Vulnerabilities > Microsoft > Windows 2003 Server > Medium

DATE CVE VULNERABILITY TITLE RISK
2011-06-16 CVE-2011-1264 Cross-Site Scripting vulnerability in Microsoft products
Cross-site scripting (XSS) vulnerability in Active Directory Certificate Services Web Enrollment in Microsoft Windows Server 2003 SP2 and Server 2008 Gold, SP2, R2, and R2 SP1 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka "Active Directory Certificate Services Vulnerability."
network
microsoft CWE-79
4.3
2011-02-09 CVE-2011-0040 Improper Input Validation vulnerability in Microsoft Windows 2003 Server
The server in Microsoft Active Directory on Windows Server 2003 SP2 does not properly handle an update request for a service principal name (SPN), which allows remote attackers to cause a denial of service (authentication downgrade or outage) via a crafted request that triggers name collisions, aka "Active Directory SPN Validation Vulnerability."
network
low complexity
microsoft CWE-20
5.0
2011-02-09 CVE-2011-0030 Permissions, Privileges, and Access Controls vulnerability in Microsoft Windows 2003 Server and Windows XP
The Client/Server Run-time Subsystem (CSRSS) in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly kill processes after a logout, which allows local users to obtain sensitive information or gain privileges via a crafted application that continues to execute throughout the logout of one user and the login session of the next user, aka "CSRSS Elevation of Privilege Vulnerability," a different vulnerability than CVE-2010-0023.
4.7
2010-12-16 CVE-2010-2742 Unspecified vulnerability in Microsoft products
The Netlogon RPC Service in Microsoft Windows Server 2003 SP2 and Server 2008 Gold, SP2, and R2, when the domain controller role is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and reboot) via a crafted RPC packet, aka "Netlogon RPC Null dereference DOS Vulnerability." Per: http://cwe.mitre.org/data/definitions/476.html 'CWE-476 NULL pointer dereference'
network
high complexity
microsoft
5.4
2010-06-15 CVE-2010-2265 Cross-Site Scripting vulnerability in Microsoft products
Cross-site scripting (XSS) vulnerability in the GetServerName function in sysinfo/commonFunc.js in Microsoft Windows Help and Support Center for Windows XP and Windows Server 2003 allows remote attackers to inject arbitrary web script or HTML via the svr parameter to sysinfo/sysinfomain.htm.
network
microsoft CWE-79
4.3
2010-05-06 CVE-2010-1735 Improper Input Validation vulnerability in Microsoft products
The SfnLOGONNOTIFY function in win32k.sys in the kernel in Microsoft Windows 2000, XP, and Server 2003 allows local users to cause a denial of service (system crash) via a 0x4c value in the second argument (aka the Msg argument) of a PostMessage function call for the DDEMLEvent window.
local
low complexity
microsoft CWE-20
4.9
2010-05-06 CVE-2010-1734 Improper Input Validation vulnerability in Microsoft products
The SfnINSTRING function in win32k.sys in the kernel in Microsoft Windows 2000, XP, and Server 2003 allows local users to cause a denial of service (system crash) via a 0x18d value in the second argument (aka the Msg argument) of a PostMessage function call for the DDEMLEvent window.
local
low complexity
microsoft CWE-20
4.9
2010-04-14 CVE-2010-0238 Improper Input Validation vulnerability in Microsoft products
Unspecified vulnerability in registry-key validation in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Vista Gold allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Registry Key Vulnerability."
local
low complexity
microsoft CWE-20
4.9
2010-04-14 CVE-2010-0235 Improper Input Validation vulnerability in Microsoft products
The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Vista Gold does not perform the expected validation before creating a symbolic link, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Symbolic Link Value Vulnerability."
4.7
2010-04-14 CVE-2010-0025 Information Exposure vulnerability in Microsoft products
The SMTP component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Server 2008 Gold, SP2, and R2, and Exchange Server 2000 SP3, does not properly allocate memory for SMTP command replies, which allows remote attackers to read fragments of e-mail messages by sending a series of invalid commands and then sending a STARTTLS command, aka "SMTP Memory Allocation Vulnerability."
network
low complexity
microsoft CWE-200
5.0