Microsoft Windows 2003 Server vulnerabilities
176 known vulnerabilities affecting microsoft/windows_2003_server.
Total CVEs
176
CISA KEV
1
actively exploited
Public exploits
67
Exploited in wild
15
Severity breakdown
CRITICAL40HIGH73MEDIUM48LOW15
Vulnerabilities
Page 3 of 9
CVE-2004-0790P3MEDIUMCVSS 5.0PoCvr22005-04-12
CVE-2004-0790 [MEDIUM] CVE-2004-0790: Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (reset
Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (reset TCP connections) via spoofed ICMP error messages, aka the "blind connection-reset attack." NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are relate
nvd
CVE-2005-1935P3HIGHCVSS 7.5PoCv64-bitvr22005-06-13
CVE-2005-1935 [HIGH] CVE-2005-1935: Heap-based buffer overflow in the BERDecBitString function in Microsoft ASN.1 library (MSASN1.DLL) a
Heap-based buffer overflow in the BERDecBitString function in Microsoft ASN.1 library (MSASN1.DLL) allows remote attackers to execute arbitrary code via nested constructed bit strings, which leads to a realloc of a non-null pointer and causes the function to overwrite previously freed memory, as demonstrated using a SPNEGO token with a constructed bit string du
nvd
CVE-2005-0551P3CRITICALCVSS 10.0PoCvr22005-05-02
CVE-2005-0551 [CRITICAL] CVE-2005-0551: Stack-based buffer overflow in WINSRV.DLL in the Client Server Runtime System (CSRSS) process of Mic
Stack-based buffer overflow in WINSRV.DLL in the Client Server Runtime System (CSRSS) process of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application that provides console window information with a long FaceName value.
nvd
CVE-2006-0988P3HIGHCVSS 7.8PoCvr22006-03-03
CVE-2006-0988 [HIGH] CVE-2006-0988: The default configuration of the DNS Server service on Windows Server 2003 and Windows 2000, and the
The default configuration of the DNS Server service on Windows Server 2003 and Windows 2000, and the Microsoft DNS Server service on Windows NT 4.0, allows recursive queries and provides additional delegation information to arbitrary IP addresses, which allows remote attackers to cause a denial of service (traffic amplification) via DNS queries with spoofed sou
nvd
CVE-2005-0356P3MEDIUMCVSS 5.0PoCventerpriseventerprise_64-bit+4 more2005-05-31
CVE-2005-0356 [MEDIUM] CVE-2005-0356: Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timest
Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host to discard later packets because they appear to be too old.
nvd
CVE-2009-1929P2CRITICALCVSS 9.3vsp22009-08-12
CVE-2009-1929 [CRITICAL] CWE-119 CVE-2009-1929: Heap-based buffer overflow in the Microsoft Terminal Services Client ActiveX control running RDP 6.1
Heap-based buffer overflow in the Microsoft Terminal Services Client ActiveX control running RDP 6.1 on Windows XP SP2, Vista SP1 or SP2, or Server 2008 Gold or SP2; or 5.2 or 6.1 on Windows XP SP3; allows remote attackers to execute arbitrary code via unspecified parameters to unknown methods, aka "Remote Desktop Connection ActiveX Control Heap Ove
nvd
CVE-2006-5583P3CRITICALCVSS 10.0v2000vsp1+1 more2006-12-12
CVE-2006-5583 [CRITICAL] CVE-2006-5583: Buffer overflow in the SNMP Service in Microsoft Windows 2000 SP4, XP SP2, Server 2003, Server 2003
Buffer overflow in the SNMP Service in Microsoft Windows 2000 SP4, XP SP2, Server 2003, Server 2003 SP1, and possibly other versions allows remote attackers to execute arbitrary code via a crafted SNMP packet, aka "SNMP Memory Corruption Vulnerability."
nvd
CVE-2005-1218P3MEDIUMCVSS 5.0PoCvdatacenter_64-bitventerprise+5 more2005-08-10
CVE-2005-1218 [MEDIUM] CVE-2005-1218: The Microsoft Windows kernel in Microsoft Windows 2000 Server, Windows XP, and Windows Server 2003 a
The Microsoft Windows kernel in Microsoft Windows 2000 Server, Windows XP, and Windows Server 2003 allows remote attackers to cause a denial of service (crash) via crafted Remote Desktop Protocol (RDP) requests.
nvd
CVE-2004-0897P3CRITICALCVSS 10.0vr22005-01-11
CVE-2004-0897 [CRITICAL] CVE-2004-0897: The Indexing Service for Microsoft Windows XP and Server 2003 does not properly validate the length
The Indexing Service for Microsoft Windows XP and Server 2003 does not properly validate the length of a message, which allows remote attackers to execute arbitrary code via a buffer overflow attack.
nvd
CVE-2003-0659P3HIGHCVSS 7.2PoCventerpriseventerprise_64-bit+3 more2003-11-17
CVE-2003-0659 [HIGH] CVE-2003-0659: Buffer overflow in a function in User32.dll on Windows NT through Server 2003 allows local users to
Buffer overflow in a function in User32.dll on Windows NT through Server 2003 allows local users to execute arbitrary code via long (1) LB_DIR messages to ListBox or (2) CB_DIR messages to ComboBox controls in a privileged application.
nvd
CVE-2006-4696P3CRITICALCVSS 9.0vr2vsp12006-10-10
CVE-2006-4696 [CRITICAL] CWE-94 CVE-2006-4696: Unspecified vulnerability in the Server service in Microsoft Windows 2000 SP4, Server 2003 SP1 and e
Unspecified vulnerability in the Server service in Microsoft Windows 2000 SP4, Server 2003 SP1 and earlier, and XP SP2 and earlier allows remote attackers to execute arbitrary code via a crafted packet, aka "SMB Rename Vulnerability."
nvd
CVE-2005-1206P3HIGHCVSS 7.5vr2vsp12005-06-14
CVE-2005-1206 [HIGH] CVE-2005-1206: Buffer overflow in the Server Message Block (SMB) functionality for Microsoft Windows 2000, XP SP1 a
Buffer overflow in the Server Message Block (SMB) functionality for Microsoft Windows 2000, XP SP1 and SP2, and Server 2003 and SP1 allows remote attackers to execute arbitrary code via unknown vectors, aka the "Server Message Block Vulnerability."
nvd
CVE-2004-1305P3MEDIUMCVSS 5.0PoCventerpriseventerprise_64-bit+3 more2004-12-23
CVE-2004-1305 [MEDIUM] CVE-2004-1305: The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP thr
The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allow remote attackers to cause a denial of service via (1) the frame number set to zero, which causes an invalid memory address to be used and leads to a kernel crash, or (2) the rate number set to zero, which leads to resource exhau
nvd
CVE-2005-2122P3CRITICALCVSS 10.0vr22005-10-21
CVE-2005-2122 [CRITICAL] CVE-2005-2122: Windows Shell for Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote attacker
Windows Shell for Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote attackers to execute arbitrary commands via a shortcut (.lnk) file with long font properties that lead to a buffer overflow in the Client/Server Runtime Server Subsystem (CSRSS), a different vulnerability than CVE-2005-2118.
nvd
CVE-2003-0469P3HIGHCVSS 7.5PoCv64-bitvr22003-08-07
CVE-2003-0469 [HIGH] CVE-2003-0469: Buffer overflow in the HTML Converter (HTML32.cnv) on various Windows operating systems allows remot
Buffer overflow in the HTML Converter (HTML32.cnv) on various Windows operating systems allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via cut-and-paste operation, as demonstrated in Internet Explorer 5.0 using a long "align" argument in an HR tag.
nvd
CVE-2007-2219P3CRITICALCVSS 9.3vsp1vsp22007-06-12
CVE-2007-2219 [CRITICAL] CVE-2007-2219: Unspecified vulnerability in the Win32 API on Microsoft Windows 2000, XP SP2, and Server 2003 SP1 an
Unspecified vulnerability in the Win32 API on Microsoft Windows 2000, XP SP2, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via certain parameters to an unspecified function.
nvd
CVE-2006-0143P3HIGHCVSS 7.5PoCvdatacenter_64-bitventerprise+5 more2006-01-09
CVE-2006-0143 [HIGH] CWE-399 CVE-2006-0143: Microsoft Windows Graphics Rendering Engine (GRE) allows remote attackers to corrupt memory and caus
Microsoft Windows Graphics Rendering Engine (GRE) allows remote attackers to corrupt memory and cause a denial of service (crash) via a WMF file containing (1) ExtCreateRegion or (2) ExtEscape function calls with arguments with inconsistent lengths.
nvd
CVE-2009-1545P3CRITICALCVSS 9.3vsp22009-08-12
CVE-2009-1545 [CRITICAL] CWE-94 CVE-2009-1545: Unspecified vulnerability in Avifil32.dll in the Windows Media file handling functionality in Micros
Unspecified vulnerability in Avifil32.dll in the Windows Media file handling functionality in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a malformed header in a crafted AVI file, aka "Malformed AVI Header Vulnerability."
nvd
CVE-2006-4495P3HIGHCVSS 7.5PoCv2000_servervadvanced_server+2 more2006-08-31
CVE-2006-4495 [HIGH] CVE-2006-4495: Microsoft Internet Explorer allows remote attackers to cause a denial of service (memory corruption)
Microsoft Internet Explorer allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code by instantiating certain Windows 2000 ActiveX COM Objects including (1) ciodm.dll, (2) myinfo.dll, (3) msdxm.ocx, and (4) creator.dll.
nvd
CVE-2005-2119P3MEDIUMCVSS 5.0PoCv64-bitvitanium+2 more2005-10-12
CVE-2005-2119 [MEDIUM] CVE-2005-2119: The MIDL_user_allocate function in the Microsoft Distributed Transaction Coordinator (MSDTC) proxy (
The MIDL_user_allocate function in the Microsoft Distributed Transaction Coordinator (MSDTC) proxy (MSDTCPRX.DLL) allocates a 4K page of memory regardless of the required size, which allows attackers to overwrite arbitrary memory locations using an incorrect size value that is provided to the NdrAllocate function, which writes management data to memory outsid
nvd