CVEs (3,554)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 4Subsystem For Unix Based Applications Windows Server 2008Windows Services For Unix+1 moreApr 23, 2026 Apr 1, 2009 N/A· v4 N/A· v3 10.0 HIGH· v2 Multiple unspecified vulnerabilities in (1) unlzh.c and (2) unpack.c in the gzip libraries in Microsoft Windows Server 2008, Windows Services for UNIX 3.0 and 3.5, and the Subsystem for UNIX-based Applications (SUA); as...Show more |
1Microsoft 3Windows 2000 Windows Server 2003Windows Server 2008Apr 23, 2026 Mar 11, 2009 N/A· v4 N/A· v3 6.4 MEDIUM· v2 The DNS Resolver Cache Service (aka DNSCache) in Windows DNS Server in Microsoft Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008 does not properly cache crafted DNS responses, which makes it easier for remote...Show more |
1Microsoft 3Windows 2000 Windows Server 2003Windows Server 2008Apr 23, 2026 Mar 11, 2009 N/A· v4 N/A· v3 5.8 MEDIUM· v2 The DNS Resolver Cache Service (aka DNSCache) in Windows DNS Server in Microsoft Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008, when dynamic updates are enabled, does not reuse cached DNS responses in all ap...Show more |
1Microsoft 3Windows 2000 Windows Server 2003Windows Server 2008Apr 23, 2026 Mar 11, 2009 N/A· v4 N/A· v3 5.5 MEDIUM· v2 The WINS server in Microsoft Windows 2000 SP4 and Server 2003 SP1 and SP2 does not restrict registration of the (1) "wpad" and (2) "isatap" NetBIOS names, which allows remote authenticated users to hijack the Web Proxy A...Show more |
1Microsoft 3Windows 2000 Windows Server 2003Windows Server 2008Apr 23, 2026 Mar 11, 2009 N/A· v4 N/A· v3 3.5 LOW· v2 Windows DNS Server in Microsoft Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008, when dynamic updates are enabled, does not restrict registration of the "wpad" hostname, which allows remote authenticated users...Show more |
1Microsoft 5Windows 2000 Windows Server 2003Windows Server 2008+2 moreApr 23, 2026 Mar 10, 2009 N/A· v4 N/A· v3 7.1 HIGH· v2 The Secure Channel (aka SChannel) authentication component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008, when certificate authentication is used, does not pr...Show more |
1Microsoft 5Windows 2000 Windows Server 2003Windows Server 2008+2 moreApr 23, 2026 Mar 10, 2009 N/A· v4 N/A· v3 7.2 HIGH· v2 The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 does not properly handle invalid pointers, which allows local users to gain privileges via an application that triggers use of a crafted point...Show more |
1Microsoft 5Windows 2000 Windows Server 2003Windows Server 2008+2 moreApr 23, 2026 Mar 10, 2009 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate handles, which allows local users to gain privileges via a crafted applica...Show more |
1Microsoft 5Windows 2000 Windows Server 2003Windows Server 2008+2 moreApr 23, 2026 Mar 10, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 The graphics device interface (GDI) implementation in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate input received from...Show more |
1Microsoft 4Windows Server 2003 Windows Server 2008Windows Vista+1 moreApr 23, 2026 Jan 28, 2009 N/A· v4 N/A· v3 4.0 MEDIUM· v2 Microsoft Windows XP, Server 2003 and 2008, and Vista exposes I/O activity measurements of all processes, which allows local users to obtain sensitive information, as demonstrated by reading the I/O Other Bytes column in...Show more |
1Microsoft 5Windows 2000 Windows Server 2003Windows Server 2008+2 moreApr 23, 2026 Jan 21, 2009 N/A· v4 N/A· v3 7.2 HIGH· v2 Microsoft Windows does not properly enforce the Autorun and NoDriveTypeAutoRun registry values, which allows physically proximate attackers to execute arbitrary code by (1) inserting CD-ROM media, (2) inserting DVD media...Show more |
1Microsoft 5Windows 2000 Windows Server 2003Windows Server 2008+2 moreApr 23, 2026 Jan 14, 2009 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 SMB in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to execute arbitrary code via malformed values of unspecified...Show more |
1Microsoft 5Windows 2000 Windows Server 2003Windows Server 2008+2 moreApr 23, 2026 Jan 14, 2009 N/A· v4 N/A· v3 10.0 HIGH· v2 Buffer overflow in SMB in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via malformed values of unspecified "fields inside...Show more |
1Microsoft 2Windows Server 2008 Windows VistaApr 23, 2026 Dec 10, 2008 N/A· v4 N/A· v3 8.5 HIGH· v2 The search-ms protocol handler in Windows Explorer in Microsoft Windows Vista Gold and SP1 and Server 2008 uses untrusted parameter data obtained from incorrect parsing, which allows remote attackers to execute arbitrary...Show more |
1Microsoft 2Windows Server 2008 Windows VistaApr 23, 2026 Dec 10, 2008 N/A· v4 N/A· v3 8.5 HIGH· v2 The Windows Search component in Microsoft Windows Vista Gold and SP1 and Server 2008 does not properly free memory during a save operation for a Windows Search file, which allows remote attackers to execute arbitrary cod...Show more |
1Microsoft 6Windows 2000 Windows 2003 ServerWindows Server 2003+3 moreApr 23, 2026 Dec 10, 2008 N/A· v4 9.8 CRITICAL· v3 9.3 HIGH· v2 Heap-based buffer overflow in an API in GDI in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows context-dependent attackers to cause a denial of service or e...Show more |
1Microsoft 6Windows 2000 Windows 2003 ServerWindows Server 2003+3 moreApr 23, 2026 Dec 10, 2008 N/A· v4 N/A· v3 9.3 HIGH· v2 Integer overflow in GDI in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to execute arbitrary code via a malformed header in a crafted WM...Show more |
1Microsoft 4Windows Windows 2000Windows Server 2008+1 moreApr 23, 2026 Nov 12, 2008 N/A· v4 N/A· v3 9.3 HIGH· v2 Microsoft Windows 2000 Gold through SP4, XP Gold through SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote SMB servers to execute arbitrary code on a client machine by replaying the NTLM cre...Show more |
1Microsoft 5Windows 2000 Windows Server 2003Windows Server 2008+2 moreMay 21, 2026 Oct 23, 2008 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitrary code via a crafted RPC request that...Show more |
12Bsd BsdiCisco+9 more19Bsd Bsd OsCatalyst Blade Switch 3020 Firmware+16 moreApr 23, 2026 Oct 20, 2008 N/A· v4 N/A· v3 7.1 HIGH· v2 The TCP implementation in (1) Linux, (2) platforms based on BSD Unix, (3) Microsoft Windows, (4) Cisco products, and probably other operating systems allows remote attackers to cause a denial of service (connection queue...Show more |