Vulnerabilities > Microsoft > Windows 2003 Server > itanium

DATE CVE VULNERABILITY TITLE RISK
2007-04-30 CVE-2007-2374 Remote Code Execution vulnerability in Microsoft Windows
Unspecified vulnerability in Microsoft Windows 2000, XP, and Server 2003 allows user-assisted remote attackers to execute arbitrary code via unspecified vectors.
network
microsoft avaya
critical
9.3
2007-02-13 CVE-2007-0214 Remote Code Execution vulnerability in Microsoft Windows 2000, Windows 2003 Server and Windows XP
The HTML Help ActiveX control (Hhctrl.ocx) in Microsoft Windows 2000 SP3, XP SP2 and Professional, 2003 SP1 allows remote attackers to execute arbitrary code via unspecified functions, related to uninitialized parameters.
network
microsoft
critical
9.3
2006-12-13 CVE-2006-5585 Permissions, Privileges, and Access Controls vulnerability in Microsoft Windows 2003 Server and Windows XP
The Client-Server Run-time Subsystem in Microsoft Windows XP SP2 and Server 2003 allows local users to gain privileges via a crafted file manifest within an application, aka "File Manifest Corruption Vulnerability."
local
low complexity
microsoft CWE-264
7.2
2006-11-14 CVE-2006-3445 Numeric Errors vulnerability in Microsoft Windows 2000, Windows 2003 Server and Windows XP
Integer overflow in the ReadWideString function in agentdpv.dll in Microsoft Agent on Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 allows remote attackers to execute arbitrary code via a large length value in an .ACF file, which results in a heap-based buffer overflow.
network
low complexity
microsoft CWE-189
7.5
2006-10-27 CVE-2006-5559 Improper Input Validation vulnerability in Microsoft Data Access Components 2.5/2.7/2.8
The Execute method in the ADODB.Connection 2.7 and 2.8 ActiveX control objects (ADODB.Connection.2.7 and ADODB.Connection.2.8) in the Microsoft Data Access Components (MDAC) 2.5 SP3, 2.7 SP1, 2.8, and 2.8 SP1 does not properly track freed memory when the second argument is a BSTR, which allows remote attackers to cause a denial of service (Internet Explorer crash) and possibly execute arbitrary code via certain strings in the second and third arguments.
network
microsoft CWE-20
critical
9.3
2006-08-09 CVE-2006-3439 Remote Buffer Overflow vulnerability in Microsoft Windows 2000, Windows 2003 Server and Windows XP
Buffer overflow in the Server Service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers, including anonymous users, to execute arbitrary code via a crafted RPC message, a different vulnerability than CVE-2006-1314.
network
low complexity
microsoft
critical
10.0
2006-07-31 CVE-2006-3942 Improper Input Validation vulnerability in Microsoft Windows 2000, Windows 2003 Server and Windows XP
The server driver (srv.sys) in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause a denial of service (system crash) via an SMB_COM_TRANSACTION SMB message that contains a string without null character termination, which leads to a NULL dereference in the ExecuteTransaction function, possibly related to an "SMB PIPE," aka the "Mailslot DOS" vulnerability.
network
low complexity
microsoft CWE-20
7.8
2006-07-11 CVE-2006-1314 Remote Heap Buffer Overflow vulnerability in Microsoft Windows 2000, Windows 2003 Server and Windows XP
Heap-based buffer overflow in the Server Service (SRV.SYS driver) in Microsoft Windows 2000 SP4, XP SP1 and SP2, Server 2003 up to SP1, and other products, allows remote attackers to execute arbitrary code via crafted first-class Mailslot messages that triggers memory corruption and bypasses size restrictions on second-class Mailslot messages.
network
low complexity
microsoft
7.5
2006-07-06 CVE-2006-3351 Denial Of Service vulnerability in Microsoft Windows 2003 Server and Windows XP
Buffer overflow in Windows Explorer (explorer.exe) on Windows XP and 2003 allows user-assisted attackers to cause a denial of service (repeated crash) and possibly execute arbitrary code via a .url file with an InternetShortcut tag containing a long URL and a large number of "file:" specifiers.
network
high complexity
microsoft
5.4
2005-11-29 CVE-2005-2124 Unspecified vulnerability in Microsoft Windows 2000, Windows 2003 Server and Windows XP
Unspecified vulnerability in the Graphics Rendering Engine (GDI32.DLL) in Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1, related to "An unchecked buffer" and possibly buffer overflows, allows remote attackers to execute arbitrary code via a crafted Windows Metafile (WMF) format image, aka "Windows Metafile Vulnerability."
network
high complexity
microsoft
7.6