CVEs (515)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 5Windows 2000 Windows 2003 ServerWindows Server 2008+2 moreApr 23, 2026 Nov 11, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 win32k.sys in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not correctly parse font code during construction of a directory-entry table, which allows remote attackers to execute arbi...Show more |
1Microsoft 5Windows 2000 Windows 2003 ServerWindows Server 2008+2 moreApr 23, 2026 Nov 11, 2009 N/A· v4 N/A· v3 7.2 HIGH· v2 The Graphics Device Interface (GDI) in win32k.sys in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 does not properly validate user-mode...Show more |
1Microsoft 5Windows 2000 Windows 2003 ServerWindows Server 2008+2 moreApr 23, 2026 Nov 11, 2009 N/A· v4 N/A· v3 7.8 HIGH· v2 Stack consumption vulnerability in the LDAP service in Active Directory on Microsoft Windows 2000 SP4, Server 2003 SP2, and Server 2008 Gold and SP2; Active Directory Application Mode (ADAM) on Windows XP SP2 and SP3 and...Show more |
1Microsoft 5Windows 2000 Windows 2003 ServerWindows Server 2008+2 moreApr 23, 2026 Nov 11, 2009 N/A· v4 N/A· v3 7.2 HIGH· v2 win32k.sys in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 does not correctly validate an argument to an unspecified system call, which...Show more |
1Microsoft 7Internet Explorer Windows 2000Windows 7+4 moreApr 23, 2026 Oct 14, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is de...Show more |
1Microsoft 7Internet Explorer Windows 2000Windows 7+4 moreApr 23, 2026 Oct 14, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is de...Show more |
1Microsoft 7Internet Explorer Windows 2000Windows 7+4 moreApr 23, 2026 Oct 14, 2009 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, 7, and 8 does not properly handle argument validation for unspecified variables, which allows remote attackers to execute arbitrary code via a crafted HTML document, aka "H...Show more |
1Microsoft 7Windows 2000 Windows Media Format RuntimeWindows Media Player+4 moreApr 23, 2026 Oct 14, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 Microsoft Windows Media Runtime, as used in DirectShow WMA Voice Codec, Windows Media Audio Voice Decoder, and Audio Compression Manager (ACM), does not properly initialize unspecified functions within compressed audio f...Show more |
1Microsoft 5Windows 2000 Windows Server 2003Windows Server 2008+2 moreApr 23, 2026 Oct 14, 2009 N/A· v4 7.1 HIGH· v3 6.9 MEDIUM· v2 The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold and SP1, and Server 2008 Gold does not properly validate data sent from user mode, which allows local users to gain privileges via a c...Show more |
1Microsoft 5Windows 2000 Windows Server 2003Windows Server 2008+2 moreApr 23, 2026 Oct 14, 2009 N/A· v4 N/A· v3 7.2 HIGH· v2 Integer underflow in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows local users to gain privileges via a crafted application that...Show more |
1Microsoft 6Windows 2000 Windows 7Windows Server 2003+3 moreApr 23, 2026 Oct 14, 2009 N/A· v4 N/A· v3 7.5 HIGH· v2 Integer overflow in the CryptoAPI component in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows ma...Show more |
1Microsoft 6Windows 2000 Windows 2003 ServerWindows 7+3 moreApr 23, 2026 Oct 14, 2009 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The CryptoAPI component in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, as used by Internet Explorer...Show more |
1Microsoft 3Windows 2000 Windows 2003 ServerWindows XpApr 23, 2026 Oct 14, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 A certain ActiveX control in the Indexing Service in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly process URLs, which allows remote attackers to execute arbitrary programs via unspeci...Show more |
1Microsoft 7.net Framework Windows 2000Windows 7+4 moreApr 23, 2026 Oct 14, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0, 2.0 SP1, 2.0 SP2, 3.5, and 3.5 SP1, and Silverlight 2, does not properly handle interfaces, which allows remote attackers to execute arbitrary code via (...Show more |
1Microsoft 7Internet Explorer Windows 2000Windows 7+4 moreApr 23, 2026 Oct 14, 2009 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via a crafted data stream header that triggers memory corruption, aka "Data Stream Head...Show more |
1Microsoft 7Windows 2000 Windows Media Format RuntimeWindows Media Player+4 moreApr 23, 2026 Oct 14, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 Microsoft Windows Media Runtime, as used in DirectShow WMA Voice Codec, Windows Media Audio Voice Decoder, and Audio Compression Manager (ACM), does not properly process Advanced Systems Format (ASF) files, which allows...Show more |
1Microsoft 7.net Framework Windows 2000Windows 7+4 moreApr 23, 2026 Oct 14, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 Microsoft .NET Framework 2.0, 2.0 SP1, and 3.5 does not properly enforce a certain type-equality constraint in .NET verifiable code, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser...Show more |
1Microsoft 7.net Framework Windows 2000Windows 7+4 moreApr 23, 2026 Oct 14, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 Microsoft .NET Framework 1.0 SP3, 1.1 SP1, and 2.0 SP1 does not properly validate .NET verifiable code, which allows remote attackers to obtain unintended access to stack memory, and execute arbitrary code, via (1) a cra...Show more |
1Microsoft 3Windows 2000 Windows Server 2003Windows XpApr 23, 2026 Sep 8, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 The DHTML Editing Component ActiveX control in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly format HTML markup, which allows remote attackers to execute arbitrary code via a crafted w...Show more |
1Microsoft 8Windows 2000 Windows Media Format RuntimeWindows Media Foundation+5 moreApr 23, 2026 Sep 8, 2009 N/A· v4 N/A· v3 8.5 HIGH· v2 Microsoft Windows Media Format Runtime 9.0, 9.5, and 11; and Microsoft Media Foundation on Windows Vista Gold, SP1, and SP2 and Server 2008; allows remote attackers to execute arbitrary code via an MP3 file with crafted...Show more |