Vulnerabilities > Microsoft > ALL Windows

DATE CVE VULNERABILITY TITLE RISK
2007-04-12 CVE-2007-1981 Denial-Of-Service vulnerability in Metamod-P
The safevoid_vsnprintf function in Metamod-P 1.19p29 and earlier on Windows allows remote attackers to cause a denial of service (daemon crash) via a long meta list command.
network
low complexity
microsoft metamod-p
7.8
2007-03-24 CVE-2007-1644 Denial-Of-Service vulnerability in Microsoft ALL Windows Abstractcpe
The dynamic DNS update mechanism in the DNS Server service on Microsoft Windows does not properly authenticate clients in certain deployments or configurations, which allows remote attackers to change DNS records for a web proxy server and conduct man-in-the-middle (MITM) attacks on web traffic, conduct pharming attacks by poisoning DNS records, and cause a denial of service (erroneous name resolution).
network
low complexity
microsoft
critical
10.0
2007-03-10 CVE-2007-1382 Local Security vulnerability in PHP
The PHP COM extensions for PHP on Windows systems allow context-dependent attackers to execute arbitrary code via a WScript.Shell COM object, as demonstrated by using the Run method of this object to execute cmd.exe, which bypasses PHP's safe mode.
local
low complexity
microsoft php
6.8
2007-03-06 CVE-2007-1281 Remote Denial of Service vulnerability in Kaspersky LAB Kaspersky Antivirus Engine 5.5.10/6.0.1.411
Kaspersky AntiVirus Engine 6.0.1.411 for Windows and 5.5-10 for Linux allows remote attackers to cause a denial of service (CPU consumption) via a crafted UPX compressed file with a negative offset, which triggers an infinite loop during decompression.
network
low complexity
microsoft kaspersky-lab linux
7.8
2007-02-26 CVE-2007-1093 Code Injection vulnerability in Hitachi products
Multiple unspecified vulnerabilities in JP1/Cm2/Network Node Manager (NNM) before 07-10-05, and before 08-00-02 in the 08-x series, allow remote attackers to execute arbitrary code, cause a denial of service, or trigger invalid Web utility behavior.
network
low complexity
hitachi microsoft hp sun CWE-94
critical
10.0
2003-12-31 CVE-2003-1477 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Clearswift Mailsweeper FOR Smtp 4.3.6/4.3.7
MAILsweeper for SMTP 4.3.6 and 4.3.7 allows remote attackers to cause a denial of service (CPU consumption) via a PowerPoint attachment that either (1) is corrupt or (2) contains "embedded objects."
network
low complexity
microsoft clearswift CWE-119
7.8
2003-12-31 CVE-2003-1472 Buffer Errors vulnerability in 3D-Ftp 4.0
Buffer overflow in 3D-FTP client 4.0 allows remote FTP servers to cause a denial of service (crash) and possibly execute arbitrary code via a long banner.
network
low complexity
microsoft 3d-ftp CWE-119
5.0
2003-12-31 CVE-2003-1467 Cross-Site Scripting vulnerability in Phorum
Multiple cross-site scripting (XSS) vulnerabilities in (1) login.php, (2) register.php, (3) post.php, and (4) common.php in Phorum before 3.4.3 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors.
4.3
2003-12-31 CVE-2003-1463 Improper Input Validation vulnerability in Alt-N Webadmin 2.0.0/2.0.1/2.0.2
Absolute path traversal vulnerability in Alt-N Technologies WebAdmin 2.0.0 through 2.0.2 allows remote attackers with administrator privileges to (1) determine the installation path by reading the contents of the Name parameter in a link, and (2) read arbitrary files via an absolute path in the Name parameter.
3.5
2003-12-31 CVE-2003-1454 Unspecified vulnerability in Invision Power Services Invision Board 1.0/1.0.1/1.1.1
Invision Power Services Invision Board 1.0 through 1.1.1, when a forum is password protected, stores the administrator password in a cookie in plaintext, which could allow remote attackers to gain access.
network
low complexity
linux microsoft unix invision-power-services
5.0