CVEs (739)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 3Windows 2003 Server Windows Server 2003Windows XpApr 29, 2026 Oct 13, 2010 N/A· v4 N/A· v3 7.2 HIGH· v2 The OpenType Font (OTF) format driver in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly perform memory allocation during font parsing, which allows local users to gain privileges via a crafted app...Show more |
1Microsoft 6Windows 2003 Server Windows 7Windows Server 2003+3 moreApr 29, 2026 Oct 13, 2010 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 Integer overflow in the Embedded OpenType (EOT) Font Engine in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows remote atta...Show more |
1Microsoft 5Office Windows Server 2003Windows Server 2008+2 moreApr 29, 2026 Sep 15, 2010 N/A· v4 N/A· v3 9.3 HIGH· v2 The Uniscribe (aka new Unicode Script Processor) implementation in USP10.DLL in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2, and Microsoft Office XP SP3, 2003 SP3, a...Show more |
1Microsoft 5Windows 7 Windows Server 2003Windows Server 2008+2 moreApr 29, 2026 Sep 15, 2010 N/A· v4 N/A· v3 9.3 HIGH· v2 The Print Spooler service in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, when printer sharing is enabled, does not properly...Show more |
1Microsoft 2Windows Server 2003 Windows XpApr 29, 2026 Sep 15, 2010 N/A· v4 N/A· v3 9.3 HIGH· v2 The RPC client implementation in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly allocate memory during the parsing of responses, which allows remote RPC servers and man-in-the-middle attackers to...Show more |
1Microsoft 2Windows Server 2003 Windows XpApr 29, 2026 Sep 15, 2010 N/A· v4 N/A· v3 9.3 HIGH· v2 The Word 97 text converter in the WordPad Text Converters in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly parse malformed structures in Word 97 documents, which allows remote attackers to execut...Show more |
1Microsoft 2Windows Server 2003 Windows XpApr 29, 2026 Sep 15, 2010 N/A· v4 N/A· v3 6.9 MEDIUM· v2 The Client/Server Runtime Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2, when a Chinese, Japanese, or Korean locale is enabled, does not properly allocate memory for...Show more |
1Microsoft 5Windows 7 Windows Server 2003Windows Server 2008+2 moreApr 29, 2026 Sep 15, 2010 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 Heap-based buffer overflow in the Local Security Authority Subsystem Service (LSASS), as used in Active Directory in Microsoft Windows Server 2003 SP2 and Windows Server 2008 Gold, SP2, and R2; Active Directory Applicati...Show more |
1Microsoft 4Windows Server 2003 Windows Server 2008Windows Vista+1 moreApr 29, 2026 Sep 15, 2010 N/A· v4 N/A· v3 9.3 HIGH· v2 The MPEG-4 codec in the Windows Media codecs in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2 does not properly handle crafted media content with MPEG-4 video encoding...Show more |
1Microsoft 6Windows 2003 Server Windows 7Windows Server 2003+3 moreApr 29, 2026 Sep 7, 2010 N/A· v4 N/A· v3 7.2 HIGH· v2 Buffer overflow in the CreateDIBPalette function in win32k.sys in Microsoft Windows XP SP3, Server 2003 R2 Enterprise SP2, Vista Business SP1, Windows 7, and Server 2008 SP2 allows local users to cause a denial of servic...Show more |
1Microsoft 7Outlook Express Windows 2003 ServerWindows 7+4 moreApr 29, 2026 Aug 27, 2010 N/A· v4 N/A· v3 9.3 HIGH· v2 Untrusted search path vulnerability in wab.exe 6.00.2900.5512 in Windows Address Book in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Wi...Show more |
1Microsoft 2Windows Server 2003 Windows XpApr 29, 2026 Aug 27, 2010 N/A· v4 N/A· v3 9.3 HIGH· v2 Untrusted search path vulnerability in the Internet Connection Signup Wizard in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a Trojan horse smmscrpt.dll file in the curre...Show more |
Untrusted search path vulnerability in Microsoft Windows Internet Communication Settings on Windows XP SP3 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks vi...Show more |
2Bsplayer Microsoft3Bs.player Windows Media PlayerWindows XpApr 29, 2026 Aug 27, 2010 N/A· v4 N/A· v3 9.3 HIGH· v2 Untrusted search path vulnerability in the Indeo Codec in iac25_32.ax in Microsoft Windows XP SP3 allows local users to gain privileges via a Trojan horse iacenc.dll file in the current working directory, as demonstrated...Show more |
1Microsoft 5Windows 2003 Server Windows 7Windows Server 2008+2 moreApr 29, 2026 Aug 16, 2010 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 SP2 and R2, and Windows 7 allow local users to gain privileges by leveraging access to a process with NetworkServi...Show more |
1Microsoft 3Windows 2003 Server Windows Server 2003Windows XpApr 29, 2026 Aug 11, 2010 N/A· v4 N/A· v3 9.3 HIGH· v2 The Secure Channel (aka SChannel) security package in Microsoft Windows XP SP2 and SP3, and Windows Server 2003 SP2, does not properly validate certificate request messages from TLS and SSL servers, which allows remote s...Show more |
1Microsoft 3Windows 7 Windows VistaWindows XpApr 29, 2026 Aug 11, 2010 N/A· v4 N/A· v3 9.3 HIGH· v2 The Cinepak codec in Microsoft Windows XP SP2 and SP3, Windows Vista SP1 and SP2, and Windows 7 does not properly decompress media files, which allows remote attackers to execute arbitrary code via a crafted file, aka "C...Show more |
1Microsoft 6Windows 2003 Server Windows 7Windows Server 2003+3 moreApr 29, 2026 Aug 11, 2010 N/A· v4 N/A· v3 10.0 HIGH· v2 The SMB Server in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate fields in an SMB request, which allo...Show more |
1Microsoft 6Windows 2003 Server Windows 7Windows Server 2003+3 moreApr 29, 2026 Aug 11, 2010 N/A· v4 N/A· v3 7.2 HIGH· v2 The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 do not properly validate pseudo-...Show more |
1Microsoft 5Windows 2003 Server Windows Server 2003Windows Server 2008+2 moreApr 29, 2026 Aug 11, 2010 N/A· v4 8.4 HIGH· v3 7.2 HIGH· v2 The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, and Windows Server 2008 Gold and SP2 do not properly validate user-mode input passed...Show more |