Vulnerabilities > Microsoft > Critical

DATE CVE VULNERABILITY TITLE RISK
2007-02-13 CVE-2006-4697 Unspecified vulnerability in Microsoft IE and Internet Explorer
Microsoft Internet Explorer 5.01, 6, and 7 uses certain COM objects from Imjpcksid.dll as ActiveX controls, which allows remote attackers to execute arbitrary code via unspecified vectors.
network
microsoft
critical
9.3
2007-02-13 CVE-2007-0209 Code Injection vulnerability in Microsoft Office and Works
Microsoft Word in Office 2000 SP3, XP SP3, Office 2003 SP2, Works Suite 2004 to 2006, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via a Word file with a malformed drawing object, which leads to memory corruption.
network
microsoft CWE-94
critical
9.3
2007-02-13 CVE-2007-0208 Improper Input Validation vulnerability in Microsoft products
Microsoft Word in Office 2000 SP3, XP SP3, Office 2003 SP2, Works Suite 2004 to 2006, and Office 2004 for Mac does not correctly check the properties of certain documents and warn the user of macro content, which allows user-assisted remote attackers to execute arbitrary code.
network
microsoft CWE-20
critical
9.3
2007-02-13 CVE-2007-0214 Remote Code Execution vulnerability in Microsoft Windows 2000, Windows 2003 Server and Windows XP
The HTML Help ActiveX control (Hhctrl.ocx) in Microsoft Windows 2000 SP3, XP SP2 and Professional, 2003 SP1 allows remote attackers to execute arbitrary code via unspecified functions, related to uninitialized parameters.
network
microsoft
critical
9.3
2007-02-13 CVE-2007-0025 Code Injection vulnerability in Microsoft Visual Studio .Net and Windows 2003 Server
The MFC component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1 and Visual Studio .NET 2000, 2002 SP1, 2003, and 2003 SP1 allows user-assisted remote attackers to execute arbitrary code via an RTF file with a malformed OLE object that triggers memory corruption.
network
microsoft CWE-94
critical
9.3
2007-02-13 CVE-2006-5270 Integer Overflow vulnerability in Microsoft Antivirus Engine
Integer overflow in the Microsoft Malware Protection Engine (mpengine.dll), as used by Windows Live OneCare, Antigen, Defender, and Forefront Security, allows user-assisted remote attackers to execute arbitrary code via a crafted PDF file.
network
microsoft
critical
9.3
2007-02-13 CVE-2006-3448 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Microsoft Step-By-Step Interactive Training
Buffer overflow in the Step-by-Step Interactive Training in Microsoft Windows 2000 SP4, XP SP2 and Professional, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a long Syllabus string in crafted bookmark link files (cbo, cbl, or .cbm), a different issue than CVE-2005-1212.
network
microsoft CWE-119
critical
9.3
2007-02-13 CVE-2006-1311 Remote Code Execution vulnerability in Microsoft Office And Microsoft Windows RichEdit Component
The RichEdit component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1; Office 2000 SP3, XP SP3, 2003 SP2, and Office 2004 for Mac; and Learning Essentials for Microsoft Office 1.0, 1.1, and 1.5 allows user-assisted remote attackers to execute arbitrary code via a malformed OLE object in an RTF file, which triggers memory corruption.
network
microsoft
critical
9.3
2007-02-03 CVE-2007-0671 Remote Code Execution vulnerability in Microsoft Office Malformed String
Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as demonstrated by Exploit-MSExcel.h in targeted zero-day attacks.
network
microsoft
critical
9.3
2007-01-26 CVE-2007-0515 Unspecified vulnerability in Microsoft products
Unspecified vulnerability in Microsoft Word allows user-assisted remote attackers to execute arbitrary code on Word 2000, and cause a denial of service on Word 2003, via unknown attack vectors that trigger memory corruption, as exploited by Trojan.Mdropper.W and later by Trojan.Mdropper.X, a different issue than CVE-2006-6456, CVE-2006-5994, and CVE-2006-6561.
network
microsoft
critical
9.3