CVEs (828)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 5Windows 2000 Windows 2003 ServerWindows Server 2008+2 moreApr 23, 2026 Jun 10, 2009 N/A· v4 N/A· v3 4.9 MEDIUM· v2 The Windows Printing Service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 allows local users to read arbitrary files via a crafted separator page, aka "Pri...Show more |
1Microsoft 2Windows 2003 Server Windows VistaApr 23, 2026 Jun 1, 2009 N/A· v4 N/A· v3 4.7 MEDIUM· v2 win32k.sys in Microsoft Windows Server 2003 and Vista allows local users to cause a denial of service (system crash) via vectors related to CreateWindow, TranslateMessage, and DispatchMessage, possibly a race condition b...Show more |
1Microsoft 7Ie Internet ExplorerWindows 2000+4 moreApr 23, 2026 Apr 15, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 Windows HTTP Services (aka WinHTTP) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008; and WinINet in Microsoft Internet Explorer 5.01 SP4, 6 SP1, 6 and 7 on Wind...Show more |
1Microsoft 5Windows 2000 Windows Server 2003Windows Server 2008+2 moreApr 23, 2026 Apr 15, 2009 N/A· v4 N/A· v3 5.8 MEDIUM· v2 Windows HTTP Services (aka WinHTTP) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, and Vista Gold allows remote web servers to impersonate arbitrary https web sites by using DNS spoofing to "forw...Show more |
1Microsoft 5Windows 2000 Windows Server 2003Windows Server 2008+2 moreApr 23, 2026 Apr 15, 2009 N/A· v4 N/A· v3 10.0 HIGH· v2 Integer underflow in Windows HTTP Services (aka WinHTTP) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote HTTP servers to execute arbitrary code vi...Show more |
1Microsoft 2Windows Server 2008 Windows VistaApr 23, 2026 Apr 15, 2009 N/A· v4 N/A· v3 6.9 MEDIUM· v2 The ThreadPool class in Windows Vista Gold and SP1, and Server 2008, does not properly implement isolation among a set of distinct processes that (1) all run under the NetworkService account or (2) all run under the Loca...Show more |
1Microsoft 4Windows Server 2003 Windows Server 2008Windows Vista+1 moreApr 23, 2026 Apr 15, 2009 N/A· v4 N/A· v3 7.2 HIGH· v2 The Windows Management Instrumentation (WMI) provider in Microsoft Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly implement isolation among a set of distinct proces...Show more |
1Microsoft 4Subsystem For Unix Based Applications Windows Server 2008Windows Services For Unix+1 moreApr 23, 2026 Apr 1, 2009 N/A· v4 N/A· v3 10.0 HIGH· v2 Multiple unspecified vulnerabilities in (1) unlzh.c and (2) unpack.c in the gzip libraries in Microsoft Windows Server 2008, Windows Services for UNIX 3.0 and 3.5, and the Subsystem for UNIX-based Applications (SUA); as...Show more |
1Microsoft 5Windows 2000 Windows Server 2003Windows Server 2008+2 moreApr 23, 2026 Mar 10, 2009 N/A· v4 N/A· v3 7.1 HIGH· v2 The Secure Channel (aka SChannel) authentication component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008, when certificate authentication is used, does not pr...Show more |
1Microsoft 5Windows 2000 Windows Server 2003Windows Server 2008+2 moreApr 23, 2026 Mar 10, 2009 N/A· v4 N/A· v3 7.2 HIGH· v2 The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 does not properly handle invalid pointers, which allows local users to gain privileges via an application that triggers use of a crafted point...Show more |
1Microsoft 5Windows 2000 Windows Server 2003Windows Server 2008+2 moreApr 23, 2026 Mar 10, 2009 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate handles, which allows local users to gain privileges via a crafted applica...Show more |
1Microsoft 5Windows 2000 Windows Server 2003Windows Server 2008+2 moreApr 23, 2026 Mar 10, 2009 N/A· v4 N/A· v3 9.3 HIGH· v2 The graphics device interface (GDI) implementation in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate input received from...Show more |
1Microsoft 4Windows Server 2003 Windows Server 2008Windows Vista+1 moreApr 23, 2026 Jan 28, 2009 N/A· v4 N/A· v3 4.0 MEDIUM· v2 Microsoft Windows XP, Server 2003 and 2008, and Vista exposes I/O activity measurements of all processes, which allows local users to obtain sensitive information, as demonstrated by reading the I/O Other Bytes column in...Show more |
1Microsoft 5Windows 2000 Windows Server 2003Windows Server 2008+2 moreApr 23, 2026 Jan 21, 2009 N/A· v4 N/A· v3 7.2 HIGH· v2 Microsoft Windows does not properly enforce the Autorun and NoDriveTypeAutoRun registry values, which allows physically proximate attackers to execute arbitrary code by (1) inserting CD-ROM media, (2) inserting DVD media...Show more |
1Microsoft 5Windows 2000 Windows Server 2003Windows Server 2008+2 moreApr 23, 2026 Jan 14, 2009 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 SMB in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to execute arbitrary code via malformed values of unspecified...Show more |
1Microsoft 5Windows 2000 Windows Server 2003Windows Server 2008+2 moreApr 23, 2026 Jan 14, 2009 N/A· v4 N/A· v3 10.0 HIGH· v2 Buffer overflow in SMB in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via malformed values of unspecified "fields inside...Show more |
1Microsoft 2Windows Server 2008 Windows VistaApr 23, 2026 Dec 10, 2008 N/A· v4 N/A· v3 8.5 HIGH· v2 The search-ms protocol handler in Windows Explorer in Microsoft Windows Vista Gold and SP1 and Server 2008 uses untrusted parameter data obtained from incorrect parsing, which allows remote attackers to execute arbitrary...Show more |
1Microsoft 2Windows Server 2008 Windows VistaApr 23, 2026 Dec 10, 2008 N/A· v4 N/A· v3 8.5 HIGH· v2 The Windows Search component in Microsoft Windows Vista Gold and SP1 and Server 2008 does not properly free memory during a save operation for a Windows Search file, which allows remote attackers to execute arbitrary cod...Show more |
1Microsoft 6Windows 2000 Windows 2003 ServerWindows Server 2003+3 moreApr 23, 2026 Dec 10, 2008 N/A· v4 9.8 CRITICAL· v3 9.3 HIGH· v2 Heap-based buffer overflow in an API in GDI in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows context-dependent attackers to cause a denial of service or e...Show more |
1Microsoft 6Windows 2000 Windows 2003 ServerWindows Server 2003+3 moreApr 23, 2026 Dec 10, 2008 N/A· v4 N/A· v3 9.3 HIGH· v2 Integer overflow in GDI in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to execute arbitrary code via a malformed header in a crafted WM...Show more |