Vulnerabilities > Microsoft

DATE CVE VULNERABILITY TITLE RISK
2003-12-31 CVE-2003-1559 Information Exposure vulnerability in Microsoft IE and Internet Explorer
Microsoft Internet Explorer 5.22, and other 5 through 6 SP1 versions, sends Referer headers containing https:// URLs in requests for http:// URLs, which allows remote attackers to obtain potentially sensitive information by reading Referer log data.
network
low complexity
microsoft CWE-200
5.0
2003-12-31 CVE-2003-1544 Denial Of Service vulnerability in Microsoft Windows MSGINA.DLL Read-Lock
Unrestricted critical resource lock in Terminal Services for Windows 2000 before SP4 and Windows XP allows remote authenticated users to cause a denial of service (reboot) by obtaining a read lock on msgina.dll, which prevents msgina.dll from being loaded.
network
low complexity
microsoft
6.8
2003-12-31 CVE-2003-1505 Unspecified vulnerability in Microsoft Internet Explorer 6
Microsoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (crash) by creating a web page or HTML e-mail with a textarea in a div element whose scrollbar-base-color is modified by a CSS style, which is then moved.
network
microsoft
4.3
2003-12-31 CVE-2003-1484 Buffer Errors vulnerability in Microsoft IE 6.0
Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service (crash) by creating a DHTML link that uses the AnchorClick "A" object with a blank href attribute.
network
microsoft CWE-119
4.3
2003-12-31 CVE-2003-1482 Credentials Management vulnerability in Microsoft Mn-500 Wireless Base Station
The backup configuration file for Microsoft MN-500 wireless base station stores administrative passwords in plaintext, which allows local users to gain access.
local
low complexity
microsoft CWE-255
4.6
2003-12-31 CVE-2003-1477 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Clearswift Mailsweeper FOR Smtp 4.3.6/4.3.7
MAILsweeper for SMTP 4.3.6 and 4.3.7 allows remote attackers to cause a denial of service (CPU consumption) via a PowerPoint attachment that either (1) is corrupt or (2) contains "embedded objects."
network
low complexity
microsoft clearswift CWE-119
7.8
2003-12-31 CVE-2003-1472 Buffer Errors vulnerability in 3D-Ftp 4.0
Buffer overflow in 3D-FTP client 4.0 allows remote FTP servers to cause a denial of service (crash) and possibly execute arbitrary code via a long banner.
network
low complexity
microsoft 3d-ftp CWE-119
5.0
2003-12-31 CVE-2003-1469 Information Exposure vulnerability in Macromedia Coldfusion and Coldfusion Professional
The default configuration of ColdFusion MX has the "Enable Robust Exception Information" option selected, which allows remote attackers to obtain the full path of the web server via a direct request to CFIDE/probe.cfm, which leaks the path in an error message.
network
low complexity
microsoft macromedia CWE-200
5.0
2003-12-31 CVE-2003-1467 Cross-Site Scripting vulnerability in Phorum
Multiple cross-site scripting (XSS) vulnerabilities in (1) login.php, (2) register.php, (3) post.php, and (4) common.php in Phorum before 3.4.3 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors.
4.3
2003-12-31 CVE-2003-1463 Improper Input Validation vulnerability in Alt-N Webadmin 2.0.0/2.0.1/2.0.2
Absolute path traversal vulnerability in Alt-N Technologies WebAdmin 2.0.0 through 2.0.2 allows remote attackers with administrator privileges to (1) determine the installation path by reading the contents of the Name parameter in a link, and (2) read arbitrary files via an absolute path in the Name parameter.
3.5