Microsoft Windows 2003 Server vulnerabilities
176 known vulnerabilities affecting microsoft/windows_2003_server.
Total CVEs
176
CISA KEV
1
actively exploited
Public exploits
67
Exploited in wild
15
Severity breakdown
CRITICAL40HIGH73MEDIUM48LOW15
Vulnerabilities
Page 5 of 9
CVE-2009-1544P3HIGHCVSS 8.8vsp22009-08-12
CVE-2009-1544 [HIGH] CWE-399 CVE-2009-1544: Double free vulnerability in the Workstation service in Microsoft Windows allows remote authenticate
Double free vulnerability in the Workstation service in Microsoft Windows allows remote authenticated users to gain privileges via a crafted RPC message to a Windows XP SP2 or SP3 or Server 2003 SP2 system, or cause a denial of service via a crafted RPC message to a Vista Gold, SP1, or SP2 or Server 2008 Gold or SP2 system, aka "Workstation Service Memo
nvd
CVE-2004-0568P3CRITICALCVSS 10.0vdatacenter_64-bitventerprise+4 more2005-01-10
CVE-2004-0568 [CRITICAL] CVE-2004-0568: HyperTerminal application for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does
HyperTerminal application for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the length of a value that is saved in a session file, which allows remote attackers to execute arbitrary code via a malicious HyperTerminal session file (.ht), web site, or Telnet URL contained in an e-mail message, triggering a buffer
nvd
CVE-2006-3880P4MEDIUMCVSS 5.0PoCvdatacenter_editionvdatacenter_edition_64-bit+8 more2006-07-27
CVE-2006-3880 [MEDIUM] CVE-2006-3880: Microsoft Windows NT 4.0, Windows 2000, Windows XP, and Windows Small Business Server 2003 allow rem
Microsoft Windows NT 4.0, Windows 2000, Windows XP, and Windows Small Business Server 2003 allow remote attackers to cause a denial of service (IP stack hang) via a continuous stream of packets on TCP port 135 that have incorrect TCP header checksums and random numbers in certain TCP header fields, as demonstrated by the Achilles Windows Attack Tool. NOTE: th
nvd
CVE-2005-0044P3HIGHCVSS 7.5venterpriseventerprise_64-bit+3 more2005-05-02
CVE-2005-0044 [HIGH] CVE-2005-0044: The OLE component in Windows 98, 2000, XP, and Server 2003, and Exchange Server 5.0 through 2003, do
The OLE component in Windows 98, 2000, XP, and Server 2003, and Exchange Server 5.0 through 2003, does not properly validate the lengths of messages for certain OLE data, which allows remote attackers to execute arbitrary code, aka the "Input Validation Vulnerability."
nvd
CVE-2006-6901P3CRITICALCVSS 10.0vr22006-12-31
CVE-2006-6901 [CRITICAL] CVE-2006-6901: Unspecified vulnerability in the Bluetooth stack in Microsoft Windows allows remote attackers to gai
Unspecified vulnerability in the Bluetooth stack in Microsoft Windows allows remote attackers to gain administrative access (aka Remote Root) via unspecified vectors.
nvd
CVE-2009-1546P3HIGHCVSS 8.5vsp22009-08-12
CVE-2009-1546 [HIGH] CWE-189 CVE-2009-1546: Integer overflow in Avifil32.dll in the Windows Media file handling functionality in Microsoft Windo
Integer overflow in Avifil32.dll in the Windows Media file handling functionality in Microsoft Windows allows remote attackers to execute arbitrary code on a Windows 2000 SP4 system via a crafted AVI file, or cause a denial of service on a Windows XP SP2 or SP3, Server 2003 SP2, Vista Gold, SP1, or SP2, or Server 2008 Gold or SP2 system via a crafted AV
nvd
CVE-2006-2371P3HIGHCVSS 7.5vdatacenter_editionvdatacenter_edition_64-bit+8 more2006-06-13
CVE-2006-2371 [HIGH] CVE-2006-2371: Buffer overflow in the Remote Access Connection Manager service (RASMAN) service in Microsoft Window
Buffer overflow in the Remote Access Connection Manager service (RASMAN) service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote unauthenticated or authenticated attackers to execute arbitrary code via certain crafted "RPC related requests," that lead to registry corruption and stack corruption, aka the "RASMAN Regis
nvd
CVE-2004-0901P3CRITICALCVSS 10.0venterpriseventerprise_64-bit+3 more2005-01-10
CVE-2004-0901 [CRITICAL] CVE-2004-0901: Microsoft Word for Windows 6.0 Converter (MSWRD632.WPC), as used in WordPad, does not properly valid
Microsoft Word for Windows 6.0 Converter (MSWRD632.WPC), as used in WordPad, does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka "Font Conversion Vulnerability," a different vulnerability than CVE-2004-0571.
nvd
CVE-2006-6902P3CRITICALCVSS 10.0vmobile_pocket_pc2006-12-31
CVE-2006-6902 [CRITICAL] CVE-2006-6902: Unspecified vulnerability in the Bluetooth stack in Microsoft Windows Mobile Pocket PC edition allow
Unspecified vulnerability in the Bluetooth stack in Microsoft Windows Mobile Pocket PC edition allows remote attackers to gain administrative access (aka Remote Root) via unspecified vectors.
nvd
CVE-2005-1979P4MEDIUMCVSS 5.0PoCv64-bitvitanium+2 more2005-10-12
CVE-2005-1979 [MEDIUM] CVE-2005-1979: Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of s
Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC service exception and exit) via an "unexpected protocol command during the reconnection request," which is not properly handled by the Transaction Internet Protocol (TIP) functionality.
nvd
CVE-2004-0571P3CRITICALCVSS 10.0venterpriseventerprise_64-bit+3 more2005-01-10
CVE-2004-0571 [CRITICAL] CVE-2004-0571: Microsoft Word for Windows 6.0 Converter does not properly validate certain data lengths, which allo
Microsoft Word for Windows 6.0 Converter does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka "Table Conversion Vulnerability," a different vulnerability than CVE-2004-0901.
nvd
CVE-2007-1215P4HIGHCVSS 7.2PoCvgoldvsp1+1 more2007-04-04
CVE-2007-1215 [HIGH] CVE-2007-1215: Buffer overflow in the Graphics Device Interface (GDI) in Microsoft Windows 2000 SP4; XP SP2; Server
Buffer overflow in the Graphics Device Interface (GDI) in Microsoft Windows 2000 SP4; XP SP2; Server 2003 Gold, SP1, and SP2; and Vista allows local users to gain privileges via certain "color-related parameters" in crafted images.
nvd
CVE-2005-1980P4MEDIUMCVSS 5.0PoCv64-bitvitanium+2 more2005-10-12
CVE-2005-1980 [MEDIUM] CVE-2005-1980: Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of s
Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC service hang) via a crafted Transaction Internet Protocol (TIP) message that causes DTC to repeatedly connect to a target IP and port number after an error occurs, aka the "Distributed TIP Vulnerability."
nvd
CVE-2003-0715P3CRITICALCVSS 10.0venterpriseventerprise_64-bit+3 more2003-09-17
CVE-2003-0715 [CRITICAL] CVE-2003-0715: Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS S
Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed DCERPC DCOM object activation request packet with modified length fields, a different vulnerability than CVE-2003-0352 (Blaster/Nachi) and CVE-2003-0528.
nvd
CVE-2005-1649P4MEDIUMCVSS 5.0PoCvdatacenter_64-bitventerprise+4 more2005-05-18
CVE-2005-1649 [MEDIUM] CVE-2005-1649: The IPv6 support in Windows XP SP2, 2003 Server SP1, and Longhorn, with Windows Firewall turned off,
The IPv6 support in Windows XP SP2, 2003 Server SP1, and Longhorn, with Windows Firewall turned off, allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet with the SYN flag set and the same destination and source address and port, a variant of CVE-2005-0688 and a reoccurrence of the "Land" vulnerability (CVE-1999-0016).
nvd
CVE-2005-1184P4MEDIUMCVSS 5.0PoCvdatacenter_64-bitventerprise+5 more2005-05-02
CVE-2005-1184 [MEDIUM] CVE-2005-1184: The TCP/IP stack in multiple operating systems allows remote attackers to cause a denial of service
The TCP/IP stack in multiple operating systems allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet with the correct sequence number but the wrong Acknowledgement number, which generates a large number of "keep alive" packets. NOTE: some followups indicate that this issue could not be replicated.
nvd
CVE-2006-6696P4MEDIUMCVSS 6.9PoCvdatacenter_editionventerprise_edition+3 more2006-12-22
CVE-2006-6696 [MEDIUM] CWE-119 CVE-2006-6696: Double free vulnerability in Microsoft Windows 2000, XP, 2003, and Vista allows local users to gain
Double free vulnerability in Microsoft Windows 2000, XP, 2003, and Vista allows local users to gain privileges by calling the MessageBox function with a MB_SERVICE_NOTIFICATION message with crafted data, which sends a HardError message to Client/Server Runtime Server Subsystem (CSRSS) process, which is not properly handled when invoking the UserHardErr
nvd
CVE-2006-3648P3HIGHCVSS 7.6vr2vsp12006-08-09
CVE-2006-3648 [HIGH] CVE-2006-3648: Unspecified vulnerability in Microsoft Windows 2000 SP4, XP SP1 and SP2, Server 2003 and 2003 SP1, a
Unspecified vulnerability in Microsoft Windows 2000 SP4, XP SP1 and SP2, Server 2003 and 2003 SP1, allows remote attackers to execute arbitrary code via unspecified vectors involving unhandled exceptions, memory resident applications, and incorrectly "unloading chained exception."
nvd
CVE-2005-0057P3HIGHCVSS 7.5venterpriseventerprise_64-bit+3 more2005-05-02
CVE-2005-0057 [HIGH] CVE-2005-0057: The Hyperlink Object Library for Windows 98, 2000, XP, and Server 2003 allows remote attackers to ex
The Hyperlink Object Library for Windows 98, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary code via a crafted link that triggers an "unchecked buffer" in the library, possibly due to a buffer overflow.
nvd
CVE-2003-0711P3HIGHCVSS 7.5venterpriseventerprise_64-bit+3 more2003-11-17
CVE-2003-0711 [HIGH] CVE-2003-0711: Stack-based buffer overflow in the PCHealth system in the Help and Support Center function in Window
Stack-based buffer overflow in the PCHealth system in the Help and Support Center function in Windows XP and Windows Server 2003 allows remote attackers to execute arbitrary code via a long query in an HCP URL.
nvd