Vulnerabilities > Microsoft

DATE CVE VULNERABILITY TITLE RISK
2004-07-07 CVE-2004-0474 Unspecified vulnerability in Microsoft Windows XP
Help Center (HelpCtr.exe) may allow remote attackers to read or execute arbitrary files via an "http://" or "file://" argument to the topic parameter in an hcp:// URL.
network
high complexity
microsoft
5.1
2004-07-07 CVE-2004-0420 Unspecified vulnerability in Microsoft IE and Internet Explorer
The Windows Shell application in Windows 98, Windows ME, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by spoofing the type of a file via a CLSID specifier in the filename, as demonstrated using Internet Explorer 6.0.2800.1106 on Windows XP.
network
low complexity
microsoft
critical
10.0
2004-06-14 CVE-2004-0199 Unspecified vulnerability in Microsoft Windows 2003 Server and Windows XP
Help and Support Center in Microsoft Windows XP and Windows Server 2003 SP1 does not properly validate HCP URLs, which allows remote attackers to execute arbitrary code, as demonstrated using certain hcp:// URLs that access the DVD Upgrade capability (dvdupgrd.htm).
network
high complexity
microsoft
5.1
2004-06-14 CVE-2003-1041 Unspecified vulnerability in Microsoft IE and Internet Explorer
Internet Explorer 5.x and 6.0 allows remote attackers to execute arbitrary programs via a modified directory traversal attack using a URL containing ".." (dot dot) sequences and a filename that ends in "::" which is treated as a .chm file even if it does not have a .chm extension.
network
low complexity
microsoft
7.5
2004-06-01 CVE-2004-0197 Remote Code Execution vulnerability in Microsoft JET 4.0
Buffer overflow in Microsoft Jet Database Engine 4.0 allows remote attackers to execute arbitrary code via a specially-crafted database query.
network
low complexity
microsoft
7.5
2004-06-01 CVE-2004-0124 Unspecified vulnerability in Microsoft products
The DCOM RPC interface for Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause network communications via an "alter context" call that contains additional data, aka the "Object Identity Vulnerability."
network
high complexity
microsoft
2.6
2004-06-01 CVE-2004-0123 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Microsoft products
Double free vulnerability in the ASN.1 library as used in Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service and possibly execute arbitrary code.
network
low complexity
microsoft CWE-119
7.5
2004-06-01 CVE-2004-0120 Denial of Service vulnerability in Microsoft Windows 2000, Windows 2003 Server and Windows XP
The Microsoft Secure Sockets Layer (SSL) library, as used in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service via malformed SSL messages.
network
low complexity
microsoft
5.0
2004-06-01 CVE-2004-0119 NULL Pointer Dereference vulnerability in Microsoft Windows 2000, Windows Server 2003 and Windows XP
The Negotiate Security Software Provider (SSP) interface in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service (crash from null dereference) or execute arbitrary code via a crafted SPNEGO NegTokenInit request during authentication protocol selection.
network
low complexity
microsoft CWE-476
7.5
2004-06-01 CVE-2004-0118 Local Privilege Escalation vulnerability in Microsoft Windows 2000 and Windows NT
The component for the Virtual DOS Machine (VDM) subsystem in Windows NT 4.0 and Windows 2000 does not properly validate system structures, which allows local users to access protected kernel memory and execute arbitrary code.
local
low complexity
microsoft
7.2