Vulnerabilities > Microsoft

DATE CVE VULNERABILITY TITLE RISK
2003-05-12 CVE-2003-0233 Unspecified vulnerability in Microsoft IE and Internet Explorer
Heap-based buffer overflow in plugin.ocx for Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code via the Load() method, a different vulnerability than CVE-2003-0115.
network
low complexity
microsoft
7.5
2003-05-12 CVE-2003-0118 Unspecified vulnerability in Microsoft Biztalk Server 2000/2002
SQL injection vulnerability in the Document Tracking and Administration (DTA) website of Microsoft BizTalk Server 2000 and 2002 allows remote attackers to execute operating system commands via a request to (1) rawdocdata.asp or (2) RawCustomSearchField.asp containing an embedded SQL statement.
network
low complexity
microsoft
7.5
2003-05-12 CVE-2003-0117 Unspecified vulnerability in Microsoft Biztalk Server 2002
Buffer overflow in the HTTP receiver function (BizTalkHTTPReceive.dll ISAPI) of Microsoft BizTalk Server 2002 allows attackers to execute arbitrary code via a certain request to the HTTP receiver.
network
low complexity
microsoft
7.5
2003-05-12 CVE-2003-0116 Unspecified vulnerability in Microsoft IE and Internet Explorer
Microsoft Internet Explorer 5.01, 5.5 and 6.0 does not properly check the Cascading Style Sheet input parameter for Modal dialogs, which allows remote attackers to read files on the local system via a web page containing script that creates a dialog and then accesses the target files, aka "Modal Dialog script execution."
network
low complexity
microsoft
5.0
2003-05-12 CVE-2003-0115 Unspecified vulnerability in Microsoft IE and Internet Explorer
Microsoft Internet Explorer 5.01, 5.5 and 6.0 does not properly check parameters that are passed during third party rendering, which could allow remote attackers to execute arbitrary web script, aka the "Third Party Plugin Rendering" vulnerability, a different vulnerability than CVE-2003-0233.
network
low complexity
microsoft
7.5
2003-05-12 CVE-2003-0114 Unspecified vulnerability in Microsoft IE and Internet Explorer
The file upload control in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to automatically upload files from the local system via a web page containing a script to upload the files.
network
low complexity
microsoft
5.0
2003-05-12 CVE-2003-0113 Unspecified vulnerability in Microsoft IE and Internet Explorer
Buffer overflow in URLMON.DLL in Microsoft Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code via an HTTP response containing long values in (1) Content-type and (2) Content-encoding fields.
network
low complexity
microsoft
7.5
2003-05-12 CVE-2003-0112 Buffer Overflow vulnerability in Microsoft Windows Kernel Message Handling
Buffer overflow in Windows Kernel allows local users to gain privileges by causing certain error messages to be passed to a debugger.
local
low complexity
microsoft
4.6
2003-05-05 CVE-2003-0111 Unspecified vulnerability in Microsoft products
The ByteCode Verifier component of Microsoft Virtual Machine (VM) build 5.0.3809 and earlier, as used in Windows and Internet Explorer, allows remote attackers to bypass security checks and execute arbitrary code via a malicious Java applet, aka "Flaw in Microsoft VM Could Enable System Compromise."
network
low complexity
microsoft
7.5
2003-05-05 CVE-2003-0110 Unspecified vulnerability in Microsoft ISA Server and Proxy Server
The Winsock Proxy service in Microsoft Proxy Server 2.0 and the Microsoft Firewall service in Internet Security and Acceleration (ISA) Server 2000 allow remote attackers to cause a denial of service (CPU consumption or packet storm) via a spoofed, malformed packet to UDP port 1745.
network
low complexity
microsoft
5.0