Vulnerabilities > Microsoft > Critical

DATE CVE VULNERABILITY TITLE RISK
2007-06-12 CVE-2007-0934 Remote Code Execution vulnerability in Microsoft Visio 2002
Unspecified vulnerability in Microsoft Visio 2002 allows remote user-assisted attackers to execute arbitrary code via a Visio (.VSD, VSS, .VST) file with a crafted version number that triggers memory corruption.
network
microsoft
critical
9.3
2007-06-12 CVE-2007-0218 Code Injection vulnerability in Microsoft Internet Explorer 5.01/6/7.0
Microsoft Internet Explorer 5.01 and 6 allows remote attackers to execute arbitrary code by instantiating certain COM objects from Urlmon.dll, which triggers memory corruption during a call to the IObjectSafety function.
network
microsoft CWE-94
critical
9.3
2007-06-07 CVE-2007-3111 Buffer overflow in the Provideo Camimage ActiveX control in ISSCamControl.dll 1.0.1.5, when Internet Explorer 6 is used on Windows 2000 SP4, allows remote attackers to execute arbitrary code via a long URL property value.
network
low complexity
microsoft provideo
critical
10.0
2007-06-06 CVE-2007-3092 Unspecified vulnerability in Microsoft Internet Explorer 6.0
Microsoft Internet Explorer 6 allows remote attackers to spoof the URL bar, and page properties including SSL certificates, by interrupting page loading through certain use of location DOM objects and setTimeout calls.
network
microsoft
critical
9.3
2007-05-31 CVE-2007-2938 Buffer overflow in the BaseRunner ActiveX control in the Ademco ATNBaseLoader100 Module (ATNBaseLoader100.dll) 5.4.0.6, when Internet Explorer 6 is used, allows remote attackers to execute arbitrary code via a long argument to the (1) Send485CMD method, and possibly the (2) SetLoginID, (3) AddSite, (4) SetScreen, and (5) SetVideoServer methods.
network
low complexity
honeywell microsoft
critical
10.0
2007-05-30 CVE-2007-2884 Improper Input Validation vulnerability in Microsoft Visual Basic 6.0
Multiple stack-based buffer overflows in Microsoft Visual Basic 6 allow user-assisted remote attackers to cause a denial of service (CPU consumption) or execute arbitrary code via a Visual Basic Project (vbp) file with a long (1) Description or (2) Company Name (VersionCompanyName) field.
network
microsoft CWE-20
critical
9.3
2007-05-29 CVE-2007-2388 Permissions, Privileges, and Access Controls vulnerability in Apple Quicktime 7.1.6
Apple QuickTime for Java 7.1.6 on Mac OS X and Windows does not properly restrict QTObject subclassing, which allows remote attackers to execute arbitrary code via a web page containing a user-defined class that accesses unsafe functions that can be leveraged to write to arbitrary memory locations.
network
apple microsoft CWE-264
critical
9.3
2007-05-24 CVE-2007-2856 Buffer Errors vulnerability in Dart Powertcp ZIP Compression 1.8.5.3
Buffer overflow in the Dart Communications PowerTCP ZIP Compression ActiveX control in DartZip.dll 1.8.5.3, when Internet Explorer 6 is used, allows user-assisted remote attackers to execute arbitrary code via a long first argument to the QuickZip function, a related issue to CVE-2007-2855.
network
dart microsoft CWE-119
critical
9.3
2007-05-22 CVE-2007-2815 Permissions, Privileges, and Access Controls vulnerability in Microsoft Internet Information Services 5.0
The "hit-highlighting" functionality in webhits.dll in Microsoft Internet Information Services (IIS) Web Server 5.0 only uses Windows NT ACL configuration, which allows remote attackers to bypass NTLM and basic authentication mechanisms and access private web directories via the CiWebhitsfile parameter to null.htw.
network
low complexity
microsoft CWE-264
critical
10.0
2007-05-17 CVE-2007-2736 Remote File Include vulnerability in Achievo 1.1.0
PHP remote file inclusion vulnerability in index.php in Achievo 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the config_atkroot parameter.
network
low complexity
apple hp ibm linux microsoft santa-cruz-operation sun windriver achievo
critical
10.0