CVEs (456)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 7Windows 2000 Windows Media Format RuntimeWindows Media Player+4 moreApr 23, 2026 Oct 14, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 Microsoft Windows Media Runtime, as used in DirectShow WMA Voice Codec, Windows Media Audio Voice Decoder, and Audio Compression Manager (ACM), does not properly process Advanced Systems Format (ASF) files, which allows...Show more |
1Microsoft 7.net Framework Windows 2000Windows 7+4 moreApr 23, 2026 Oct 14, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 Microsoft .NET Framework 2.0, 2.0 SP1, and 3.5 does not properly enforce a certain type-equality constraint in .NET verifiable code, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser...Show more |
1Microsoft 7.net Framework Windows 2000Windows 7+4 moreApr 23, 2026 Oct 14, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 Microsoft .NET Framework 1.0 SP3, 1.1 SP1, and 2.0 SP1 does not properly validate .NET verifiable code, which allows remote attackers to obtain unintended access to stack memory, and execute arbitrary code, via (1) a cra...Show more |
1Microsoft 3Windows 2000 Windows Server 2003Windows XpApr 23, 2026 Sep 8, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 The DHTML Editing Component ActiveX control in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly format HTML markup, which allows remote attackers to execute arbitrary code via a crafted w...Show more |
1Microsoft 8Windows 2000 Windows Media Format RuntimeWindows Media Foundation+5 moreApr 23, 2026 Sep 8, 2009 N/A· v4 N/A· v3 8.5 HIGH· v2 Microsoft Windows Media Format Runtime 9.0, 9.5, and 11; and Microsoft Media Foundation on Windows Vista Gold, SP1, and SP2 and Server 2008; allows remote attackers to execute arbitrary code via an MP3 file with crafted...Show more |
1Microsoft 8Media Foundation Sdk Windows 2000Windows Media Format Runtime+5 moreApr 23, 2026 Sep 8, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 Microsoft Windows Media Format Runtime 9.0, 9.5, and 11 and Windows Media Services 9.1 and 2008 do not properly parse malformed headers in Advanced Systems Format (ASF) files, which allows remote attackers to execute arb...Show more |
1Microsoft 5Windows 2000 Windows Server 2003Windows Server 2008+2 moreApr 23, 2026 Sep 8, 2009 N/A· v4 N/A· v3 7.8 HIGH· v2 Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allow remote attackers to cause a denial of service (TCP outage) via a series of TCP sessions that have...Show more |
1Microsoft 4Windows 2000 Windows Server 2003Windows Server 2008+1 moreApr 23, 2026 Sep 8, 2009 N/A· v4 N/A· v3 10.0 HIGH· v2 The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 does not properly manage state information, which allows remote attackers to execute arbitrary code by sending packets...Show more |
1Microsoft 5Windows 2000 Windows Server 2003Windows Server 2008+2 moreApr 23, 2026 Sep 8, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 The JScript scripting engine 5.1, 5.6, 5.7, and 5.8 in JScript.dll in Microsoft Windows, as used in Internet Explorer, does not properly load decoded scripts into memory before execution, which allows remote attackers to...Show more |
win32k.sys in Microsoft Windows Server 2003 SP2 allows remote attackers to cause a denial of service (system crash) by referencing a crafted .eot file in the src descriptor of an @font-face Cascading Style Sheets (CSS) r...Show more |
1Microsoft 5Windows 2000 Windows Server 2003Windows Server 2008+2 moreApr 23, 2026 Aug 12, 2009 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The Active Template Library (ATL) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via vectors relat...Show more |
1Microsoft 4Windows 2000 Windows Server 2003Windows Vista+1 moreApr 23, 2026 Aug 12, 2009 N/A· v4 N/A· v3 6.9 MEDIUM· v2 The Message Queuing (aka MSMQ) service for Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP2, and Vista Gold does not properly validate unspecified IOCTL request data from user mode before passing this data to kernel m...Show more |
1Microsoft 6Windows 2000 Windows ServerWindows Server 2003+3 moreApr 23, 2026 Aug 12, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 Heap-based buffer overflow in Microsoft Remote Desktop Connection (formerly Terminal Services Client) running RDP 5.0 through 6.1 on Windows, and Remote Desktop Connection Client for Mac 2.0, allows remote attackers to e...Show more |
1Microsoft 2Windows Server 2003 Windows XpApr 23, 2026 Aug 3, 2009 N/A· v4 N/A· v3 4.6 MEDIUM· v2 The NtUserConsoleControl function in win32k.sys in Microsoft Windows XP SP2 and SP3, and Server 2003 before SP1, allows local administrators to bypass unspecified "security software" and gain privileges via a crafted cal...Show more |
1Microsoft 6Internet Explorer Windows 2000Windows Server 2003+3 moreApr 23, 2026 Jul 29, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 Microsoft Internet Explorer 5.01 SP4 and 6 SP1; Internet Explorer 6 for Windows XP SP2 and SP3 and Server 2003 SP2; and Internet Explorer 7 and 8 for Windows XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and...Show more |
1Microsoft 4Directx Windows 2000Windows Server 2003+1 moreApr 23, 2026 Jul 15, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 The QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2 does not properly validate unspecified size fie...Show more |
1Microsoft 4Directx Windows 2000Windows Server 2003+1 moreApr 23, 2026 Jul 15, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 The QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2 performs updates to pointers without properly v...Show more |
1Microsoft 5Windows 2000 Windows Server 2003Windows Server 2008+2 moreApr 23, 2026 Jul 15, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 Integer overflow in the Embedded OpenType (EOT) Font Engine in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitr...Show more |
1Microsoft 5Windows 2000 Windows Server 2003Windows Server 2008+2 moreApr 23, 2026 Jul 15, 2009 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 The Embedded OpenType (EOT) Font Engine (T2EMBED.DLL) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary co...Show more |
1Microsoft 5Windows 2000 Windows Server 2003Windows Server 2008+2 moreApr 23, 2026 Jun 10, 2009 N/A· v4 N/A· v3 7.2 HIGH· v2 The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly validate the user-mode input associated with the editing of an unspecified desktop parameter, which allows local users to ga...Show more |