|
278011
|
- |
|
microsoft
|
windows_2003_server windows_server_2003 windows_xp
|
Per: http://blogs.technet.com/b/msrc/archive/2010/06/10/windows-help-vulnerability-disclosure.aspx
"customers running Windows Vista, Windows 7, Windows Server 2008, and Windows Server 2008 R2, are…
|
CWE-78
OS Command
|
CVE-2010-1885
|
2019-02-26 23:04 |
2010-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278012
|
- |
|
microsoft
|
windows_server_2003 windows_xp
|
The RPCSS service in Microsoft Windows XP SP2 and SP3 and Server 2003 SP1 and SP2 does not properly implement isolation among a set of distinct processes that (1) all run under the NetworkService acc…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-0079
|
2019-02-26 23:04 |
2009-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278013
|
- |
|
microsoft
|
directx
|
Use-after-free vulnerability in DirectShow in Microsoft DirectX 8.1 and 9.0 allows remote attackers to execute arbitrary code via an MJPEG file or video stream with a malformed Huffman table, which t…
|
CWE-94
Code Injection
|
CVE-2009-0084
|
2019-02-26 23:04 |
2009-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278014
|
- |
|
microsoft
|
office_converter_pack office_word windows_2000 windows_server_2003 windows_xp
|
The WordPerfect 6.x Converter (WPFT632.CNV, 1998.1.27.0) in Microsoft Office Word 2000 SP3 and Microsoft Office Converter Pack does not properly validate the length of an unspecified string, which al…
|
CWE-20
Improper Input Validation
|
CVE-2009-0088
|
2019-02-26 23:04 |
2009-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278015
|
- |
|
microsoft
|
windows_2000 windows_server_2003 windows_server_2008
|
Windows DNS Server in Microsoft Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008, when dynamic updates are enabled, does not restrict registration of the "wpad" hostname, which allows remot…
|
CWE-20
Improper Input Validation
|
CVE-2009-0093
|
2019-02-26 23:04 |
2009-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278016
|
- |
|
microsoft
|
windows_2000 windows_server_2003 windows_server_2008
|
The WINS server in Microsoft Windows 2000 SP4 and Server 2003 SP1 and SP2 does not restrict registration of the (1) "wpad" and (2) "isatap" NetBIOS names, which allows remote authenticated users to h…
|
NVD-CWE-Other
|
CVE-2009-0094
|
2019-02-26 23:04 |
2009-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278017
|
- |
|
microsoft
|
windows_2000 windows_server_2003 windows_server_2008
|
Per: http://www.microsoft.com/technet/security/Bulletin/MS09-008.mspx
Mitigating Factors for WPAD WINS Server Registration Vulnerability - CVE-2009-0094
Mitigation refers to a setting, common c…
|
NVD-CWE-Other
|
CVE-2009-0094
|
2019-02-26 23:04 |
2009-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278018
|
- |
|
microsoft
|
windows_2000 windows_server_2003 windows_server_2008
|
The DNS Resolver Cache Service (aka DNSCache) in Windows DNS Server in Microsoft Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008, when dynamic updates are enabled, does not reuse cached DN…
|
CWE-20
Improper Input Validation
|
CVE-2009-0233
|
2019-02-26 23:04 |
2009-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278019
|
- |
|
microsoft
|
windows_2000 windows_server_2003 windows_server_2008
|
The DNS Resolver Cache Service (aka DNSCache) in Windows DNS Server in Microsoft Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008 does not properly cache crafted DNS responses, which makes …
|
CWE-20
Improper Input Validation
|
CVE-2009-0234
|
2019-02-26 23:04 |
2009-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278020
|
- |
|
microsoft
|
windows_search
|
Cross-site scripting (XSS) vulnerability in Windows Search 4.0 for Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows user-assisted remote attackers to inject arbitrary web script or HTML vi…
|
CWE-79
Cross-site Scripting
|
CVE-2009-0239
|
2019-02-26 23:04 |
2009-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|