Vulnerabilities > Microsoft > Windows 98

DATE CVE VULNERABILITY TITLE RISK
2004-08-06 CVE-2004-0202 Remote Malformed Packet Denial Of Service vulnerability in Microsoft DirectX DirectPlay
IDirectPlay4 Application Programming Interface (API) of Microsoft DirectPlay 7.0a thru 9.0b, as used in Windows Server 2003 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed packet.
network
low complexity
microsoft
5.0
2004-08-06 CVE-2004-0201 Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, Me, NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary commands via a .CHM file with a large length field, a different vulnerability than CVE-2003-1041.
network
low complexity
avaya microsoft
critical
10.0
2004-07-27 CVE-2003-1048 Double Free vulnerability in Microsoft products
Double free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image.
local
low complexity
microsoft CWE-415
7.8
2004-06-01 CVE-2004-0123 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Microsoft products
Double free vulnerability in the ASN.1 library as used in Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service and possibly execute arbitrary code.
network
low complexity
microsoft CWE-119
7.5
2004-06-01 CVE-2004-0117 Unspecified vulnerability in Microsoft products
Unknown vulnerability in the H.323 protocol implementation in Windows 98, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code.
network
low complexity
microsoft
7.5
2004-06-01 CVE-2003-0719 Unspecified vulnerability in Microsoft products
Buffer overflow in the Private Communications Transport (PCT) protocol implementation in the Microsoft SSL library, as used in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via PCT 1.0 handshake packets.
network
low complexity
microsoft
7.5
2004-06-01 CVE-2003-0533 Buffer Overrun vulnerability in Microsoft Windows LSASS
Stack-based buffer overflow in certain Active Directory service functions in LSASRV.DLL of the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via a packet that causes the DsRolerUpgradeDownlevelServer function to create long debug entries for the DCPROMO.LOG log file, as exploited by the Sasser worm.
network
low complexity
microsoft
7.5
2003-08-07 CVE-2003-0469 Buffer Overflow vulnerability in Microsoft Windows HTML Converter HR Align
Buffer overflow in the HTML Converter (HTML32.cnv) on various Windows operating systems allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via cut-and-paste operation, as demonstrated in Internet Explorer 5.0 using a long "align" argument in an HR tag.
network
low complexity
microsoft
7.5
2003-03-24 CVE-2003-0010 Heap Overflow vulnerability in Microsoft Windows Script Engine JScript.DLL
Integer overflow in JsArrayFunctionHeapSort function used by Windows Script Engine for JScript (JScript.dll) on various Windows operating system allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail that uses a large array index value that enables a heap-based buffer overflow attack.
network
low complexity
microsoft
7.5
2002-12-31 CVE-2002-2185 Denial Of Service vulnerability in Multiple Vendor Spoofed IGMP Report
The Internet Group Management Protocol (IGMP) allows local users to cause a denial of service via an IGMP membership report to a target's Ethernet address instead of the Multicast group address, which causes the target to stop sending reports to the router and effectively disconnect the group from the network.
local
low complexity
sgi debian mandrakesoft microsoft redhat suse
4.9