Vulnerabilities > Microsoft > Windows 7 > Medium

DATE CVE VULNERABILITY TITLE RISK
2013-05-20 CVE-2013-0996 Resource Management Errors vulnerability in Apple Itunes
WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.
6.8
2013-05-20 CVE-2013-0995 Resource Management Errors vulnerability in Apple Itunes
WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.
6.8
2013-05-20 CVE-2013-0994 Resource Management Errors vulnerability in Apple Itunes
WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.
6.8
2013-05-20 CVE-2013-0993 Resource Management Errors vulnerability in Apple Itunes
WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.
6.8
2013-05-20 CVE-2013-0992 Resource Management Errors vulnerability in multiple products
WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.
6.8
2013-05-20 CVE-2013-0991 Resource Management Errors vulnerability in Apple Itunes
WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.
6.8
2012-10-09 CVE-2012-2551 Denial of Service vulnerability in Microsoft Windows Kerberos
The server in Kerberos in Microsoft Windows Server 2008 R2 and R2 SP1, and Windows 7 Gold and SP1, allows remote attackers to cause a denial of service (NULL pointer dereference and reboot) via a crafted session request, aka "Kerberos NULL Dereference Vulnerability." Per: http://cwe.mitre.org/data/definitions/476.html 'CWE-476: NULL Pointer Dereference'
network
low complexity
microsoft
5.0
2012-04-20 CVE-2012-2273 Code Injection vulnerability in Comodo Internet Security
Comodo Internet Security before 5.10.228257.2253 on Windows 7 x64 allows local users to cause a denial of service (system crash) via a crafted 32-bit Portable Executable (PE) file with a kernel ImageBase value.
local
low complexity
comodo microsoft CWE-94
4.9
2012-03-28 CVE-2007-6753 Unspecified vulnerability in Microsoft products
Untrusted search path vulnerability in Shell32.dll in Microsoft Windows 2000, Windows XP, Windows Vista, Windows Server 2008, and Windows 7, when using an environment configured with a string such as %APPDATA% or %PROGRAMFILES% in a certain way, allows local users to gain privileges via a Trojan horse DLL under the current working directory, as demonstrated by iTunes and Safari.
local
high complexity
microsoft
6.2
2012-03-13 CVE-2012-0152 Improper Input Validation vulnerability in Microsoft Windows 7 and Windows Server 2008
The Remote Desktop Protocol (RDP) service in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows remote attackers to cause a denial of service (application hang) via a series of crafted packets, aka "Terminal Server Denial of Service Vulnerability."
network
microsoft CWE-20
4.3