Vulnerabilities > Microsoft > Windows 2003 Server > professional

DATE CVE VULNERABILITY TITLE RISK
2008-10-15 CVE-2008-3464 Permissions, Privileges, and Access Controls vulnerability in Microsoft Windows 2003 Server and Windows XP
afd.sys in the Ancillary Function Driver (AFD) component in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP1 and SP2 does not properly validate input sent from user mode to the kernel, which allows local users to gain privileges via a crafted application, as demonstrated using crafted pointers and lengths that bypass intended ProbeForRead and ProbeForWrite restrictions, aka "AFD Kernel Overwrite Vulnerability."
local
low complexity
microsoft CWE-264
7.2
2006-08-31 CVE-2006-4495 COM Object Instantiation Code Execution vulnerability in Microsoft Windows 2000
Microsoft Internet Explorer allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code by instantiating certain Windows 2000 ActiveX COM Objects including (1) ciodm.dll, (2) myinfo.dll, (3) msdxm.ocx, and (4) creator.dll.
network
low complexity
microsoft
7.5