Vulnerabilities > Microsoft

DATE CVE VULNERABILITY TITLE RISK
2006-02-18 CVE-2006-0753 Denial-Of-Service vulnerability in Microsoft IE 6
Memory leak in Microsoft Internet Explorer 6 for Windows XP Service Pack 2 allows remote attackers to cause a denial of service (memory consumption) via JavaScript that uses setInterval to repeatedly call a function to set the value of window.status.
network
high complexity
microsoft
2.6
2006-02-14 CVE-2006-0006 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Microsoft products
Heap-based buffer overflow in the bitmap processing routine in Microsoft Windows Media Player 7.1 on Windows 2000 SP4, Media Player 9 on Windows 2000 SP4 and XP SP1, and Media Player 10 on XP SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted bitmap (.BMP) file that specifies a size of 0 but contains additional data.
network
microsoft CWE-119
critical
9.3
2006-02-14 CVE-2006-0004 Remote Information Disclosure vulnerability in Microsoft Office 2000
Microsoft PowerPoint 2000 in Office 2000 SP3 has an interaction with Internet Explorer that allows remote attackers to obtain sensitive information via a PowerPoint presentation that attempts to access objects in the Temporary Internet Files Folder (TIFF).
network
low complexity
microsoft
5.0
2006-02-14 CVE-2006-0021 Buffer Errors vulnerability in Microsoft Windows 2003 Server and Windows XP
Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote attackers to cause a denial of service (hang) via an IGMP packet with an invalid IP option, aka the "IGMP v3 DoS Vulnerability."
network
low complexity
microsoft CWE-119
7.8
2006-02-14 CVE-2006-0013 Buffer Overflow vulnerability in Microsoft Windows 2003 Server and Windows XP
Buffer overflow in the Web Client service (WebClnt.dll) for Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote authenticated users or Guests to execute arbitrary code via crafted RPC requests, a different vulnerability than CVE-2005-1207.
network
low complexity
microsoft
6.5
2006-02-14 CVE-2006-0008 Permissions, Privileges, and Access Controls vulnerability in Microsoft Office, Windows 2003 Server and Windows XP
The ShellAbout API call in Korean Input Method Editor (IME) in Korean versions of Microsoft Windows XP SP1 and SP2, Windows Server 2003 up to SP1, and Office 2003, allows local users to gain privileges by launching the "shell about dialog box" and clicking the "End-User License Agreement" link, which executes Notepad with the privileges of the program that displays the about box.
local
low complexity
microsoft CWE-264
7.2
2006-02-14 CVE-2006-0005 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Microsoft products
Buffer overflow in the plug-in for Microsoft Windows Media Player (WMP) 9 and 10, when used in browsers other than Internet Explorer and set as the default application to handle media files, allows remote attackers to execute arbitrary code via HTML with an EMBED element containing a long src attribute.
network
microsoft CWE-119
critical
9.3
2006-02-08 CVE-2006-0023 Permissions, Privileges, and Access Controls vulnerability in Microsoft Windows XP
Microsoft Windows XP SP1 and SP2 before August 2004, and possibly other operating systems and versions, uses insecure default ACLs that allow the Authenticated Users group to gain privileges by modifying critical configuration information for the (1) Simple Service Discovery Protocol (SSDP), (2) Universal Plug and Play Device Host (UPnP), (3) NetBT, (4) SCardSvr, (5) DHCP, and (6) DnsCache services, aka "Permissive Windows Services DACLs." NOTE: the NetBT, SCardSvr, DHCP, DnsCache already require privileged access to exploit.
local
low complexity
microsoft CWE-264
4.3
2006-02-08 CVE-2006-0585 Unspecified vulnerability in Microsoft Internet Explorer
jscript.dll in Microsoft Internet Explorer 6.0 SP1 and earlier allows remote attackers to cause a denial of service (application crash) via a Shockwave Flash object that contains ActionScript code that calls VBScript, which in turn calls the Javascript document.write function, which triggers a null dereference.
network
low complexity
microsoft
5.0
2006-02-06 CVE-2006-0564 Remote Security vulnerability in HTML Help Workshop
Stack-based buffer overflow in Microsoft HTML Help Workshop 4.74.8702.0, and possibly earlier versions, and as included in the Microsoft HTML Help 1.4 SDK, allows context-dependent attackers to execute arbitrary code via a .hhp file with a long Contents file field.
network
low complexity
microsoft
7.5