Vulnerabilities > Microsoft > ALL Windows > Critical

DATE CVE VULNERABILITY TITLE RISK
2008-05-12 CVE-2008-2161 Buffer Errors vulnerability in Tftp Server SP 1.4/1.5
Buffer overflow in TFTP Server SP 1.4 and 1.5 on Windows, and possibly other versions, allows remote attackers to execute arbitrary code via a long TFTP error packet.
network
low complexity
microsoft tftp CWE-119
critical
10.0
2007-06-21 CVE-2007-3334 Remote vulnerability in Ingress Database Server
Multiple heap-based buffer overflows in the (1) Communications Server (iigcc.exe) and (2) Data Access Server (iigcd.exe) components for Ingres Database Server 3.0.3, as used in CA (Computer Associates) products including eTrust Secure Content Manager r8 on Windows, allow remote attackers to execute arbitrary code via unknown vectors.
network
low complexity
microsoft ca ingres
critical
10.0
2007-05-29 CVE-2007-2388 Permissions, Privileges, and Access Controls vulnerability in Apple Quicktime 7.1.6
Apple QuickTime for Java 7.1.6 on Mac OS X and Windows does not properly restrict QTObject subclassing, which allows remote attackers to execute arbitrary code via a web page containing a user-defined class that accesses unsafe functions that can be leveraged to write to arbitrary memory locations.
network
apple microsoft CWE-264
critical
9.3
2007-03-24 CVE-2007-1644 Denial-Of-Service vulnerability in Microsoft ALL Windows Abstractcpe
The dynamic DNS update mechanism in the DNS Server service on Microsoft Windows does not properly authenticate clients in certain deployments or configurations, which allows remote attackers to change DNS records for a web proxy server and conduct man-in-the-middle (MITM) attacks on web traffic, conduct pharming attacks by poisoning DNS records, and cause a denial of service (erroneous name resolution).
network
low complexity
microsoft
critical
10.0
2007-02-26 CVE-2007-1093 Code Injection vulnerability in Hitachi products
Multiple unspecified vulnerabilities in JP1/Cm2/Network Node Manager (NNM) before 07-10-05, and before 08-00-02 in the 08-x series, allow remote attackers to execute arbitrary code, cause a denial of service, or trigger invalid Web utility behavior.
network
low complexity
hitachi microsoft hp sun CWE-94
critical
10.0