Vulnerabilities > Microsoft > Critical

DATE CVE VULNERABILITY TITLE RISK
2006-07-13 CVE-2006-1302 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Microsoft Excel and Excel Viewer
Buffer overflow in Microsoft Excel 2000 through 2003 allows user-assisted attackers to execute arbitrary code via a .xls file with certain crafted fields in a SELECTION record, which triggers memory corruption, aka "Malformed SELECTION record Vulnerability."
network
microsoft CWE-119
critical
9.3
2006-07-11 CVE-2006-2389 Unspecified vulnerability in Microsoft Office 2000/2003/Xp
Unspecified vulnerability in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via an Office file with a malformed property that triggers memory corruption related to record lengths, aka "Microsoft Office Property Vulnerability," a different vulnerability than CVE-2006-1316.
network
microsoft
critical
9.3
2006-07-11 CVE-2006-2372 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Microsoft Dhcp Client Service
Buffer overflow in the DHCP Client service for Microsoft Windows 2000 SP4, Windows XP SP1 and SP2, and Server 2003 up to SP1 allows remote attackers to execute arbitrary code via a crafted DHCP response.
network
low complexity
microsoft CWE-119
critical
10.0
2006-07-11 CVE-2006-1316 Code Injection vulnerability in Microsoft Office 2000/2003/Xp
Unspecified vulnerability in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via an Office file with malformed string that triggers memory corruption related to record lengths, aka "Microsoft Office Parsing Vulnerability," a different vulnerability than CVE-2006-2389.
network
microsoft CWE-94
critical
9.3
2006-07-11 CVE-2006-0033 Remote Code Execution vulnerability in Microsoft Office Malformed PNG File
Unspecified vulnerability in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via a crafted PNG image that triggers memory corruption when it is parsed.
network
microsoft
critical
9.3
2006-07-11 CVE-2006-0007 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Microsoft Office 2000/2003/Xp
Buffer overflow in GIFIMP32.FLT, as used in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via a crafted GIF image that triggers memory corruption when it is parsed.
network
microsoft CWE-119
critical
9.3
2006-06-19 CVE-2006-3086 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Microsoft Hyperlink Object Library
Stack-based buffer overflow in the HrShellOpenWithMonikerDisplayName function in Microsoft Hyperlink Object Library (hlink.dll) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long hyperlink, as demonstrated using an Excel worksheet with a long link in Unicode, aka "Hyperlink COM Object Buffer Overflow Vulnerability." NOTE: this is a different issue than CVE-2006-3059.
network
microsoft CWE-119
critical
9.3
2006-06-17 CVE-2006-3059 Remote Code Execution vulnerability in Microsoft Excel
Unspecified vulnerability in Microsoft Excel 2000 through 2004 allows remote user-assisted attackers to execute arbitrary code via unspecified vectors.
network
microsoft
critical
9.3
2006-06-13 CVE-2006-2383 Unspecified vulnerability in Microsoft Internet Explorer 5.01/6
Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows remote attackers to execute arbitrary code via "unexpected data" related to "parameter validation" in the DXImageTransform.Microsoft.Light ActiveX control, which causes Internet Explorer to crash in a way that enables the code execution.
network
microsoft
critical
9.3
2006-06-13 CVE-2006-2382 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Microsoft Internet Explorer 5.01/6
Heap-based buffer overflow in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows remote attackers to execute arbitrary code via crafted UTF-8 encoded HTML that results in size discrepancies during conversion to Unicode, aka "HTML Decoding Memory Corruption Vulnerability."
network
low complexity
microsoft CWE-119
critical
10.0