Vulnerabilities > Microsoft > Windows NT > Medium

DATE CVE VULNERABILITY TITLE RISK
2008-05-13 CVE-2008-2163 Cross-Site Scripting vulnerability in IBM Lotus Quickr 8.1
Cross-site scripting (XSS) vulnerability in IBM Lotus Quickr 8.1 before Hotfix 5 for Windows and AIX, and before Hotfix 3 for i5/OS, allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to "WYSIWYG editors."
network
ibm microsoft CWE-79
4.3
2008-04-25 CVE-2008-1932 Numeric Errors vulnerability in Realtek HD Audio Codec Drivers
Integer overflow in Realtek HD Audio Codec Drivers RTKVHDA.sys and RTKVHDA64.sys before 6.0.1.5605 on Windows Vista allows local users to execute arbitrary code via a crafted IOCTL request.
local
low complexity
microsoft realtek CWE-189
6.8
2008-04-25 CVE-2008-1931 Permissions, Privileges, and Access Controls vulnerability in Realtek HD Audio Codec Drivers
Realtek HD Audio Codec Drivers RTKVHDA.sys and RTKVHDA64.sys before 6.0.1.5605 on Windows Vista allow local users to create, write, and read registry keys via a crafted IOCTL request.
local
low complexity
microsoft realtek CWE-264
6.8
2008-04-14 CVE-2008-0927 Resource Management Errors vulnerability in Microsoft Windows-Nt 2000/2003
dhost.exe in Novell eDirectory 8.7.3 before sp10 and 8.8.2 allows remote attackers to cause a denial of service (CPU consumption) via an HTTP request with (1) multiple Connection headers or (2) a Connection header with multiple comma-separated values.
network
low complexity
novell microsoft CWE-399
5.0
2007-12-20 CVE-2007-6334 Permissions, Privileges, and Access Controls vulnerability in Ingres 2.5/2.6
Ingres 2.5 and 2.6 on Windows, as used in multiple CA products and possibly other products, assigns the privileges and identity of users to be the same as the first user, which allows remote attackers to gain privileges.
network
low complexity
microsoft ingres CWE-264
5.0
2007-05-16 CVE-2007-1898 Unspecified vulnerability in Jetbox CMS 2.1
formmail.php in Jetbox CMS 2.1 allows remote attackers to send arbitrary e-mails (spam) via modified recipient, _SETTINGS[allowed_email_hosts][], and subject parameters.
5.8
2007-04-24 CVE-2007-2186 Denial of Service vulnerability in Foxit PDF Reader 2.0
Foxit Reader 2.0 allows remote attackers to cause a denial of service (application crash) via a crafted PDF document.
network
low complexity
microsoft foxit
5.0
2007-04-11 CVE-2007-1973 Denial-Of-Service vulnerability in Microsoft Windows NT 4.0
Race condition in the Virtual DOS Machine (VDM) in the Windows Kernel in Microsoft Windows NT 4.0 allows local users to modify memory and gain privileges via the temporary \Device\PhysicalMemory section handle, a related issue to CVE-2007-1206.
local
microsoft
6.9
2007-04-10 CVE-2007-1912 Heap Overflow vulnerability in Microsoft Windows Help File
Heap-based buffer overflow in Microsoft Windows allows user-assisted remote attackers to have an unknown impact via a crafted .HLP file.
network
microsoft
6.8
2007-03-28 CVE-2007-1727 Remote Unauthorized Access vulnerability in HP OpenView Network Node Manager
Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 6.20, 6.4x, 7.01, 7.50, and 7.51 allows remote authenticated users to access certain privileged "facilities" via unspecified vectors.
network
low complexity
hp linux microsoft sun
6.5