Vulnerabilities > Microsoft > Windows 2003 Server > Critical

DATE CVE VULNERABILITY TITLE RISK
2004-11-03 CVE-2004-0575 Unspecified vulnerability in Microsoft Windows 2003 Server and Windows XP
Integer overflow in DUNZIP32.DLL for Microsoft Windows XP, Windows XP 64-bit Edition, Windows Server 2003, and Windows Server 2003 64-bit Edition allows remote attackers to execute arbitrary code via compressed (zipped) folders that involve an "unchecked buffer" and improper length validation.
network
low complexity
microsoft
critical
10.0
2004-09-28 CVE-2004-0200 Unspecified vulnerability in Microsoft products
Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.
network
microsoft
critical
9.3
2004-08-06 CVE-2004-0201 Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, Me, NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary commands via a .CHM file with a large length field, a different vulnerability than CVE-2003-1041.
network
low complexity
avaya microsoft
critical
10.0
2004-03-03 CVE-2003-0825 Improper Input Validation vulnerability in Microsoft Windows 2000, Windows 2003 Server and Windows NT
The Windows Internet Naming Service (WINS) for Microsoft Windows Server 2003, and possibly Windows NT and Server 2000, does not properly validate the length of certain packets, which allows attackers to cause a denial of service and possibly execute arbitrary code.
network
microsoft CWE-20
critical
9.3
2003-09-17 CVE-2003-0528 Unspecified vulnerability in Microsoft products
Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed RPC request with a long filename parameter, a different vulnerability than CVE-2003-0352 (Blaster/Nachi) and CVE-2003-0715.
network
low complexity
microsoft
critical
10.0
2003-09-17 CVE-2003-0715 Unspecified vulnerability in Microsoft products
Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed DCERPC DCOM object activation request packet with modified length fields, a different vulnerability than CVE-2003-0352 (Blaster/Nachi) and CVE-2003-0528.
network
low complexity
microsoft
critical
10.0