Vulnerabilities > Microsoft > ALL Windows

DATE CVE VULNERABILITY TITLE RISK
2008-05-12 CVE-2008-2161 Buffer Errors vulnerability in Tftp Server SP 1.4/1.5
Buffer overflow in TFTP Server SP 1.4 and 1.5 on Windows, and possibly other versions, allows remote attackers to execute arbitrary code via a long TFTP error packet.
network
low complexity
microsoft tftp CWE-119
critical
10.0
2007-08-08 CVE-2007-2927 Denial of Service vulnerability in Atheros Wireless Drivers
Unspecified vulnerability in Atheros 802.11 a/b/g wireless adapter drivers before 5.3.0.35, and 6.x before 6.0.3.67, on Windows allows remote attackers to cause a denial of service via a crafted 802.11 management frame.
network
low complexity
atheros microsoft
5.0
2007-07-24 CVE-2007-3956 Remote Denial Of Service vulnerability in Teamspeak web Server 2.0
TeamSpeak WebServer 2.0 for Windows does not validate parameter value lengths and does not expire TCP sessions, which allows remote attackers to cause a denial of service (CPU and memory consumption) via long username and password parameters in a request to login.tscmd on TCP port 14534.
network
low complexity
microsoft teamspeak
7.8
2007-07-06 CVE-2007-3615 Denial of Service vulnerability in SAP products
Internet Communication Manager (aka ICMAN.exe or ICM) in SAP NetWeaver Application Server 6.x and 7.x, possibly only on Windows, allows remote attackers to cause a denial of service (process crash) via a URI of a certain length that contains a sap-isc-key parameter, related to configuration of a web cache.
network
low complexity
microsoft sap
7.8
2007-06-21 CVE-2007-3334 Remote vulnerability in Ingress Database Server
Multiple heap-based buffer overflows in the (1) Communications Server (iigcc.exe) and (2) Data Access Server (iigcd.exe) components for Ingres Database Server 3.0.3, as used in CA (Computer Associates) products including eTrust Secure Content Manager r8 on Windows, allow remote attackers to execute arbitrary code via unknown vectors.
network
low complexity
microsoft ca ingres
critical
10.0
2007-05-30 CVE-2007-2896 Denial of Service vulnerability in Symantec Enterprise Security Manager 6.5.3
Race condition in the Symantec Enterprise Security Manager (ESM) 6.5.3 managers and agents on Windows before 20070524 allows remote attackers to cause a denial of service (CPU consumption and application hang) via certain network scans to ESM ports.
4.3
2007-05-29 CVE-2007-2389 Information Disclosure vulnerability in Apple Quicktime 7.1.6
Apple QuickTime for Java 7.1.6 on Mac OS X and Windows does not clear potentially sensitive memory before use, which allows remote attackers to read memory from a web browser via unknown vectors related to Java applets.
network
apple microsoft
7.1
2007-05-29 CVE-2007-2388 Permissions, Privileges, and Access Controls vulnerability in Apple Quicktime 7.1.6
Apple QuickTime for Java 7.1.6 on Mac OS X and Windows does not properly restrict QTObject subclassing, which allows remote attackers to execute arbitrary code via a web page containing a user-defined class that accesses unsafe functions that can be leveraged to write to arbitrary memory locations.
network
apple microsoft CWE-264
critical
9.3
2007-05-10 CVE-2007-1280 Cross-Site Scripting vulnerability in Adobe Robohelp and Robohelp Server
Cross-site scripting (XSS) vulnerability in Adobe RoboHelp X5, 6, and Server 6 allows remote attackers to inject arbitrary web script or HTML via a URL after a # (hash) in the URL path, as demonstrated using en/frameset-7.html, and possibly other unspecified vectors involving templates and (1) whstart.js and (2) whcsh_home.htm in WebHelp, (3) wf_startpage.js and (4) wf_startqs.htm in FlashHelp, or (5) WindowManager.dll in RoboHelp Server 6.
network
microsoft adobe
4.3
2007-05-01 CVE-2007-2414 Denial Of Service vulnerability in MyServer
MyServer before 0.8.8 allows remote attackers to cause a denial of service via unspecified vectors.
network
low complexity
microsoft myserver
7.8