Microsoft Windows 2003 Server vulnerabilities

176 known vulnerabilities affecting microsoft/windows_2003_server.

Total CVEs
176
CISA KEV
1
actively exploited
Public exploits
65
Exploited in wild
2
Severity breakdown
CRITICAL40HIGH73MEDIUM48LOW15

Vulnerabilities

Page 4 of 9
CVE-2006-2379CRITICALCVSS 9.3PoCvdatacenter_64-bitventerprise+5 more2006-06-13
CVE-2006-2379 [CRITICAL] CWE-119 CVE-2006-2379: Buffer overflow in the TCP/IP Protocol driver in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Ser Buffer overflow in the TCP/IP Protocol driver in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote attackers to execute arbitrary code via unknown vectors related to IP source routing.
nvd
CVE-2006-2371HIGHCVSS 7.5vdatacenter_editionvdatacenter_edition_64-bit+8 more2006-06-13
CVE-2006-2371 [HIGH] CVE-2006-2371: Buffer overflow in the Remote Access Connection Manager service (RASMAN) service in Microsoft Window Buffer overflow in the Remote Access Connection Manager service (RASMAN) service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote unauthenticated or authenticated attackers to execute arbitrary code via certain crafted "RPC related requests," that lead to registry corruption and stack corruption, aka the "RASMAN Regis
nvd
CVE-2006-2370HIGHCVSS 7.5PoCvdatacenter_editionvdatacenter_edition_64-bit+8 more2006-06-13
CVE-2006-2370 [HIGH] CVE-2006-2370: Buffer overflow in the Routing and Remote Access service (RRAS) in Microsoft Windows 2000 SP4, XP SP Buffer overflow in the Routing and Remote Access service (RRAS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote unauthenticated or authenticated attackers to execute arbitrary code via certain crafted "RPC related requests," aka the "RRAS Memory Corruption Vulnerability."
nvd
CVE-2006-2378MEDIUMCVSS 6.8vdatacenter_editionvdatacenter_edition_64-bit+8 more2006-06-13
CVE-2006-2378 [MEDIUM] CVE-2006-2378: Buffer overflow in the ART Image Rendering component (jgdw400.dll) in Microsoft Windows XP SP1 and S Buffer overflow in the ART Image Rendering component (jgdw400.dll) in Microsoft Windows XP SP1 and Sp2, Server 2003 SP1 and earlier, and Windows 98 and Me allows remote attackers to execute arbitrary code via a crafted ART image that causes heap corruption.
nvd
CVE-2006-1313MEDIUMCVSS 6.8vdatacenter_editionvdatacenter_edition_64-bit+8 more2006-06-13
CVE-2006-1313 [MEDIUM] CVE-2006-1313: Microsoft JScript 5.1, 5.5, and 5.6 on Windows 2000 SP4, and 5.6 on Windows XP, Server 2003, Windows Microsoft JScript 5.1, 5.5, and 5.6 on Windows 2000 SP4, and 5.6 on Windows XP, Server 2003, Windows 98 and Windows Me, will "release objects early" in certain cases, which results in memory corruption and allows remote attackers to execute arbitrary code.
nvd
CVE-2006-0034HIGHCVSS 7.5venterpriseventerprise_64-bit+3 more2006-05-10
CVE-2006-0034 [HIGH] CWE-119 CVE-2006-0034: Heap-based buffer overflow in the CRpcIoManagerServer::BuildContext function in msdtcprx.dll for Mic Heap-based buffer overflow in the CRpcIoManagerServer::BuildContext function in msdtcprx.dll for Microsoft Distributed Transaction Coordinator (MSDTC) for Windows NT 4.0 and Windows 2000 SP2 and SP3 allows remote attackers to execute arbitrary code via a long fifth argument to the BuildContextW or BuildContext opcode, which triggers a bug in the NdrAllo
nvd
CVE-2006-1184MEDIUMCVSS 5.0venterpriseventerprise_64-bit+3 more2006-05-10
CVE-2006-1184 [MEDIUM] CVE-2006-1184: Microsoft Distributed Transaction Coordinator (MSDTC) for Windows NT 4.0, 2000 SP4, XP SP1 and SP2, Microsoft Distributed Transaction Coordinator (MSDTC) for Windows NT 4.0, 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote attackers to cause a denial of service (crash) via a BuildContextW request with a large (1) UuidString or (2) GuidIn of a certain length, which causes an out-of-range memory access, aka the MSDTC Denial of Service Vulnerability. NOT
nvd
CVE-2006-0012MEDIUMCVSS 5.1vdatacenter_64-bitventerprise+5 more2006-04-12
CVE-2006-0012 [MEDIUM] CVE-2006-0012: Unspecified vulnerability in Windows Explorer in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Ser Unspecified vulnerability in Windows Explorer in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via attack vectors involving COM objects and "crafted files and directories," aka the "Windows Shell Vulnerability."
nvd
CVE-2006-1591MEDIUMCVSS 5.1venterprisevr2+2 more2006-04-03
CVE-2006-1591 [MEDIUM] CVE-2006-1591: Heap-based buffer overflow in Microsoft Windows Help winhlp32.exe allows user-assisted attackers to Heap-based buffer overflow in Microsoft Windows Help winhlp32.exe allows user-assisted attackers to execute arbitrary code via crafted embedded image data in a .hlp file.
nvd
CVE-2006-0988HIGHCVSS 7.8vr22006-03-03
CVE-2006-0988 [HIGH] CVE-2006-0988: The default configuration of the DNS Server service on Windows Server 2003 and Windows 2000, and the The default configuration of the DNS Server service on Windows Server 2003 and Windows 2000, and the Microsoft DNS Server service on Windows NT 4.0, allows recursive queries and provides additional delegation information to arbitrary IP addresses, which allows remote attackers to cause a denial of service (traffic amplification) via DNS queries with spoofed sou
nvd
CVE-2006-0005CRITICALCVSS 9.3PoCvdatacenter_editionvdatacenter_edition_64-bit+5 more2006-02-14
CVE-2006-0005 [CRITICAL] CWE-119 CVE-2006-0005: Buffer overflow in the plug-in for Microsoft Windows Media Player (WMP) 9 and 10, when used in brows Buffer overflow in the plug-in for Microsoft Windows Media Player (WMP) 9 and 10, when used in browsers other than Internet Explorer and set as the default application to handle media files, allows remote attackers to execute arbitrary code via HTML with an EMBED element containing a long src attribute.
nvd
CVE-2006-0006CRITICALCVSS 9.3PoCvr22006-02-14
CVE-2006-0006 [CRITICAL] CWE-119 CVE-2006-0006: Heap-based buffer overflow in the bitmap processing routine in Microsoft Windows Media Player 7.1 on Heap-based buffer overflow in the bitmap processing routine in Microsoft Windows Media Player 7.1 on Windows 2000 SP4, Media Player 9 on Windows 2000 SP4 and XP SP1, and Media Player 10 on XP SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted bitmap (.BMP) file that specifies a size of 0 but contains additional data.
nvd
CVE-2006-0008HIGHCVSS 7.2vdatacenter_64-bitventerprise+5 more2006-02-14
CVE-2006-0008 [HIGH] CWE-264 CVE-2006-0008: The ShellAbout API call in Korean Input Method Editor (IME) in Korean versions of Microsoft Windows The ShellAbout API call in Korean Input Method Editor (IME) in Korean versions of Microsoft Windows XP SP1 and SP2, Windows Server 2003 up to SP1, and Office 2003, allows local users to gain privileges by launching the "shell about dialog box" and clicking the "End-User License Agreement" link, which executes Notepad with the privileges of the program th
nvd
CVE-2006-0021HIGHCVSS 7.8PoCvdatacenter_64-bitventerprise+5 more2006-02-14
CVE-2006-0021 [HIGH] CWE-119 CVE-2006-0021: Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote attackers to cause a deni Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote attackers to cause a denial of service (hang) via an IGMP packet with an invalid IP option, aka the "IGMP v3 DoS Vulnerability."
nvd
CVE-2006-0013MEDIUMCVSS 6.5vdatacenter_64-bitventerprise+5 more2006-02-14
CVE-2006-0013 [MEDIUM] CVE-2006-0013: Buffer overflow in the Web Client service (WebClnt.dll) for Microsoft Windows XP SP1 and SP2, and Se Buffer overflow in the Web Client service (WebClnt.dll) for Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote authenticated users or Guests to execute arbitrary code via crafted RPC requests, a different vulnerability than CVE-2005-1207.
nvd
CVE-2006-0488LOWCVSS 2.1vr22006-02-01
CVE-2006-0488 [LOW] CVE-2006-0488: The VDM (Virtual DOS Machine) emulation environment for MS-DOS applications in Windows 2000, Windows The VDM (Virtual DOS Machine) emulation environment for MS-DOS applications in Windows 2000, Windows XP SP2, and Windows Server 2003 allows local users to read the first megabyte of memory and possibly obtain sensitive information, as demonstrated by dumper.asm.
nvd
CVE-2006-0376HIGHCVSS 7.5vr22006-01-22
CVE-2006-0376 [HIGH] CVE-2006-0376: The 802.11 wireless client in certain operating systems including Windows 2000, Windows XP, and Wind The 802.11 wireless client in certain operating systems including Windows 2000, Windows XP, and Windows Server 2003 does not warn the user when (1) it establishes an association with a station in ad hoc (aka peer-to-peer) mode or (2) a station in ad hoc mode establishes an association with it, which allows remote attackers to put unexpected wireless communicati
nvd
CVE-2006-0020CRITICALCVSS 9.3vr2vsp12006-01-10
CVE-2006-0020 [CRITICAL] CVE-2006-0020: An unspecified Microsoft WMF parsing application, as used in Internet Explorer 5.01 SP4 on Windows 2 An unspecified Microsoft WMF parsing application, as used in Internet Explorer 5.01 SP4 on Windows 2000 SP4, and 5.5 SP2 on Windows Millennium, and possibly other versions, allows attackers to cause a denial of service (crash) and possibly execute code via a crafted WMF file with a manipulated WMF header size, possibly involving an integer overflow, a diffe
nvd
CVE-2006-0010CRITICALCVSS 9.3vdatacenter_64-bitventerprise+5 more2006-01-10
CVE-2006-0010 [CRITICAL] CWE-119 CVE-2006-0010: Heap-based buffer overflow in T2EMBED.DLL in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server Heap-based buffer overflow in T2EMBED.DLL in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1, Windows 98, and Windows ME allows remote attackers to execute arbitrary code via an e-mail message or web page with a crafted Embedded Open Type (EOT) web font that triggers the overflow during decompression.
nvd
CVE-2006-0143HIGHCVSS 7.5PoCvdatacenter_64-bitventerprise+5 more2006-01-09
CVE-2006-0143 [HIGH] CWE-399 CVE-2006-0143: Microsoft Windows Graphics Rendering Engine (GRE) allows remote attackers to corrupt memory and caus Microsoft Windows Graphics Rendering Engine (GRE) allows remote attackers to corrupt memory and cause a denial of service (crash) via a WMF file containing (1) ExtCreateRegion or (2) ExtEscape function calls with arguments with inconsistent lengths.
nvd