Vulnerabilities > Microsoft > Windows 2003 Server

DATE CVE VULNERABILITY TITLE RISK
2005-10-12 CVE-2005-1978 Remote Code Execution vulnerability in Microsoft Windows 2000, Windows 2003 Server and Windows XP
COM+ in Microsoft Windows does not properly "create and use memory structures," which allows local users or remote attackers to execute arbitrary code.
network
low complexity
microsoft
7.5
2005-10-06 CVE-2005-3177 Local Security vulnerability in Microsoft Windows 2000, Windows 2003 Server and Windows XP
CHKDSK in Microsoft Windows 2000 before Update Rollup 1 for SP4, Windows XP, and Windows Server 2003, when running in fix mode, does not properly handle security descriptors if the master file table contains a large number of files or if the descriptors do not satisfy certain NTFS conventions, which could cause ACLs for some files to be reverted to less secure defaults, or cause security descriptors to be removed.
local
low complexity
microsoft
4.6
2005-09-01 CVE-2005-2765 Local Security vulnerability in Microsoft Windows 2003 Server and Windows XP
The user interface in the Windows Firewall does not properly display certain malformed entries in the Windows Registry, which makes it easier for attackers with administrator privileges to hide activities if the administrator only uses the Windows Firewall interface to monitor exceptions.
local
low complexity
microsoft
2.1
2005-08-10 CVE-2005-1984 Buffer Overflow vulnerability in Microsoft Windows 2000, Windows 2003 Server and Windows XP
Buffer overflow in the Print Spooler service (Spoolsv.exe) for Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via a malicious message.
network
low complexity
microsoft
7.5
2005-08-10 CVE-2005-1982 Man In The Middle vulnerability in Microsoft Windows 2000, Windows 2003 Server and Windows XP
Unknown vulnerability in the PKINIT Protocol for Microsoft Windows 2000, Windows XP, and Windows Server 2003 could allow a local user to obtain information and spoof a server via a man-in-the-middle (MITM) attack between a client and a domain controller when PKINIT smart card authentication is being used.
local
low complexity
microsoft
3.6
2005-08-10 CVE-2005-1981 Unspecified vulnerability in Microsoft Windows 2000 and Windows 2003 Server
Unknown vulnerability in Microsoft Windows 2000 Server and Windows Server 2003 domain controllers allows remote authenticated users to cause a denial of service (system crash) via a crafted Kerberos message.
local
low complexity
microsoft
2.1
2005-08-10 CVE-2005-1218 Remote Desktop Protocol Denial Of Service vulnerability in Microsoft Windows 2000, Windows 2003 Server and Windows XP
The Microsoft Windows kernel in Microsoft Windows 2000 Server, Windows XP, and Windows Server 2003 allows remote attackers to cause a denial of service (crash) via crafted Remote Desktop Protocol (RDP) requests.
network
low complexity
microsoft
5.0
2005-08-10 CVE-2005-0058 Buffer Overflow vulnerability in Microsoft Windows Telephony Service
Buffer overflow in the Telephony Application Programming Interface (TAPI) for Microsoft Windows 98, Windows 98 SE, Windows ME, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to elevate privileges or execute arbitrary code via a crafted message.
network
low complexity
microsoft
7.5
2005-06-14 CVE-2005-1214 Unspecified vulnerability in Microsoft products
Microsoft Agent allows remote attackers to spoof trusted Internet content and execute arbitrary code by disguising security prompts on a malicious Web page.
network
high complexity
microsoft
5.1
2005-06-14 CVE-2005-1212 Buffer Overflow vulnerability in Microsoft Step-By-Step Interactive Training Bookmark Link
Buffer overflow in Microsoft Step-by-Step Interactive Training (orun32.exe) allows remote attackers to execute arbitrary code via a bookmark link file (.cbo, cbl, or .cbm extension) with a long User field.
network
low complexity
microsoft
7.5