Microsoft Windows 2003 Server vulnerabilities
176 known vulnerabilities affecting microsoft/windows_2003_server.
Total CVEs
176
CISA KEV
1
actively exploited
Public exploits
67
Exploited in wild
15
Severity breakdown
CRITICAL40HIGH73MEDIUM48LOW15
Vulnerabilities
Page 8 of 9
CVE-2007-5352P4HIGHCVSS 7.2vsp1vsp22008-01-08
CVE-2007-5352 [HIGH] CWE-264 CVE-2007-5352: Unspecified vulnerability in Local Security Authority Subsystem Service (LSASS) in Microsoft Windows
Unspecified vulnerability in Local Security Authority Subsystem Service (LSASS) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2 allows local users to gain privileges via a crafted local procedure call (LPC) request.
nvd
CVE-2007-0211P4HIGHCVSS 7.2vsp12007-02-13
CVE-2007-0211 [HIGH] CVE-2007-0211: The hardware detection functionality in the Windows Shell in Microsoft Windows XP SP2 and Profession
The hardware detection functionality in the Windows Shell in Microsoft Windows XP SP2 and Professional, and Server 2003 SP1 allows local users to gain privileges via an unvalidated parameter to a function related to the "detection and registration of new hardware."
nvd
CVE-2003-0839P4MEDIUMCVSS 5.0vr22003-11-17
CVE-2003-0839 [MEDIUM] CVE-2003-0839: Directory traversal vulnerability in the "Shell Folders" capability in Microsoft Windows Server 2003
Directory traversal vulnerability in the "Shell Folders" capability in Microsoft Windows Server 2003 allows remote attackers to read arbitrary files via .. (dot dot) sequences in a "shell:" link.
nvd
CVE-2004-2339P4HIGHCVSS 8.4vr22004-12-31
CVE-2004-2339 [HIGH] CVE-2004-2339: Microsoft Windows 2000, XP, and possibly 2003 allows local users with the SeDebugPrivilege privilege
Microsoft Windows 2000, XP, and possibly 2003 allows local users with the SeDebugPrivilege privilege to execute arbitrary code as kernel and read or write kernel memory via the NtSystemDebugControl function, which does not verify its pointer arguments. Note: this issue has been disputed, since Administrator privileges are typically required to exploit this issu
nvd
CVE-2007-1206P4HIGHCVSS 7.2vgoldvsp1+1 more2007-04-10
CVE-2007-1206 [HIGH] CWE-264 CVE-2007-1206: The Virtual DOS Machine (VDM) in the Windows Kernel in Microsoft Windows NT 4.0; 2000 SP4; XP SP2; S
The Virtual DOS Machine (VDM) in the Windows Kernel in Microsoft Windows NT 4.0; 2000 SP4; XP SP2; Server 2003, 2003 SP1, and 2003 SP2; and Windows Vista before June 2006; uses insecure permissions (PAGE_READWRITE) for a physical memory view, which allows local users to gain privileges by modifying the "zero page" during a race condition before the view
nvd
CVE-2006-5585P4HIGHCVSS 7.2vitaniumvr22006-12-13
CVE-2006-5585 [HIGH] CWE-264 CVE-2006-5585: The Client-Server Run-time Subsystem in Microsoft Windows XP SP2 and Server 2003 allows local users
The Client-Server Run-time Subsystem in Microsoft Windows XP SP2 and Server 2003 allows local users to gain privileges via a crafted file manifest within an application, aka "File Manifest Corruption Vulnerability."
nvd
CVE-2005-2388P4HIGHCVSS 7.2vdatacenter_64-bitventerprise+5 more2005-07-27
CVE-2005-2388 [HIGH] CVE-2005-2388: Buffer overflow in a certain USB driver, as used on Microsoft Windows, allows attackers to execute a
Buffer overflow in a certain USB driver, as used on Microsoft Windows, allows attackers to execute arbitrary code.
nvd
CVE-2006-1591P4MEDIUMCVSS 5.1venterprisevr2+2 more2006-04-03
CVE-2006-1591 [MEDIUM] CVE-2006-1591: Heap-based buffer overflow in Microsoft Windows Help winhlp32.exe allows user-assisted attackers to
Heap-based buffer overflow in Microsoft Windows Help winhlp32.exe allows user-assisted attackers to execute arbitrary code via crafted embedded image data in a .hlp file.
nvd
CVE-2003-0661P4MEDIUMCVSS 5.0venterpriseventerprise_64-bit+3 more2003-10-20
CVE-2003-0661 [MEDIUM] CVE-2003-0661: The NetBT Name Service (NBNS) for NetBIOS in Windows NT 4.0, 2000, XP, and Server 2003 may include r
The NetBT Name Service (NBNS) for NetBIOS in Windows NT 4.0, 2000, XP, and Server 2003 may include random memory in a response to a NBNS query, which could allow remote attackers to obtain sensitive information.
nvd
CVE-2005-4269P4HIGHCVSS 7.8vr22005-12-15
CVE-2005-4269 [HIGH] CVE-2005-4269: mshtml.dll in Microsoft Windows XP, Server 2003, and Internet Explorer 6.0 SP1 allows attackers to c
mshtml.dll in Microsoft Windows XP, Server 2003, and Internet Explorer 6.0 SP1 allows attackers to cause a denial of service (access violation) by causing mshtml.dll to process button-focus events at the same time that a document is reloading, as seen in Microsoft Office InfoPath 2003 by repeatedly clicking the "Delete" button in a repeating section in a form.
nvd
CVE-2004-0202P4MEDIUMCVSS 5.0venterpriseventerprise_64-bit+3 more2004-08-06
CVE-2004-0202 [MEDIUM] CVE-2004-0202: IDirectPlay4 Application Programming Interface (API) of Microsoft DirectPlay 7.0a thru 9.0b, as used
IDirectPlay4 Application Programming Interface (API) of Microsoft DirectPlay 7.0a thru 9.0b, as used in Windows Server 2003 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed packet.
nvd
CVE-2006-0008P4HIGHCVSS 7.2vdatacenter_64-bitventerprise+5 more2006-02-14
CVE-2006-0008 [HIGH] CWE-264 CVE-2006-0008: The ShellAbout API call in Korean Input Method Editor (IME) in Korean versions of Microsoft Windows
The ShellAbout API call in Korean Input Method Editor (IME) in Korean versions of Microsoft Windows XP SP1 and SP2, Windows Server 2003 up to SP1, and Office 2003, allows local users to gain privileges by launching the "shell about dialog box" and clicking the "End-User License Agreement" link, which executes Notepad with the privileges of the program th
nvd
CVE-2005-1214P4MEDIUMCVSS 5.1v64-bitvdatacenter_64-bit+6 more2005-06-14
CVE-2005-1214 [MEDIUM] CVE-2005-1214: Microsoft Agent allows remote attackers to spoof trusted Internet content and execute arbitrary code
Microsoft Agent allows remote attackers to spoof trusted Internet content and execute arbitrary code by disguising security prompts on a malicious Web page.
nvd
CVE-2005-0061P4HIGHCVSS 7.2venterpriseventerprise_64-bit+3 more2005-05-02
CVE-2005-0061 [HIGH] CVE-2005-0061: The kernel of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local u
The kernel of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via certain access requests.
nvd
CVE-2015-2371P4MEDIUMCVSS 6.9vr22015-07-14
CVE-2015-2371 [MEDIUM] CWE-264 CVE-2015-2371: The Windows Installer service in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Wi
The Windows Installer service in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a custom action script associated with a .msi package, aka "Windows Installer
nvd
CVE-2004-0124P4LOWCVSS 2.6vr22004-06-01
CVE-2004-0124 [LOW] CVE-2004-0124: The DCOM RPC interface for Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attacke
The DCOM RPC interface for Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause network communications via an "alter context" call that contains additional data, aka the "Object Identity Vulnerability."
nvd
CVE-2009-0229P4MEDIUMCVSS 4.9vsp22009-06-10
CVE-2009-0229 [MEDIUM] CWE-200 CVE-2009-0229: The Windows Printing Service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista G
The Windows Printing Service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 allows local users to read arbitrary files via a crafted separator page, aka "Print Spooler Read File Vulnerability."
nvd
CVE-2005-0060P4HIGHCVSS 7.2venterpriseventerprise_64-bit+3 more2005-05-02
CVE-2005-0060 [HIGH] CVE-2005-0060: Buffer overflow in the font processing component of Microsoft Windows 2000, Windows XP SP1 and SP2,
Buffer overflow in the font processing component of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application.
nvd
CVE-2004-0893P4HIGHCVSS 7.2vdatacenter_64-bitventerprise+4 more2005-01-10
CVE-2004-0893 [HIGH] CVE-2004-0893: The Local Procedure Call (LPC) interface of the Windows Kernel for Windows NT 4.0, Windows 2000, Win
The Local Procedure Call (LPC) interface of the Windows Kernel for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the lengths of messages sent to the LPC port, which allows local users to gain privileges, aka "Windows Kernel Vulnerability."
nvd
CVE-2006-3351P4MEDIUMCVSS 5.4v3.1.0.3270v64-bit+13 more2006-07-06
CVE-2006-3351 [MEDIUM] CVE-2006-3351: Buffer overflow in Windows Explorer (explorer.exe) on Windows XP and 2003 allows user-assisted attac
Buffer overflow in Windows Explorer (explorer.exe) on Windows XP and 2003 allows user-assisted attackers to cause a denial of service (repeated crash) and possibly execute arbitrary code via a .url file with an InternetShortcut tag containing a long URL and a large number of "file:" specifiers.
nvd