CVEs (58)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 7Windows 2000 Windows 2003 ServerWindows 98+4 moreApr 16, 2026 Jan 10, 2005 N/A· v4 N/A· v3 10.0 HIGH· v2 Microsoft Word for Windows 6.0 Converter (MSWRD632.WPC), as used in WordPad, does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent b...Show more |
1Microsoft 7Windows 2000 Windows 2003 ServerWindows 98+4 moreApr 16, 2026 Jan 10, 2005 N/A· v4 N/A· v3 10.0 HIGH· v2 Microsoft Word for Windows 6.0 Converter does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka "...Show more |
2Microsoft Nortel19Ip Softphone 2050 Media Communication Server 5100Media Communication Server 5200+16 moreApr 16, 2026 Dec 23, 2004 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allow remote attackers to cause a denial of service via (1) the frame number set to zero, whi...Show more |
2Microsoft Nortel9Ip Softphone 2050 Mobile Voice Client 2050Optivity Telephony Manager+6 moreApr 16, 2026 Dec 15, 2004 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The DHTML Edit Control (dhtmled.ocx) allows remote attackers to inject arbitrary web script into other domains by setting a name for a window, opening a child page whose target is the window with the given name, then inj...Show more |
2Greg Roelofs Microsoft6Libpng Msn MessengerWindows 98se+3 moreApr 16, 2026 Nov 23, 2004 N/A· v4 N/A· v3 10.0 HIGH· v2 Multiple buffer overflows in libpng 1.2.5 and earlier, as used in multiple products, allow remote attackers to execute arbitrary code via malformed PNG images in which (1) the png_handle_tRNS function does not properly v...Show more |
1Microsoft 5Internet Explorer Windows 2000Windows 98+2 moreApr 16, 2026 Nov 3, 2004 N/A· v4 N/A· v3 10.0 HIGH· v2 Buffer overflow in Microsoft Internet Explorer and Explorer on Windows XP SP1, WIndows 2000, Windows 98, and Windows Me may allow remote malicious servers to cause a denial of service (application crash) and possibly exe...Show more |
3Avaya MicrosoftNortel18Definity One Media Server IeInternet Explorer+15 moreApr 16, 2026 Aug 18, 2004 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, a...Show more |
1Microsoft 7Directx Windows 2000Windows 2003 Server+4 moreApr 16, 2026 Aug 6, 2004 N/A· v4 N/A· v3 5.0 MEDIUM· v2 IDirectPlay4 Application Programming Interface (API) of Microsoft DirectPlay 7.0a thru 9.0b, as used in Windows Server 2003 and earlier allows remote attackers to cause a denial of service (application crash) via a malfo...Show more |
2Avaya Microsoft11Definity One Media Server Ip600 Media ServersModular Messaging Message Storage Server+8 moreApr 16, 2026 Aug 6, 2004 N/A· v4 N/A· v3 10.0 HIGH· v2 Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, Me, NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary commands via a .CHM file with a large...Show more |
1Microsoft 8Internet Explorer OutlookWindows 98+5 moreApr 16, 2026 Jul 27, 2004 N/A· v4 7.8 HIGH· v3 10.0 HIGH· v2 Double free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image. |
1Microsoft 7Windows 2000 Windows 2003 ServerWindows 98+4 moreApr 16, 2026 Jun 1, 2004 N/A· v4 N/A· v3 7.5 HIGH· v2 Double free vulnerability in the ASN.1 library as used in Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service and possibly execute arbitrary code. |
1Microsoft 6Netmeeting Windows 2000Windows 2003 Server+3 moreApr 16, 2026 Jun 1, 2004 N/A· v4 N/A· v3 7.5 HIGH· v2 Unknown vulnerability in the H.323 protocol implementation in Windows 98, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code. |
1Microsoft 7Netmeeting Windows 2000Windows 2003 Server+4 moreApr 16, 2026 Jun 1, 2004 N/A· v4 N/A· v3 7.5 HIGH· v2 Buffer overflow in the Private Communications Transport (PCT) protocol implementation in the Microsoft SSL library, as used in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows...Show more |
1Microsoft 7Netmeeting Windows 2000Windows 2003 Server+4 moreApr 16, 2026 Jun 1, 2004 N/A· v4 N/A· v3 7.5 HIGH· v2 Stack-based buffer overflow in certain Active Directory service functions in LSASRV.DLL of the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 200...Show more |
1Microsoft 5Windows 2000 Windows 2003 ServerWindows Me+2 moreApr 16, 2026 Nov 17, 2003 N/A· v4 N/A· v3 7.5 HIGH· v2 The Messenger Service for Windows NT through Server 2003 does not properly verify the length of the message, which allows remote attackers to execute arbitrary code via a buffer overflow attack. |
1Microsoft 5Windows 2000 Windows 2003 ServerWindows Me+2 moreApr 16, 2026 Nov 17, 2003 N/A· v4 N/A· v3 7.5 HIGH· v2 Stack-based buffer overflow in the PCHealth system in the Help and Support Center function in Windows XP and Windows Server 2003 allows remote attackers to execute arbitrary code via a long query in an HCP URL. |
1Microsoft 7Windows 2000 Windows 2003 ServerWindows 98+4 moreApr 16, 2026 Aug 7, 2003 N/A· v4 N/A· v3 7.5 HIGH· v2 Buffer overflow in the HTML Converter (HTML32.cnv) on various Windows operating systems allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via cut-and-paste operation, as dem...Show more |
1Microsoft 7Windows 2000 Windows 2000 Terminal ServicesWindows 98+4 moreApr 16, 2026 Mar 24, 2003 N/A· v4 N/A· v3 7.5 HIGH· v2 Integer overflow in JsArrayFunctionHeapSort function used by Windows Script Engine for JScript (JScript.dll) on various Windows operating system allows remote attackers to execute arbitrary code via a malicious web page...Show more |
Cross-site scripting (XSS) vulnerability in Help and Support Center for Microsoft Windows Me allows remote attackers to execute arbitrary script in the Local Computer security context via an hcp:// URL with the malicious...Show more |
1Microsoft 8Windows 2000 Windows 2000 Terminal ServicesWindows 95+5 moreApr 16, 2026 Dec 23, 2002 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Microsoft Virtual Machine (VM) build 5.0.3805 and earlier allows remote attackers to determine a local user's username via a Java applet that accesses the user.dir system property, aka "User.dir Exposure Vulnerability." |