Microsoft Services for Unix RPC Library Malformed Packet Fragment DoS
22139| [14430] Microsoft Commerce Server 2000 Profile Service Affected API Overflow
22140| [13762] Microsoft 2000 Domain Controller Directory Service Restore Mode Blank Password
22141| [13599] Microsoft Windows License Logging Service Overflow
22142| [13595] Microsoft Windows Sharepoint Services HTML Redirection XSS
22143| [13475] Microsoft Windows 2000 Telnet Service Predictable Named Pipe Arbitrary Command Execution Variant
22144| [13474] Microsoft Windows 2000 Telnet Service Predictable Named Pipe Arbitrary Command Execution
22145| [13472] Microsoft Services for Unix Telnet Service Memory Consumption DoS
22146| [13471] Microsoft Services for Unix NFS Service Memory Consumption DoS
22147| [13423] Microsoft Windows 2000 Terminal Server SYSVOL Share Connection Saturation Restriction Bypass
22148| [13422] Microsoft Windows PPTP Service Malformed Control Data Overflow
22149| [12832] Microsoft Windows Indexing Service Query Overflow
22150| [12374] Microsoft Windows HyperTerminal Session File Remote Overflow
22151| [11797] Microsoft Windows DCOM RPCSS Service DCERPC Packet Overflow
22152| [11473] Microsoft Windows NT Messenger Service Long Username DoS
22153| [11461] Microsoft Windows Workstation Service WKSSVC.DLL Logging Function Remote Overflow
22154| [11268] Microsoft Exchange Internet Mail Service AUTH/AUTHINFO Command DoS
22155| [11157] Microsoft IIS FTP Service PASV Connection Saturation DoS
22156| [10936] Microsoft Windows Messenger Service Message Length Remote Overflow
22157| [10247] Microsoft Windows SMTP Service NTLM Null Session Mail Relay
22158| [9856] Xylogics Annex Terminal Service ping CGI Program DoS
22159| [7905] Microsoft IE ie5setup.exe Multple Service Disable
22160| [7881] Microsoft Java Implementation INativeServices Clipboard Content Disclosure
22161| [7880] Microsoft Java INativeServices Arbitrary Memory Information Disclosure
22162| [7182] Microsoft Windows Media Unicast Service Severed Connection Memory Leak DoS
22163| [5936] Microsoft SMTP Service 4xx Error Code DoS
22164| [5686] Microsoft Windows Telnet Service Account Information Disclosure
22165| [5133] Microsoft Metadirectory Services LDAP Client Authentication Bypass
22166| [4578] Microsoft SQL Resolution Service Monitor Thread Registry Key Name Overflow
22167| [4577] Microsoft SQL Resolution Service 0x08 Byte Long String Overflow
22168| [4535] Microsoft Media Services ISAPI nsiislog.dll POST Overflow
22169| [4170] Microsoft Windows 2000 Server Media Services TCP Packet Handling Remote DoS
22170| [2960] Microsoft Windows Messenger Service Social Engineering Weakness
22171| [2657] Microsoft Windows Message Queuing Service Heap Overflow
22172| [2535] Microsoft Windows DCOM RPCSS Service Filename Parameter Overflow
22173| [2247] Microsoft Windows Media Services Remote Command Execution #2
22174| [2106] Microsoft Media Services ISAPI nsiislog.dll Overflow
22175| [1933] Microsoft ISA Server Proxy Service Memory Leak DoS
22176| [1912] Microsoft Windows Terminal Server Malformed RDP DoS
22177| [1860] Microsoft Windows Telnet Service Handle Leak DoS
22178| [1858] Microsoft Windows Telnet Service Logon Backspace DoS
22179| [1639] Microsoft Windows NT Terminal Server RegAPI.DLL Username Overflow
22180| [1621] Microsoft Indexing Services for Windows 2000 .htw XSS
22181| [1546] Microsoft Windows Media Unicast Service Malformed Request DoS
22182| [1268] Microsoft Windows TCP/IP Printing Service DoS
22183| [1209] Microsoft Terminal Server rdisk Registry Information Disclosure
22184| [1135] Microsoft Windows NT Print Spooler Service (spoolss.exe) AddPrintProvider() Function Alternate Print Provider Arbitrary Command Execution
22185| [967] Microsoft Windows NT WINS Service Malformed Data DoS
22186| [878] Microsoft SQL Resolution Service Keep-Alive Function DoS
22187| [732] Microsoft Windows SMTP Service Malformed BDAT Request Remote DoS
22188| [463] Microsoft IIS Phone Book Service /pbserver/pbserver.dll Remote Overflow
22189| [403] Microsoft Windows 2000 Still Image Service WM_USER Message Local Overflow
22190| [304] Microsoft Windows NT service pack level via remote registry access
22191|_
22192Device type: general purpose|WAP
22193Running (JUST GUESSING): Linux 2.6.X|2.4.X (90%), Microsoft Windows 2012 (85%)
22194OS CPE: cpe:/o:linux:linux_kernel:2.6 cpe:/o:linux:linux_kernel:2.4.20 cpe:/o:microsoft:windows_server_2012:r2
22195OS fingerprint not ideal because: Didn't receive UDP response. Please try again with -sSU
22196Aggressive OS guesses: Linux 2.6.18 - 2.6.22 (90%), Tomato 1.27 - 1.28 (Linux 2.4.20) (86%), Microsoft Windows Server 2012 or Windows Server 2012 R2 (85%), Microsoft Windows Server 2012 R2 (85%)
22197No exact OS matches for host (test conditions non-ideal).
22198TCP/IP fingerprint:
22199SCAN(V=7.70%E=4%D=7/26%OT=80%CT=25%CU=%PV=N%G=N%TM=5D3A8A14%P=x86_64-pc-linux-gnu)
22200SEQ(SP=108%GCD=1%ISR=10E%TI=I%CI=Z%TS=7)
22201OPS(O1=M44FNW8ST11%O2=M44FNW8ST11%O3=M44FNW8NNT11%O4=M44FNW8ST11%O5=M44FNW8ST11%O6=M44FST11)
22202WIN(W1=2000%W2=2000%W3=2000%W4=2000%W5=2000%W6=2000)
22203ECN(R=Y%DF=Y%TG=80%W=2000%O=M44FNW8NNS%CC=Y%Q=)
22204T1(R=Y%DF=Y%TG=80%S=O%A=S+%F=AS%RD=0%Q=)
22205T2(R=N)
22206T3(R=N)
22207T4(R=N)
22208T5(R=Y%DF=Y%TG=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)
22209T6(R=Y%DF=Y%TG=40%W=0%S=A%A=Z%F=R%O=%RD=0%Q=)
22210T7(R=N)
22211U1(R=N)
22212IE(R=N)
22213
22214Uptime guess: 77.091 days (since Thu May 9 22:53:42 2019)
22215TCP Sequence Prediction: Difficulty=264 (Good luck!)
22216IP ID Sequence Generation: Incremental
22217Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows
22218
22219TRACEROUTE (using proto 1/icmp)
22220HOP RTT ADDRESS
222211 164.97 ms 10.250.200.1
222222 166.06 ms 213.184.122.97
222233 165.04 ms bzq-82-80-246-9.cablep.bezeqint.net (82.80.246.9)
222244 226.82 ms bzq-219-189-185.cablep.bezeqint.net (62.219.189.185)
222255 165.56 ms bzq-114-65-2.cust.bezeqint.net (192.114.65.2)
222266 165.61 ms bzq-179-124-82.cust.bezeqint.net (212.179.124.82)
222277 227.02 ms bzq-179-124-118.cust.bezeqint.net (212.179.124.118)
222288 221.60 ms ae9.cr1-lon2.ip4.gtt.net (46.33.89.185)
222299 289.07 ms et-10-1-0.cr4-nyc2.ip4.gtt.net (213.254.214.14)
2223010 289.49 ms a100-gw.ip4.gtt.net (173.205.58.70)
2223111 298.60 ms 52.93.1.89
2223212 288.53 ms 52.93.1.56
2223313 ... 17
2223418 295.20 ms 52.93.132.142
2223519 ... 28
2223629 320.07 ms 52.93.28.184
2223730 ...
22238
22239NSE: Script Post-scanning.
22240NSE: Starting runlevel 1 (of 2) scan.
22241Initiating NSE at 01:05
22242Completed NSE at 01:05, 0.00s elapsed
22243NSE: Starting runlevel 2 (of 2) scan.
22244Initiating NSE at 01:05
22245Completed NSE at 01:05, 0.00s elapsed
22246Read data files from: /usr/bin/../share/nmap
22247OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
22248Nmap done: 1 IP address (1 host up) scanned in 259.09 seconds
22249 Raw packets sent: 140 (10.088KB) | Rcvd: 41 (3.020KB)
22250######################################################################################################################################
22251Starting Nmap 7.70 ( https://nmap.org ) at 2019-07-26 01:05 EDT
22252NSE: Loaded 45 scripts for scanning.
22253NSE: Script Pre-scanning.
22254Initiating NSE at 01:05
22255Completed NSE at 01:05, 0.00s elapsed
22256Initiating NSE at 01:05
22257Completed NSE at 01:05, 0.00s elapsed
22258Initiating Parallel DNS resolution of 1 host. at 01:05
22259Completed Parallel DNS resolution of 1 host. at 01:05, 0.02s elapsed
22260Initiating UDP Scan at 01:05
22261Scanning ec2-52-44-246-60.compute-1.amazonaws.com (52.44.246.60) [14 ports]
22262Completed UDP Scan at 01:05, 2.59s elapsed (14 total ports)
22263Initiating Service scan at 01:05
22264Scanning 12 services on ec2-52-44-246-60.compute-1.amazonaws.com (52.44.246.60)
22265Service scan Timing: About 8.33% done; ETC: 01:24 (0:17:47 remaining)
22266Completed Service scan at 01:07, 102.60s elapsed (12 services on 1 host)
22267Initiating OS detection (try #1) against ec2-52-44-246-60.compute-1.amazonaws.com (52.44.246.60)
22268Retrying OS detection (try #2) against ec2-52-44-246-60.compute-1.amazonaws.com (52.44.246.60)
22269Initiating Traceroute at 01:07
22270Completed Traceroute at 01:07, 7.20s elapsed
22271Initiating Parallel DNS resolution of 1 host. at 01:07
22272Completed Parallel DNS resolution of 1 host. at 01:07, 0.00s elapsed
22273NSE: Script scanning 52.44.246.60.
22274Initiating NSE at 01:07
22275Completed NSE at 01:07, 7.24s elapsed
22276Initiating NSE at 01:07
22277Completed NSE at 01:07, 1.30s elapsed
22278Nmap scan report for ec2-52-44-246-60.compute-1.amazonaws.com (52.44.246.60)
22279Host is up (0.17s latency).
22280
22281PORT STATE SERVICE VERSION
2228253/udp open|filtered domain
2228367/udp open|filtered dhcps
2228468/udp open|filtered dhcpc
2228569/udp open|filtered tftp
2228688/udp open|filtered kerberos-sec
22287123/udp open|filtered ntp
22288137/udp filtered netbios-ns
22289138/udp filtered netbios-dgm
22290139/udp open|filtered netbios-ssn
22291161/udp open|filtered snmp
22292162/udp open|filtered snmptrap
22293389/udp open|filtered ldap
22294520/udp open|filtered route
222952049/udp open|filtered nfs
22296Too many fingerprints match this host to give specific OS details
22297
22298TRACEROUTE (using port 138/udp)
22299HOP RTT ADDRESS
223001 164.94 ms 10.250.200.1
223012 ... 3
223024 165.76 ms 10.250.200.1
223035 165.63 ms 10.250.200.1
223046 165.62 ms 10.250.200.1
223057 165.60 ms 10.250.200.1
223068 165.58 ms 10.250.200.1
223079 165.57 ms 10.250.200.1
2230810 165.56 ms 10.250.200.1
2230911 ... 18
2231019 163.68 ms 10.250.200.1
2231120 163.78 ms 10.250.200.1
2231221 ... 27
2231328 165.47 ms 10.250.200.1
2231429 ...
2231530 163.81 ms 10.250.200.1
22316
22317NSE: Script Post-scanning.
22318Initiating NSE at 01:07
22319Completed NSE at 01:07, 0.00s elapsed
22320Initiating NSE at 01:07
22321Completed NSE at 01:07, 0.00s elapsed
22322Read data files from: /usr/bin/../share/nmap
22323OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
22324Nmap done: 1 IP address (1 host up) scanned in 127.47 seconds
22325 Raw packets sent: 147 (9.964KB) | Rcvd: 21 (1.634KB)
22326######################################################################################################################################
22327Hosts
22328=====
22329
22330address mac name os_name os_flavor os_sp purpose info comments
22331------- --- ---- ------- --------- ----- ------- ---- --------
2233252.44.246.60 ec2-52-44-246-60.compute-1.amazonaws.com Linux 2.6.X server
22333
22334Services
22335========
22336
22337host port proto name state info
22338---- ---- ----- ---- ----- ----
2233952.44.246.60 25 tcp smtp closed
2234052.44.246.60 53 udp domain unknown
2234152.44.246.60 67 udp dhcps unknown
2234252.44.246.60 68 udp dhcpc unknown
2234352.44.246.60 69 udp tftp unknown
2234452.44.246.60 80 tcp http open Microsoft HTTPAPI httpd 2.0 SSDP/UPnP
2234552.44.246.60 88 udp kerberos-sec unknown
2234652.44.246.60 123 udp ntp unknown
2234752.44.246.60 137 udp netbios-ns filtered
2234852.44.246.60 138 udp netbios-dgm filtered
2234952.44.246.60 139 tcp netbios-ssn closed
2235052.44.246.60 139 udp netbios-ssn unknown
2235152.44.246.60 161 udp snmp unknown
2235252.44.246.60 162 udp snmptrap unknown
2235352.44.246.60 389 udp ldap unknown
2235452.44.246.60 443 tcp ssl/http open Microsoft IIS httpd 8.5
2235552.44.246.60 445 tcp microsoft-ds closed
2235652.44.246.60 520 udp route unknown
2235752.44.246.60 2049 udp nfs unknown
2235852.44.246.60 3389 tcp ms-wbt-server open Microsoft Terminal Service
22359#######################################################################################################################################
22360 Anonymous JTSEC #OpTrump Full Recon #2