Microsoft Windows-Nt vulnerabilities
15 known vulnerabilities affecting microsoft/windows-nt.
Total CVEs
15
CISA KEV
0
Public exploits
6
Exploited in wild
0
Severity breakdown
CRITICAL11HIGH3MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2007-5348CRITICALCVSS 9.3PoCvvistavxp2008-09-11
CVE-2007-5348 [CRITICAL] CWE-189 CVE-2007-5348: Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 S
Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Serv
nvd
CVE-2008-3008CRITICALCVSS 9.3PoCvxp2008-09-11
CVE-2008-3008 [CRITICAL] CWE-119 CVE-2008-3008: Stack-based buffer overflow in the WMEncProfileManager ActiveX control in wmex.dll in Microsoft Wind
Stack-based buffer overflow in the WMEncProfileManager ActiveX control in wmex.dll in Microsoft Windows Media Encoder 9 Series allows remote attackers to execute arbitrary code via a long first argument to the GetDetailsString method, aka "Windows Media Encoder Buffer Overrun Vulnerability."
nvd
CVE-2008-3014CRITICALCVSS 9.3vvistavxp2008-09-11
CVE-2008-3014 [CRITICAL] CWE-119 CVE-2008-3014: Buffer overflow in gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3,
Buffer overflow in gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services
nvd
CVE-2008-3012CRITICALCVSS 9.3vvistavxp2008-09-11
CVE-2008-3012 [CRITICAL] CWE-119 CVE-2008-3012: gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 an
gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 20
nvd
CVE-2008-1457CRITICALCVSS 9.0v2008vvista+1 more2008-08-13
CVE-2008-1457 [CRITICAL] CWE-20 CVE-2008-1457: The Event System in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold
The Event System in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate per-user subscriptions, which allows remote authenticated users to execute arbitrary code via a crafted event subscription request.
nvd
CVE-2008-1456CRITICALCVSS 9.0v2008vvista+1 more2008-08-13
CVE-2008-1456 [CRITICAL] CWE-20 CVE-2008-1456: Array index vulnerability in the Event System in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server
Array index vulnerability in the Event System in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote authenticated users to execute arbitrary code via a crafted event subscription request that is used to access an array of function pointers.
nvd
CVE-2008-2246HIGHCVSS 7.8v20082008-08-13
CVE-2008-2246 [HIGH] CWE-200 CVE-2008-2246: Microsoft Windows Vista through SP1 and Server 2008 do not properly import the default IPsec policy
Microsoft Windows Vista through SP1 and Server 2008 do not properly import the default IPsec policy from a Windows Server 2003 domain to a Windows Server 2008 domain, which prevents IPsec rules from being enforced and allows remote attackers to bypass intended access restrictions.
nvd
CVE-2008-1435CRITICALCVSS 9.3v20082008-07-08
CVE-2008-1435 [CRITICAL] CWE-94 CVE-2008-1435: Windows Explorer in Microsoft Windows Vista up to SP1, and Server 2008, allows user-assisted remote
Windows Explorer in Microsoft Windows Vista up to SP1, and Server 2008, allows user-assisted remote attackers to execute arbitrary code via crafted saved-search (.search-ms) files that are not properly handled when saving, aka "Windows Saved Search Vulnerability."
nvd
CVE-2008-1453HIGHCVSS 8.3vxp2008-06-12
CVE-2008-1453 [HIGH] CWE-20 CVE-2008-1453: The Bluetooth stack in Microsoft Windows XP SP2 and SP3, and Vista Gold and SP1, allows physically p
The Bluetooth stack in Microsoft Windows XP SP2 and SP3, and Vista Gold and SP1, allows physically proximate attackers to execute arbitrary code via a large series of Service Discovery Protocol (SDP) packets.
nvd
CVE-2008-1445HIGHCVSS 7.1v2008vxp2008-06-12
CVE-2008-1445 [HIGH] CWE-20 CVE-2008-1445: Active Directory on Microsoft Windows 2000 Server SP4, XP Professional SP2 and SP3, Server 2003 SP1
Active Directory on Microsoft Windows 2000 Server SP4, XP Professional SP2 and SP3, Server 2003 SP1 and SP2, and Server 2008 allows remote authenticated users to cause a denial of service (system hang or reboot) via a crafted LDAP request.
nvd
CVE-2008-1436CRITICALCVSS 9.0PoCvvista2008-04-21
CVE-2008-1436 [CRITICAL] CWE-264 CVE-2008-1436: Microsoft Windows XP Professional SP2, Vista, and Server 2003 and 2008 does not properly assign acti
Microsoft Windows XP Professional SP2, Vista, and Server 2003 and 2008 does not properly assign activities to the (1) NetworkService and (2) LocalService accounts, which might allow context-dependent attackers to gain privileges by using one service process to capture a resource from a second service process that has a LocalSystem privilege-escalati
nvd
CVE-2008-0927MEDIUMCVSS 5.0PoCv2000v20032008-04-14
CVE-2008-0927 [MEDIUM] CWE-399 CVE-2008-0927: dhost.exe in Novell eDirectory 8.7.3 before sp10 and 8.8.2 allows remote attackers to cause a denial
dhost.exe in Novell eDirectory 8.7.3 before sp10 and 8.8.2 allows remote attackers to cause a denial of service (CPU consumption) via an HTTP request with (1) multiple Connection headers or (2) a Connection header with multiple comma-separated values. NOTE: this might be similar to CVE-2008-1777.
nvd
CVE-2008-1086CRITICALCVSS 9.3v20082008-04-08
CVE-2008-1086 [CRITICAL] CWE-94 CVE-2008-1086: The HxTocCtrl ActiveX control (hxvz.dll), as used in Microsoft Internet Explorer 5.01 SP4 and 6 SP1,
The HxTocCtrl ActiveX control (hxvz.dll), as used in Microsoft Internet Explorer 5.01 SP4 and 6 SP1, in Windows XP SP2, Server 2003 SP1 and SP2, Vista SP1, and Server 2008, allows remote attackers to execute arbitrary code via malformed arguments, which triggers memory corruption.
nvd
CVE-2008-1087CRITICALCVSS 9.3PoCv20082008-04-08
CVE-2008-1087 [CRITICAL] CWE-119 CVE-2008-1087: Stack-based buffer overflow in GDI in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, V
Stack-based buffer overflow in GDI in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, and Server 2008 allows remote attackers to execute arbitrary code via an EMF image file with crafted filename parameters, aka "GDI Stack Overflow Vulnerability."
nvd
CVE-2006-0005CRITICALCVSS 9.3PoCvdatacenter_servervxp+1 more2006-02-14
CVE-2006-0005 [CRITICAL] CWE-119 CVE-2006-0005: Buffer overflow in the plug-in for Microsoft Windows Media Player (WMP) 9 and 10, when used in brows
Buffer overflow in the plug-in for Microsoft Windows Media Player (WMP) 9 and 10, when used in browsers other than Internet Explorer and set as the default application to handle media files, allows remote attackers to execute arbitrary code via HTML with an EMBED element containing a long src attribute.
nvd