Microsoft Windows 2003 Server vulnerabilities
176 known vulnerabilities affecting microsoft/windows_2003_server.
Total CVEs
176
CISA KEV
1
actively exploited
Public exploits
67
Exploited in wild
15
Severity breakdown
CRITICAL40HIGH73MEDIUM48LOW15
Vulnerabilities
Page 7 of 9
CVE-2006-4071P4LOWCVSS 2.6PoCvr2vsp12006-08-10
CVE-2006-4071 [LOW] CVE-2006-4071: Sign extension vulnerability in the createBrushIndirect function in the GDI library (gdi32.dll) in M
Sign extension vulnerability in the createBrushIndirect function in the GDI library (gdi32.dll) in Microsoft Windows XP, Server 2003, and possibly other versions, allows user-assisted attackers to cause a denial of service (application crash) via a crafted WMF file.
nvd
CVE-2007-1692P3HIGHCVSS 7.5v2000vr22007-03-26
CVE-2007-1692 [HIGH] CWE-16 CVE-2007-1692: The default configuration of Microsoft Windows uses the Web Proxy Autodiscovery Protocol (WPAD) with
The default configuration of Microsoft Windows uses the Web Proxy Autodiscovery Protocol (WPAD) without static WPAD entries, which might allow remote attackers to intercept web traffic by registering a proxy server using WINS or DNS, then responding to WPAD requests, as demonstrated using Internet Explorer. NOTE: it could be argued that if an attacker al
nvd
CVE-2005-3981P4MEDIUMCVSS 4.9PoCventerprisevr2+2 more2005-12-04
CVE-2005-3981 [MEDIUM] CVE-2005-3981: NOTE: this issue has been disputed by third parties. Microsoft Windows XP, 2000, and 2003 allows lo
NOTE: this issue has been disputed by third parties. Microsoft Windows XP, 2000, and 2003 allows local users to kill a writable process by using the CreateRemoteThread function with certain arguments on a process that has been opened using the OpenProcess function, possibly involving an invalid address for the start routine. NOTE: followup posts have disputed
nvd
CVE-2004-0199P3MEDIUMCVSS 5.1venterpriseventerprise_64-bit+3 more2004-06-14
CVE-2004-0199 [MEDIUM] CVE-2004-0199: Help and Support Center in Microsoft Windows XP and Windows Server 2003 SP1 does not properly valida
Help and Support Center in Microsoft Windows XP and Windows Server 2003 SP1 does not properly validate HCP URLs, which allows remote attackers to execute arbitrary code, as demonstrated using certain hcp:// URLs that access the DVD Upgrade capability (dvdupgrd.htm).
nvd
CVE-2004-0892P3HIGHCVSS 7.5v2000v20032005-01-27
CVE-2004-0892 [HIGH] CVE-2004-0892: Microsoft Proxy Server 2.0 and Microsoft ISA Server 2000 (which is included in Small Business Server
Microsoft Proxy Server 2.0 and Microsoft ISA Server 2000 (which is included in Small Business Server 2000 and Small Business Server 2003 Premium Edition) allows remote attackers to spoof trusted Internet content on a specially crafted webpage via spoofed reverse DNS lookup results.
nvd
CVE-2004-0123P3HIGHCVSS 7.5vr22004-06-01
CVE-2004-0123 [HIGH] CWE-119 CVE-2004-0123: Double free vulnerability in the ASN.1 library as used in Windows NT 4.0, Windows 2000, Windows XP,
Double free vulnerability in the ASN.1 library as used in Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service and possibly execute arbitrary code.
nvd
CVE-2006-0020P3CRITICALCVSS 9.3vr2vsp12006-01-10
CVE-2006-0020 [CRITICAL] CVE-2006-0020: An unspecified Microsoft WMF parsing application, as used in Internet Explorer 5.01 SP4 on Windows 2
An unspecified Microsoft WMF parsing application, as used in Internet Explorer 5.01 SP4 on Windows 2000 SP4, and 5.5 SP2 on Windows Millennium, and possibly other versions, allows attackers to cause a denial of service (crash) and possibly execute code via a crafted WMF file with a manipulated WMF header size, possibly involving an integer overflow, a diffe
nvd
CVE-2005-1205P4MEDIUMCVSS 5.0venterprisevr2+2 more2005-06-14
CVE-2005-1205 [MEDIUM] CVE-2005-1205: The Telnet client for Microsoft Windows XP, Windows Server 2003, and Windows Services for UNIX allow
The Telnet client for Microsoft Windows XP, Windows Server 2003, and Windows Services for UNIX allows remote attackers to read sensitive environment variables via the NEW-ENVIRON option with a SEND ENV_USERVAR command.
nvd
CVE-2003-0825P3CRITICALCVSS 9.3venterpriseventerprise_64-bit+3 more2004-03-03
CVE-2003-0825 [CRITICAL] CWE-20 CVE-2003-0825: The Windows Internet Naming Service (WINS) for Microsoft Windows Server 2003, and possibly Windows N
The Windows Internet Naming Service (WINS) for Microsoft Windows Server 2003, and possibly Windows NT and Server 2000, does not properly validate the length of certain packets, which allows attackers to cause a denial of service and possibly execute arbitrary code.
nvd
CVE-2008-0088P4MEDIUMCVSS 6.8vsp1vsp22008-02-12
CVE-2008-0088 [MEDIUM] CWE-20 CVE-2008-0088: Unspecified vulnerability in Active Directory on Microsoft Windows 2000 and Windows Server 2003, and
Unspecified vulnerability in Active Directory on Microsoft Windows 2000 and Windows Server 2003, and Active Directory Application Mode (ADAM) on XP and Server 2003, allows remote attackers to cause a denial of service (hang and restart) via a crafted LDAP request.
nvd
CVE-2004-1361P4MEDIUMCVSS 5.0venterpriseventerprise_64-bit+3 more2004-12-23
CVE-2004-1361 [MEDIUM] CVE-2004-1361: Integer underflow in winhlp32.exe in Windows NT, Windows 2000 through SP4, Windows XP through SP2, a
Integer underflow in winhlp32.exe in Windows NT, Windows 2000 through SP4, Windows XP through SP2, and Windows 2003 allows remote attackers to execute arbitrary code via a malformed .hlp file, which leads to a heap-based buffer overflow.
nvd
CVE-2005-1207P4HIGHCVSS 7.2vr22005-06-14
CVE-2005-1207 [HIGH] CVE-2005-1207: Buffer overflow in the Web Client service in Microsoft Windows XP and Windows Server 2003 allows rem
Buffer overflow in the Web Client service in Microsoft Windows XP and Windows Server 2003 allows remote authenticated users to execute arbitrary code via a crafted WebDAV request containing special parameters.
nvd
CVE-2003-0807P4MEDIUMCVSS 5.0vr22004-06-01
CVE-2003-0807 [MEDIUM] CVE-2003-0807: Buffer overflow in the COM Internet Services and in the RPC over HTTP Proxy components for Microsoft
Buffer overflow in the COM Internet Services and in the RPC over HTTP Proxy components for Microsoft Windows NT Server 4.0, NT 4.0 Terminal Server Edition, 2000, XP, and Server 2003 allows remote attackers to cause a denial of service via a crafted request.
nvd
CVE-2006-4689P4MEDIUMCVSS 5.0vsp12006-11-14
CVE-2006-4689 [MEDIUM] CVE-2006-4689: Unspecified vulnerability in the driver for the Client Service for NetWare (CSNW) in Microsoft Windo
Unspecified vulnerability in the driver for the Client Service for NetWare (CSNW) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 allows remote attackers to cause a denial of service (hang and reboot) via has unknown attack vectors, aka "NetWare Driver Denial of Service Vulnerability."
nvd
CVE-2015-2416P3MEDIUMCVSS 5.0vr22015-07-14
CVE-2015-2416 [MEDIUM] CWE-20 CVE-2015-2416: OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Win
OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to gain privileges via crafted input, as demonstrated by a transition from Low Integrity to Medium Integrity, aka "OLE Elevation of P
nvd
CVE-2015-2417P3MEDIUMCVSS 5.0vr22015-07-14
CVE-2015-2417 [MEDIUM] CVE-2015-2417: OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Win
OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to gain privileges via crafted input, as demonstrated by a transition from Low Integrity to Medium Integrity, aka "OLE Elevation of Privileg
nvd
CVE-2006-1184P4MEDIUMCVSS 5.0venterpriseventerprise_64-bit+3 more2006-05-10
CVE-2006-1184 [MEDIUM] CVE-2006-1184: Microsoft Distributed Transaction Coordinator (MSDTC) for Windows NT 4.0, 2000 SP4, XP SP1 and SP2,
Microsoft Distributed Transaction Coordinator (MSDTC) for Windows NT 4.0, 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote attackers to cause a denial of service (crash) via a BuildContextW request with a large (1) UuidString or (2) GuidIn of a certain length, which causes an out-of-range memory access, aka the MSDTC Denial of Service Vulnerability. NOT
nvd
CVE-2005-3945P4HIGHCVSS 7.8venterprisevr2+2 more2005-12-01
CVE-2005-3945 [HIGH] CVE-2005-3945: The SynAttackProtect protection in Microsoft Windows 2003 before SP1 and Windows 2000 before SP4 wit
The SynAttackProtect protection in Microsoft Windows 2003 before SP1 and Windows 2000 before SP4 with Update Roll-up uses a hash of predictable data, which allows remote attackers to cause a denial of service (CPU consumption) via a flood of SYN packets that produce identical hash values, which slows down the hash table lookups.
nvd
CVE-2015-2363P4HIGHCVSS 7.2vr22015-07-14
CVE-2015-2363 [HIGH] CWE-264 CVE-2015-2363: win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."
nvd
CVE-2015-2364P4HIGHCVSS 7.2vr22015-07-14
CVE-2015-2364 [HIGH] CWE-264 CVE-2015-2364: The graphics component in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows S
The graphics component in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application that leverages an incorrect bitmap conversion, aka "Graphics Com
nvd