Microsoft Windows 2003 Server vulnerabilities
176 known vulnerabilities affecting microsoft/windows_2003_server.
Total CVEs
176
CISA KEV
1
actively exploited
Public exploits
67
Exploited in wild
15
Severity breakdown
CRITICAL40HIGH73MEDIUM48LOW15
Vulnerabilities
Page 6 of 9
CVE-2006-2378P3MEDIUMCVSS 6.8vdatacenter_editionvdatacenter_edition_64-bit+8 more2006-06-13
CVE-2006-2378 [MEDIUM] CVE-2006-2378: Buffer overflow in the ART Image Rendering component (jgdw400.dll) in Microsoft Windows XP SP1 and S
Buffer overflow in the ART Image Rendering component (jgdw400.dll) in Microsoft Windows XP SP1 and Sp2, Server 2003 SP1 and earlier, and Windows 98 and Me allows remote attackers to execute arbitrary code via a crafted ART image that causes heap corruption.
nvd
CVE-2004-0894P4HIGHCVSS 7.2PoCvdatacenter_64-bitventerprise+4 more2005-01-10
CVE-2004-0894 [HIGH] CVE-2004-0894: LSASS (Local Security Authority Subsystem Service) of Windows 2000 Server and Windows Server 2003 do
LSASS (Local Security Authority Subsystem Service) of Windows 2000 Server and Windows Server 2003 does not properly validate connection information, which allows local users to gain privileges via a specially-designed program.
nvd
CVE-2007-0026P3HIGHCVSS 7.6vsp12007-02-13
CVE-2007-0026 [HIGH] CVE-2007-0026: The OLE Dialog component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1 allows user-assisted re
The OLE Dialog component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1 allows user-assisted remote attackers to execute arbitrary code via an RTF file with a malformed OLE object that triggers memory corruption.
nvd
CVE-2007-2374P3CRITICALCVSS 9.3vdatacenterventerprise+3 more2007-04-30
CVE-2007-2374 [CRITICAL] CVE-2007-2374: Unspecified vulnerability in Microsoft Windows 2000, XP, and Server 2003 allows user-assisted remote
Unspecified vulnerability in Microsoft Windows 2000, XP, and Server 2003 allows user-assisted remote attackers to execute arbitrary code via unspecified vectors. NOTE: this information is based upon a vague pre-advisory with no actionable information. However, the advisory is from a reliable source.
nvd
CVE-2004-0117P3HIGHCVSS 7.5vr22004-06-01
CVE-2004-0117 [HIGH] CVE-2004-0117: Unknown vulnerability in the H.323 protocol implementation in Windows 98, Windows 2000, Windows XP,
Unknown vulnerability in the H.323 protocol implementation in Windows 98, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code.
nvd
CVE-2006-0032P4MEDIUMCVSS 4.3PoCvdatacenter_editionvdatacenter_edition_itanium+8 more2006-09-12
CVE-2006-0032 [MEDIUM] CWE-79 CVE-2006-0032: Cross-site scripting (XSS) vulnerability in the Indexing Service in Microsoft Windows 2000, XP, and
Cross-site scripting (XSS) vulnerability in the Indexing Service in Microsoft Windows 2000, XP, and Server 2003, when the Encoding option is set to Auto Select, allows remote attackers to inject arbitrary web script or HTML via a UTF-7 encoded URL, which is injected into an error message whose charset is set to UTF-7.
nvd
CVE-2007-1212P4MEDIUMCVSS 6.6PoCvgoldvsp1+1 more2007-04-04
CVE-2007-1212 [MEDIUM] CVE-2007-1212: Buffer overflow in the Graphics Device Interface (GDI) in Microsoft Windows 2000 SP4; XP SP2; Server
Buffer overflow in the Graphics Device Interface (GDI) in Microsoft Windows 2000 SP4; XP SP2; Server 2003 Gold, SP1, and SP2; and Vista allows local users to gain privileges via a crafted Enhanced Metafile (EMF) image format file.
nvd
CVE-2006-0013P3MEDIUMCVSS 6.5vdatacenter_64-bitventerprise+5 more2006-02-14
CVE-2006-0013 [MEDIUM] CVE-2006-0013: Buffer overflow in the Web Client service (WebClnt.dll) for Microsoft Windows XP SP1 and SP2, and Se
Buffer overflow in the Web Client service (WebClnt.dll) for Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote authenticated users or Guests to execute arbitrary code via crafted RPC requests, a different vulnerability than CVE-2005-1207.
nvd
CVE-2006-0376P3HIGHCVSS 7.5vr22006-01-22
CVE-2006-0376 [HIGH] CVE-2006-0376: The 802.11 wireless client in certain operating systems including Windows 2000, Windows XP, and Wind
The 802.11 wireless client in certain operating systems including Windows 2000, Windows XP, and Windows Server 2003 does not warn the user when (1) it establishes an association with a station in ad hoc (aka peer-to-peer) mode or (2) a station in ad hoc mode establishes an association with it, which allows remote attackers to put unexpected wireless communicati
nvd
CVE-2005-2118P3MEDIUMCVSS 5.1vr22005-10-21
CVE-2005-2118 [MEDIUM] CVE-2005-2118: Windows Shell for Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote user-ass
Windows Shell for Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote user-assisted attackers to execute arbitrary commands via a crafted shortcut (.lnk) file with long font properties that lead to a buffer overflow when the user views the file's properties using Windows Explorer, a different vulnerability than CVE-2005-2122.
nvd
CVE-2006-1313P3MEDIUMCVSS 6.8vdatacenter_editionvdatacenter_edition_64-bit+8 more2006-06-13
CVE-2006-1313 [MEDIUM] CVE-2006-1313: Microsoft JScript 5.1, 5.5, and 5.6 on Windows 2000 SP4, and 5.6 on Windows XP, Server 2003, Windows
Microsoft JScript 5.1, 5.5, and 5.6 on Windows 2000 SP4, and 5.6 on Windows XP, Server 2003, Windows 98 and Windows Me, will "release objects early" in certain cases, which results in memory corruption and allows remote attackers to execute arbitrary code.
nvd
CVE-2006-4702P3MEDIUMCVSS 6.8vgoldvsp12006-12-13
CVE-2006-4702 [MEDIUM] CVE-2006-4702: Buffer overflow in the Windows Media Format Runtime in Microsoft Windows Media Player (WMP) 6.4 and
Buffer overflow in the Windows Media Format Runtime in Microsoft Windows Media Player (WMP) 6.4 and Windows XP SP2, Server 2003, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted Advanced Systems Format (ASF) file.
nvd
CVE-2007-2218P3CRITICALCVSS 9.3vsp1vsp22007-06-12
CVE-2007-2218 [CRITICAL] CVE-2007-2218: Unspecified vulnerability in the Windows Schannel Security Package for Microsoft Windows 2000 SP4, X
Unspecified vulnerability in the Windows Schannel Security Package for Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2, allows remote servers to execute arbitrary code or cause a denial of service via crafted digital signatures that are processed during an SSL handshake.
nvd
CVE-2005-1212P3HIGHCVSS 7.5v64-bitvdatacenter_64-bit+6 more2005-06-14
CVE-2005-1212 [HIGH] CVE-2005-1212: Buffer overflow in Microsoft Step-by-Step Interactive Training (orun32.exe) allows remote attackers
Buffer overflow in Microsoft Step-by-Step Interactive Training (orun32.exe) allows remote attackers to execute arbitrary code via a bookmark link file (.cbo, cbl, or .cbm extension) with a long User field.
nvd
CVE-2006-0012P3MEDIUMCVSS 5.1vdatacenter_64-bitventerprise+5 more2006-04-12
CVE-2006-0012 [MEDIUM] CVE-2006-0012: Unspecified vulnerability in Windows Explorer in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Ser
Unspecified vulnerability in Windows Explorer in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via attack vectors involving COM objects and "crafted files and directories," aka the "Windows Shell Vulnerability."
nvd
CVE-2003-0660P3HIGHCVSS 7.5venterpriseventerprise_64-bit+3 more2003-11-17
CVE-2003-0660 [HIGH] CVE-2003-0660: The Authenticode capability in Microsoft Windows NT through Server 2003 does not prompt the user to
The Authenticode capability in Microsoft Windows NT through Server 2003 does not prompt the user to download and install ActiveX controls when the system is low on memory, which could allow remote attackers to execute arbitrary code without user approval.
nvd
CVE-2006-3873P3HIGHCVSS 7.5v64-bitvitanium+2 more2006-09-12
CVE-2006-3873 [HIGH] CVE-2006-3873: Heap-based buffer overflow in URLMON.DLL in Microsoft Internet Explorer 6 SP1 on Windows 2000 and XP
Heap-based buffer overflow in URLMON.DLL in Microsoft Internet Explorer 6 SP1 on Windows 2000 and XP SP1, with versions the MS06-042 patch before 20060912, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long URL in a GZIP-encoded website that was the target of an HTTP redirect, due to an incomplete fix for CVE-2006-
nvd
CVE-2005-4717P4MEDIUMCVSS 5.0PoCvsp12005-12-31
CVE-2005-4717 [MEDIUM] CVE-2005-4717: Microsoft Internet Explorer 6.0 on Windows NT 4.0 SP6a, Windows 2000 SP4, Windows XP SP1, Windows XP
Microsoft Internet Explorer 6.0 on Windows NT 4.0 SP6a, Windows 2000 SP4, Windows XP SP1, Windows XP SP2, and Windows Server 2003 SP1 allows remote attackers to cause a denial of service (client crash) via a certain combination of a malformed HTML file and a CSS file that triggers a null dereference, probably related to rendering of a DIV element that contain
nvd
CVE-2007-3091P3HIGHCVSS 7.1vsp1vsp22007-06-06
CVE-2007-3091 [HIGH] CWE-362 CVE-2007-3091: Race condition in Microsoft Internet Explorer 6 SP1; 6 and 7 for Windows XP SP2 and SP3; 6 and 7 for
Race condition in Microsoft Internet Explorer 6 SP1; 6 and 7 for Windows XP SP2 and SP3; 6 and 7 for Server 2003 SP2; 7 for Vista Gold, SP1, and SP2; and 7 for Server 2008 SP2 allows remote attackers to execute arbitrary code or perform other actions upon a page transition, with the permissions of the old page and the content of the new page, as demonst
nvd
CVE-2005-2117P3MEDIUMCVSS 5.1vr22005-10-21
CVE-2005-2117 [MEDIUM] CVE-2005-2117: Web View in Windows Explorer on Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 does not
Web View in Windows Explorer on Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 does not properly handle certain HTML characters in preview fields, which allows remote user-assisted attackers to execute arbitrary code.
nvd