Vulnerabilities > Microsoft > Windows 2003 Server > High

DATE CVE VULNERABILITY TITLE RISK
2013-07-31 CVE-2013-3697 Numeric Errors vulnerability in Novell Client 2.0/4.91
Integer overflow in the NWFS.SYS kernel driver 4.91.5.8 in Novell Client 4.91 SP5 on Windows XP and Windows Server 2003 and the NCPL.SYS kernel driver in Novell Client 2 SP2 on Windows Vista and Windows Server 2008 and Novell Client 2 SP3 on Windows Server 2008 R2, Windows 7, Windows 8, and Windows Server 2012 might allow local users to gain privileges via a crafted 0x1439EB IOCTL call.
local
low complexity
novell microsoft CWE-189
7.2
2012-05-02 CVE-2012-2004 Improper Input Validation vulnerability in HP Insight Management Agents
Open redirect vulnerability in HP Insight Management Agents before 9.0.0.0 on Windows Server 2003 and 2008 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
network
hp microsoft CWE-20
8.3
2011-12-16 CVE-2011-4847 SQL Injection vulnerability in Parallels Plesk Panel 10.4.4Build20111103.18
SQL injection vulnerability in the Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 allows remote attackers to execute arbitrary SQL commands via a certificateslist cookie to notification@/.
network
low complexity
parallels microsoft CWE-89
7.5
2011-10-12 CVE-2011-2005 Permissions, Privileges, and Access Controls vulnerability in Microsoft products
afd.sys in the Ancillary Function Driver in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application, aka "Ancillary Function Driver Elevation of Privilege Vulnerability."
local
low complexity
microsoft CWE-264
7.2
2011-09-15 CVE-2011-1984 Permissions, Privileges, and Access Controls vulnerability in Microsoft products
WINS in Microsoft Windows Server 2003 SP2 and Server 2008 SP2, R2, and R2 SP1 allows local users to gain privileges by sending crafted packets over the loopback interface, aka "WINS Local Elevation of Privilege Vulnerability."
local
low complexity
microsoft CWE-264
7.2
2011-08-10 CVE-2011-1974 Permissions, Privileges, and Access Controls vulnerability in Microsoft products
NDISTAPI.sys in the NDISTAPI driver in Remote Access Service (RAS) in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP2 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "NDISTAPI Elevation of Privilege Vulnerability."
local
low complexity
microsoft CWE-264
7.2
2011-08-10 CVE-2011-1968 Resource Management Errors vulnerability in Microsoft products
The Remote Desktop Protocol (RDP) implementation in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP2 does not properly process packets in memory, which allows remote attackers to cause a denial of service (reboot) by sending crafted RDP packets triggering access to an object that (1) was not properly initialized or (2) is deleted, as exploited in the wild in 2011, aka "Remote Desktop Protocol Vulnerability."
network
microsoft CWE-399
7.1
2011-07-13 CVE-2011-1870 Numeric Errors vulnerability in Microsoft products
Integer overflow in the Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, and Windows Server 2003 SP2, allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application that triggers an incorrect memory assignment for a user transaction, aka "CSRSS Local EOP SrvWriteConsoleOutputString Vulnerability."
local
low complexity
microsoft CWE-189
7.2
2011-06-16 CVE-2011-1249 Permissions, Privileges, and Access Controls vulnerability in Microsoft products
The Ancillary Function Driver (AFD) in afd.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Ancillary Function Driver Elevation of Privilege Vulnerability."
local
low complexity
microsoft CWE-264
7.2
2011-04-13 CVE-2011-1229 Null Pointer Dereference vulnerability in multiple products
win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."
local
low complexity
microsoft avaya CWE-476
7.2