Microsoft Windows 2003 Server vulnerabilities
176 known vulnerabilities affecting microsoft/windows_2003_server.
Total CVEs
176
CISA KEV
1
actively exploited
Public exploits
67
Exploited in wild
15
Severity breakdown
CRITICAL40HIGH73MEDIUM48LOW15
Vulnerabilities
Page 9 of 9
CVE-2004-0208P4HIGHCVSS 7.2vr22004-11-03
CVE-2004-0208 [HIGH] CVE-2004-0208: The Virtual DOS Machine (VDM) subsystem of Microsoft Windows NT 4.0, Windows 2000, Windows XP, and W
The Virtual DOS Machine (VDM) subsystem of Microsoft Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows local users to access kernel memory and gain privileges via a malicious program that modified some system structures in a way that is not properly validated by privileged operating system functions.
nvd
CVE-2002-2189P4MEDIUMCVSS 5.1vr22002-12-31
CVE-2002-2189 [MEDIUM] CVE-2002-2189: Cross-site scripting (XSS) vulnerability in ActiveXperts Software ActiveWebserver allows remote atta
Cross-site scripting (XSS) vulnerability in ActiveXperts Software ActiveWebserver allows remote attackers to execute arbitrary web script via a link.
nvd
CVE-2005-2126P4LOWCVSS 2.6vr22005-10-21
CVE-2005-2126 [LOW] CVE-2005-2126: The FTP client in Windows XP SP1 and Server 2003, and Internet Explorer 6 SP1 on Windows 2000 SP4, w
The FTP client in Windows XP SP1 and Server 2003, and Internet Explorer 6 SP1 on Windows 2000 SP4, when "Enable Folder View for FTP Sites" is enabled and the user manually initiates a file transfer, allows user-assisted, remote FTP servers to overwrite files in arbitrary locations via crafted filenames.
nvd
CVE-2015-2374P4LOWCVSS 3.3vr22015-07-14
CVE-2015-2374 [LOW] CWE-200 CVE-2015-2374: The Netlogon service in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Server 2008 SP2 and R2
The Netlogon service in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Server 2008 SP2 and R2 SP1, and Windows Server 2012 Gold and R2 does not properly implement domain-controller communication, which allows remote attackers to discover credentials by leveraging certain PDC access and spoofing the BDC role in a PDC communication channel, aka "Ele
nvd
CVE-2004-0207P4LOWCVSS 2.1vr22004-11-03
CVE-2004-0207 [LOW] CVE-2004-0207: "Shatter" style vulnerability in the Window Management application programming interface (API) for M
"Shatter" style vulnerability in the Window Management application programming interface (API) for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows local users to gain privileges by using certain API functions to change properties of privileged programs using the SetWindowLong and SetWIndowLongPtr API functions.
nvd
CVE-2015-2367P4LOWCVSS 2.1vr22015-07-14
CVE-2015-2367 [LOW] CWE-200 CVE-2015-2367: win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to obtain sensitive information from uninitialized kernel memory via a crafted application, aka
nvd
CVE-2005-3177P4MEDIUMCVSS 4.6vr22005-10-06
CVE-2005-3177 [MEDIUM] CVE-2005-3177: CHKDSK in Microsoft Windows 2000 before Update Rollup 1 for SP4, Windows XP, and Windows Server 2003
CHKDSK in Microsoft Windows 2000 before Update Rollup 1 for SP4, Windows XP, and Windows Server 2003, when running in fix mode, does not properly handle security descriptors if the master file table contains a large number of files or if the descriptors do not satisfy certain NTFS conventions, which could cause ACLs for some files to be reverted to less secur
nvd
CVE-2005-1982P4LOWCVSS 3.6venterprisevr2+2 more2005-08-10
CVE-2005-1982 [LOW] CVE-2005-1982: Unknown vulnerability in the PKINIT Protocol for Microsoft Windows 2000, Windows XP, and Windows Ser
Unknown vulnerability in the PKINIT Protocol for Microsoft Windows 2000, Windows XP, and Windows Server 2003 could allow a local user to obtain information and spoof a server via a man-in-the-middle (MITM) attack between a client and a domain controller when PKINIT smart card authentication is being used.
nvd
CVE-2007-1537P4LOWCVSS 3.6vsp12007-03-20
CVE-2007-1537 [LOW] CVE-2007-1537: \Device\NdisTapi (NDISTAPI.sys) in Microsoft Windows XP SP2 and 2003 SP1 uses weak permissions, whic
\Device\NdisTapi (NDISTAPI.sys) in Microsoft Windows XP SP2 and 2003 SP1 uses weak permissions, which allows local users to write to the device and cause a denial of service, as demonstrated by using an IRQL to acquire a spinlock on paged memory via the NdisTapiDispatch function.
nvd
CVE-2005-1981P4LOWCVSS 2.1vr22005-08-10
CVE-2005-1981 [LOW] CVE-2005-1981: Unknown vulnerability in Microsoft Windows 2000 Server and Windows Server 2003 domain controllers al
Unknown vulnerability in Microsoft Windows 2000 Server and Windows Server 2003 domain controllers allows remote authenticated users to cause a denial of service (system crash) via a crafted Kerberos message.
nvd
CVE-2005-0550P4LOWCVSS 2.1vr22005-05-02
CVE-2005-0550 [LOW] CVE-2005-0550: Buffer overflow in Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows lo
Buffer overflow in Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to cause a denial of service (i.e., system crash) via a malformed request, aka "Object Management Vulnerability".
nvd
CVE-2004-0211P4LOWCVSS 2.1vr22004-11-03
CVE-2004-0211 [LOW] CVE-2004-0211: The kernel for Microsoft Windows Server 2003 does not reset certain values in CPU data structures, w
The kernel for Microsoft Windows Server 2003 does not reset certain values in CPU data structures, which allows local users to cause a denial of service (system crash) via a malicious program.
nvd
CVE-2004-2365P4LOWCVSS 2.1vr22004-12-31
CVE-2004-2365 [LOW] CVE-2004-2365: Memory leak in Microsoft Windows XP and Windows Server 2003 allows local users to cause a denial of
Memory leak in Microsoft Windows XP and Windows Server 2003 allows local users to cause a denial of service (memory exhaustion) by repeatedly creating and deleting directories using a non-standard tool such as smbmount.
nvd
CVE-2006-0488P4LOWCVSS 2.1vr22006-02-01
CVE-2006-0488 [LOW] CVE-2006-0488: The VDM (Virtual DOS Machine) emulation environment for MS-DOS applications in Windows 2000, Windows
The VDM (Virtual DOS Machine) emulation environment for MS-DOS applications in Windows 2000, Windows XP SP2, and Windows Server 2003 allows local users to read the first megabyte of memory and possibly obtain sensitive information, as demonstrated by dumper.asm.
nvd
CVE-2005-2765P4LOWCVSS 2.1v64-bitvsp12005-09-01
CVE-2005-2765 [LOW] CVE-2005-2765: The user interface in the Windows Firewall does not properly display certain malformed entries in th
The user interface in the Windows Firewall does not properly display certain malformed entries in the Windows Registry, which makes it easier for attackers with administrator privileges to hide activities if the administrator only uses the Windows Firewall interface to monitor exceptions. NOTE: the vendor disputes this issue, saying that since administrative pri
nvd
CVE-2007-2999P4LOWCVSS 1.8vgoldvsp1+1 more2007-06-04
CVE-2007-2999 [LOW] CVE-2007-2999: Microsoft Windows Server 2003, when time restrictions are in effect for user accounts, generates dif
Microsoft Windows Server 2003, when time restrictions are in effect for user accounts, generates different error messages for failed login attempts with a valid user name than for those with an invalid user name, which allows context-dependent attackers to determine valid Active Directory account names.
nvd
← Previous9 / 9