CVEs (3,554)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 2Windows 7 Windows Server 2008Apr 29, 2026 Apr 14, 2010 N/A· v4 N/A· v3 10.0 HIGH· v2 The SMB client in Microsoft Windows Server 2008 R2 and Windows 7 does not properly handle (1) SMBv1 and (2) SMBv2 response packets, which allows remote SMB servers and man-in-the-middle attackers to execute arbitrary cod...Show more |
1Microsoft 5Windows 2003 Server Windows 7Windows Server 2003+2 moreApr 29, 2026 Apr 14, 2010 N/A· v4 N/A· v3 10.0 HIGH· v2 The SMB client in Microsoft Windows Server 2003 SP2, Vista Gold, SP1, and SP2, and Windows Server 2008 Gold and SP2 allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code or cause a denial of...Show more |
1Microsoft 2Windows 7 Windows Server 2008Apr 29, 2026 Apr 14, 2010 N/A· v4 N/A· v3 10.0 HIGH· v2 The SMB client in Microsoft Windows Server 2008 R2 and Windows 7 does not properly validate fields in SMB transaction responses, which allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code o...Show more |
1Microsoft 7Windows 2000 Windows 2003 ServerWindows 7+4 moreApr 29, 2026 Apr 14, 2010 N/A· v4 N/A· v3 10.0 HIGH· v2 The SMB client in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly allocate memory for...Show more |
1Microsoft 6Windows 2000 Windows 2003 ServerWindows Server 2003+3 moreApr 29, 2026 Apr 14, 2010 N/A· v4 N/A· v3 4.7 MEDIUM· v2 The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 does not properly validate a registry-key argument to an unspecified system call, which al...Show more |
1Microsoft 6Exchange Server Windows 2000Windows 2003 Server+3 moreApr 29, 2026 Apr 14, 2010 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The SMTP component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Server 2008 Gold, SP2, and R2, and Exchange Server 2000 SP3, does not properly allocate memory for SMTP command replies, which allows...Show more |
1Microsoft 6Exchange Server Windows 2000Windows 2003 Server+3 moreApr 29, 2026 Apr 14, 2010 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The SMTP component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Server 2008 Gold, SP2, and R2, and Exchange Server 2003 SP2, does not properly parse MX records, which allows remote DNS servers to c...Show more |
1Microsoft 6Internet Explorer Windows 2003 ServerWindows Server 2003+3 moreApr 29, 2026 Mar 31, 2010 N/A· v4 N/A· v3 9.3 HIGH· v2 Microsoft Internet Explorer 7 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, leading to memory corruption, aka "HTML Rendering Memory Co...Show more |
1Microsoft 8Internet Explorer Windows 2000Windows 2003 Server+5 moreApr 29, 2026 Mar 31, 2010 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-domain vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 allows user-assisted remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted HTML docume...Show more |
1Microsoft 7Internet Explorer Windows 2003 ServerWindows 7+4 moreApr 29, 2026 Mar 31, 2010 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 Use-after-free vulnerability in mstime.dll in Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code via vectors related to the TIME2 behavior, the CTimeAction object, and destruction of markup,...Show more |
1Microsoft 7Internet Explorer Windows 2003 ServerWindows 7+4 moreApr 29, 2026 Mar 31, 2010 N/A· v4 N/A· v3 9.3 HIGH· v2 Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is de...Show more |
1Microsoft 7Internet Explorer Windows 2000Windows 2003 Server+4 moreApr 29, 2026 Mar 31, 2010 N/A· v4 N/A· v3 9.3 HIGH· v2 Race condition in Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via a crafted HTML document that triggers memory corruption, aka "Race Condition Memory Corruption...Show more |
1Microsoft 7Internet Explorer Windows 2000Windows 2003 Server+4 moreApr 29, 2026 Mar 31, 2010 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 does not properly handle unspecified "encoding strings," which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted...Show more |
1Microsoft 7Internet Explorer Windows 2000Windows 2003 Server+4 moreApr 29, 2026 Mar 31, 2010 N/A· v4 N/A· v3 9.3 HIGH· v2 Microsoft Internet Explorer 6, 6 SP1, and 7 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is delet...Show more |
1Microsoft 7Internet Explorer Windows 2000Windows 2003 Server+4 moreMay 21, 2026 Mar 10, 2010 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via vectors involving access to an invalid poi...Show more |
1Microsoft 6Windows 2000 Windows 2003 ServerWindows 7+3 moreApr 29, 2026 Feb 26, 2010 N/A· v4 N/A· v3 4.7 MEDIUM· v2 An unspecified API in Microsoft Windows 2000, Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, and Windows 7 does not validate arguments, which allows local users to cause a denial of service (system...Show more |
1Microsoft 6Windows 2000 Windows 2003 ServerWindows 7+3 moreApr 29, 2026 Feb 10, 2010 N/A· v4 N/A· v3 9.3 HIGH· v2 The Microsoft Data Analyzer ActiveX control (aka the Office Excel ActiveX control for Data Analysis) in max3activex.dll in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold,...Show more |
1Microsoft 4Windows 7 Windows Server 2008Windows Vista+1 moreApr 29, 2026 Feb 10, 2010 N/A· v4 N/A· v3 9.3 HIGH· v2 Heap-based buffer overflow in DirectShow in Microsoft DirectX, as used in the AVI Filter on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2, and in Quartz on Windows 2000 SP4, Windows XP SP2 and SP3...Show more |
1Microsoft 2Windows Server 2008 Windows VistaApr 29, 2026 Feb 10, 2010 N/A· v4 N/A· v3 7.8 HIGH· v2 The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 allows remote attackers to cause a denial of service (system hang) via crafted packets with malformed TCP selective ack...Show more |
1Microsoft 2Windows Server 2008 Windows VistaApr 29, 2026 Feb 10, 2010 N/A· v4 N/A· v3 10.0 HIGH· v2 The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2, when IPv6 is enabled, does not properly perform bounds checking on ICMPv6 Route Information packets, which allows remo...Show more |