Vulnerabilities > Microsoft > Windows Media Player > 10

DATE CVE VULNERABILITY TITLE RISK
2015-06-10 CVE-2015-1728 Code vulnerability in Microsoft Windows Media Player
Microsoft Windows Media Player 10 through 12 allows remote attackers to execute arbitrary code via a crafted DataObject on a web site, aka "Windows Media Player RCE via DataObject Vulnerability."
network
microsoft CWE-17
critical
9.3
2008-12-29 CVE-2008-5745 Numeric Errors vulnerability in Microsoft Windows Media Player 10/11/9
Integer overflow in quartz.dll in the DirectShow framework in Microsoft Windows Media Player (WMP) 9, 10, and 11, including 11.0.5721.5260, allows remote attackers to cause a denial of service (application crash) via a crafted (1) WAV, (2) SND, or (3) MID file.
network
microsoft CWE-189
4.3
2008-11-04 CVE-2008-4927 Improper Input Validation vulnerability in Microsoft Windows Media Player 10/11/9
Microsoft Windows Media Player (WMP) 9.0 through 11 allows user-assisted attackers to cause a denial of service (application crash) via a malformed (1) MIDI or (2) DAT file, related to "MThd Header Parsing." NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
network
microsoft CWE-20
4.3
2007-08-14 CVE-2007-3037 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Microsoft Windows Media Player
Microsoft Windows Media Player 7.1, 9, 10, and 11 allows remote attackers to execute arbitrary code via a skin file (WMZ or WMD) with crafted header information that causes a size mismatch between compressed and decompressed data and triggers a heap-based buffer overflow, aka "Windows Media Player Code Execution Vulnerability Parsing Skins."
network
high complexity
microsoft CWE-119
4.0
2007-08-14 CVE-2007-3035 Remote Skin Header Code Execution vulnerability in Microsoft Windows Media Player
Unspecified vulnerability in Microsoft Windows Media Player 7.1, 9, 10, and 11 allows remote attackers to execute arbitrary code via a skin file (WMZ or WMD) with crafted header information that is not properly handled during decompression, aka "Windows Media Player Code Execution Vulnerability Decompressing Skins."
network
high complexity
microsoft
7.6
2006-06-13 CVE-2006-0025 Buffer Errors vulnerability in Microsoft Windows Media Player 10/9
Stack-based buffer overflow in Microsoft Windows Media Player 9 and 10 allows remote attackers to execute arbitrary code via a PNG image with a large chunk size.
network
microsoft CWE-119
critical
9.3
2006-02-14 CVE-2006-0006 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Microsoft products
Heap-based buffer overflow in the bitmap processing routine in Microsoft Windows Media Player 7.1 on Windows 2000 SP4, Media Player 9 on Windows 2000 SP4 and XP SP1, and Media Player 10 on XP SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted bitmap (.BMP) file that specifies a size of 0 but contains additional data.
network
microsoft CWE-119
critical
9.3