Vulnerabilities > Microsoft > Windows 2003 Server > r2

DATE CVE VULNERABILITY TITLE RISK
2007-03-26 CVE-2007-1692 Configuration vulnerability in Microsoft Windows 2000 and Windows 2003 Server
The default configuration of Microsoft Windows uses the Web Proxy Autodiscovery Protocol (WPAD) without static WPAD entries, which might allow remote attackers to intercept web traffic by registering a proxy server using WINS or DNS, then responding to WPAD requests, as demonstrated using Internet Explorer.
network
low complexity
microsoft CWE-16
7.5
2007-02-21 CVE-2007-1070 Stack Buffer Overflow vulnerability in Trend Micro Serverprotect 5.58/5.61/5.62
Multiple stack-based buffer overflows in Trend Micro ServerProtect for Windows and EMC 5.58, and for Network Appliance Filer 5.61 and 5.62, allow remote attackers to execute arbitrary code via crafted RPC requests to TmRpcSrv.dll that trigger overflows when calling the (1) CMON_NetTestConnection, (2) CMON_ActiveUpdate, and (3) CMON_ActiveRollback functions in (a) StCommon.dll, and (4) ENG_SetRealTimeScanConfigInfo and (5) ENG_SendEMail functions in (b) eng50.dll.
network
low complexity
microsoft trend-micro
critical
10.0
2007-01-19 CVE-2007-0351 Local Security vulnerability in Microsoft Windows
Microsoft Windows XP and Windows Server 2003 do not properly handle user logoff, which might allow local users to gain the privileges of a previous system user, possibly related to user profile unload failure.
local
high complexity
microsoft zonelabs
6.2
2006-12-31 CVE-2006-6901 Remote Security vulnerability in Microsoft Windows 2003 Server R2
Unspecified vulnerability in the Bluetooth stack in Microsoft Windows allows remote attackers to gain administrative access (aka Remote Root) via unspecified vectors.
network
low complexity
microsoft
critical
10.0
2006-12-13 CVE-2006-5585 Permissions, Privileges, and Access Controls vulnerability in Microsoft Windows 2003 Server and Windows XP
The Client-Server Run-time Subsystem in Microsoft Windows XP SP2 and Server 2003 allows local users to gain privileges via a crafted file manifest within an application, aka "File Manifest Corruption Vulnerability."
local
low complexity
microsoft CWE-264
7.2
2006-11-14 CVE-2006-3445 Numeric Errors vulnerability in Microsoft Windows 2000, Windows 2003 Server and Windows XP
Integer overflow in the ReadWideString function in agentdpv.dll in Microsoft Agent on Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 allows remote attackers to execute arbitrary code via a large length value in an .ACF file, which results in a heap-based buffer overflow.
network
low complexity
microsoft CWE-189
7.5
2006-10-10 CVE-2006-4696 Code Injection vulnerability in Microsoft Windows 2000, Windows 2003 Server and Windows XP
Unspecified vulnerability in the Server service in Microsoft Windows 2000 SP4, Server 2003 SP1 and earlier, and XP SP2 and earlier allows remote attackers to execute arbitrary code via a crafted packet, aka "SMB Rename Vulnerability."
network
low complexity
microsoft CWE-94
critical
9.0
2006-09-12 CVE-2006-0032 Cross-Site Scripting vulnerability in Microsoft Windows 2000, Windows 2003 Server and Windows XP
Cross-site scripting (XSS) vulnerability in the Indexing Service in Microsoft Windows 2000, XP, and Server 2003, when the Encoding option is set to Auto Select, allows remote attackers to inject arbitrary web script or HTML via a UTF-7 encoded URL, which is injected into an error message whose charset is set to UTF-7.
network
microsoft CWE-79
4.3
2006-08-10 CVE-2006-4071 Remote Denial of Service vulnerability in Microsoft Windows 2003 Server and Windows XP
Sign extension vulnerability in the createBrushIndirect function in the GDI library (gdi32.dll) in Microsoft Windows XP, Server 2003, and possibly other versions, allows user-assisted attackers to cause a denial of service (application crash) via a crafted WMF file.
network
high complexity
microsoft
2.6
2006-08-09 CVE-2006-3648 Remote Code Execution vulnerability in Microsoft Windows 2000, Windows 2003 Server and Windows XP
Unspecified vulnerability in Microsoft Windows 2000 SP4, XP SP1 and SP2, Server 2003 and 2003 SP1, allows remote attackers to execute arbitrary code via unspecified vectors involving unhandled exceptions, memory resident applications, and incorrectly "unloading chained exception."
network
high complexity
microsoft
7.6