Microsoft Windows 2003 Server vulnerabilities
176 known vulnerabilities affecting microsoft/windows_2003_server.
Total CVEs
176
CISA KEV
1
actively exploited
Public exploits
65
Exploited in wild
2
Severity breakdown
CRITICAL40HIGH73MEDIUM48LOW15
Vulnerabilities
Page 8 of 9
CVE-2004-2365LOWCVSS 2.1vr22004-12-31
CVE-2004-2365 [LOW] CVE-2004-2365: Memory leak in Microsoft Windows XP and Windows Server 2003 allows local users to cause a denial of
Memory leak in Microsoft Windows XP and Windows Server 2003 allows local users to cause a denial of service (memory exhaustion) by repeatedly creating and deleting directories using a non-standard tool such as smbmount.
nvd
CVE-2004-1305MEDIUMCVSS 5.0PoCventerpriseventerprise_64-bit+3 more2004-12-23
CVE-2004-1305 [MEDIUM] CVE-2004-1305: The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP thr
The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allow remote attackers to cause a denial of service via (1) the frame number set to zero, which causes an invalid memory address to be used and leads to a kernel crash, or (2) the rate number set to zero, which leads to resource exhau
nvd
CVE-2004-1361MEDIUMCVSS 5.0venterpriseventerprise_64-bit+3 more2004-12-23
CVE-2004-1361 [MEDIUM] CVE-2004-1361: Integer underflow in winhlp32.exe in Windows NT, Windows 2000 through SP4, Windows XP through SP2, a
Integer underflow in winhlp32.exe in Windows NT, Windows 2000 through SP4, Windows XP through SP2, and Windows 2003 allows remote attackers to execute arbitrary code via a malformed .hlp file, which leads to a heap-based buffer overflow.
nvd
CVE-2004-1319MEDIUMCVSS 5.0venterpriseventerprise_64-bit+3 more2004-12-15
CVE-2004-1319 [MEDIUM] CVE-2004-1319: The DHTML Edit Control (dhtmled.ocx) allows remote attackers to inject arbitrary web script into oth
The DHTML Edit Control (dhtmled.ocx) allows remote attackers to inject arbitrary web script into other domains by setting a name for a window, opening a child page whose target is the window with the given name, then injecting the script from the parent into the child using execScript, as demonstrated by "AbusiveParent" in Internet Explorer 6.0.2900.2180.
nvd
CVE-2004-0209CRITICALCVSS 10.0PoCvr22004-11-03
CVE-2004-0209 [CRITICAL] CVE-2004-0209: Unknown vulnerability in the Graphics Rendering Engine processes of Microsoft Windows 2000, Windows
Unknown vulnerability in the Graphics Rendering Engine processes of Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats that involve "an unchecked buffer."
nvd
CVE-2004-0575CRITICALCVSS 10.0PoCv64-bitvr22004-11-03
CVE-2004-0575 [CRITICAL] CVE-2004-0575: Integer overflow in DUNZIP32.DLL for Microsoft Windows XP, Windows XP 64-bit Edition, Windows Server
Integer overflow in DUNZIP32.DLL for Microsoft Windows XP, Windows XP 64-bit Edition, Windows Server 2003, and Windows Server 2003 64-bit Edition allows remote attackers to execute arbitrary code via compressed (zipped) folders that involve an "unchecked buffer" and improper length validation.
nvd
CVE-2004-0208HIGHCVSS 7.2vr22004-11-03
CVE-2004-0208 [HIGH] CVE-2004-0208: The Virtual DOS Machine (VDM) subsystem of Microsoft Windows NT 4.0, Windows 2000, Windows XP, and W
The Virtual DOS Machine (VDM) subsystem of Microsoft Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows local users to access kernel memory and gain privileges via a malicious program that modified some system structures in a way that is not properly validated by privileged operating system functions.
nvd
CVE-2004-0206HIGHCVSS 7.5PoCvr22004-11-03
CVE-2004-0206 [HIGH] CVE-2004-0206: Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 20
Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to remotely execute arbitrary code or locally gain privileges via a malicious message or application that involves an "unchecked buffer," possibly a buffer overflow.
nvd
CVE-2004-0207LOWCVSS 2.1vr22004-11-03
CVE-2004-0207 [LOW] CVE-2004-0207: "Shatter" style vulnerability in the Window Management application programming interface (API) for M
"Shatter" style vulnerability in the Window Management application programming interface (API) for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows local users to gain privileges by using certain API functions to change properties of privileged programs using the SetWindowLong and SetWIndowLongPtr API functions.
nvd
CVE-2004-0211LOWCVSS 2.1vr22004-11-03
CVE-2004-0211 [LOW] CVE-2004-0211: The kernel for Microsoft Windows Server 2003 does not reset certain values in CPU data structures, w
The kernel for Microsoft Windows Server 2003 does not reset certain values in CPU data structures, which allows local users to cause a denial of service (system crash) via a malicious program.
nvd
CVE-2004-0200CRITICALCVSS 9.3PoCvr22004-09-28
CVE-2004-0200 [CRITICAL] CVE-2004-0200: Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI
Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.
nvd
CVE-2004-0839MEDIUMCVSS 5.0venterpriseventerprise_64-bit+3 more2004-08-18
CVE-2004-0839 [MEDIUM] CVE-2004-0839: Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attack
Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by "wottapoop.html".
nvd
CVE-2004-0201CRITICALCVSS 10.0venterpriseventerprise_64-bit+3 more2004-08-06
CVE-2004-0201 [CRITICAL] CVE-2004-0201: Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, M
Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, Me, NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary commands via a .CHM file with a large length field, a different vulnerability than CVE-2003-1041.
nvd
CVE-2004-0202MEDIUMCVSS 5.0venterpriseventerprise_64-bit+3 more2004-08-06
CVE-2004-0202 [MEDIUM] CVE-2004-0202: IDirectPlay4 Application Programming Interface (API) of Microsoft DirectPlay 7.0a thru 9.0b, as used
IDirectPlay4 Application Programming Interface (API) of Microsoft DirectPlay 7.0a thru 9.0b, as used in Windows Server 2003 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed packet.
nvd
CVE-2004-0199MEDIUMCVSS 5.1venterpriseventerprise_64-bit+3 more2004-06-14
CVE-2004-0199 [MEDIUM] CVE-2004-0199: Help and Support Center in Microsoft Windows XP and Windows Server 2003 SP1 does not properly valida
Help and Support Center in Microsoft Windows XP and Windows Server 2003 SP1 does not properly validate HCP URLs, which allows remote attackers to execute arbitrary code, as demonstrated using certain hcp:// URLs that access the DVD Upgrade capability (dvdupgrd.htm).
nvd
CVE-2004-0123HIGHCVSS 7.5vr22004-06-01
CVE-2004-0123 [HIGH] CWE-119 CVE-2004-0123: Double free vulnerability in the ASN.1 library as used in Windows NT 4.0, Windows 2000, Windows XP,
Double free vulnerability in the ASN.1 library as used in Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service and possibly execute arbitrary code.
nvd
CVE-2003-0533HIGHCVSS 7.5PoCvr22004-06-01
CVE-2003-0533 [HIGH] CVE-2003-0533: Stack-based buffer overflow in certain Active Directory service functions in LSASRV.DLL of the Local
Stack-based buffer overflow in certain Active Directory service functions in LSASRV.DLL of the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via a packet that causes the DsRolerUpgradeDownlev
nvd
CVE-2003-0719HIGHCVSS 7.5PoCvr22004-06-01
CVE-2003-0719 [HIGH] CVE-2003-0719: Buffer overflow in the Private Communications Transport (PCT) protocol implementation in the Microso
Buffer overflow in the Private Communications Transport (PCT) protocol implementation in the Microsoft SSL library, as used in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via PCT 1.0 handshake packets.
nvd
CVE-2004-0117HIGHCVSS 7.5vr22004-06-01
CVE-2004-0117 [HIGH] CVE-2004-0117: Unknown vulnerability in the H.323 protocol implementation in Windows 98, Windows 2000, Windows XP,
Unknown vulnerability in the H.323 protocol implementation in Windows 98, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code.
nvd
CVE-2004-0120MEDIUMCVSS 5.0PoCvr22004-06-01
CVE-2004-0120 [MEDIUM] CVE-2004-0120: The Microsoft Secure Sockets Layer (SSL) library, as used in Windows 2000, Windows XP, and Windows S
The Microsoft Secure Sockets Layer (SSL) library, as used in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service via malformed SSL messages.
nvd