Vulnerabilities > Microsoft > Windows Server 2003 > Medium

DATE CVE VULNERABILITY TITLE RISK
2013-12-11 CVE-2013-3878 Buffer Errors vulnerability in Microsoft Windows Server 2003 and Windows XP
Stack-based buffer overflow in the LRPC client in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges by operating an LRPC server that sends a crafted LPC port message, aka "LRPC Client Buffer Overrun Vulnerability."
6.9
2013-11-13 CVE-2013-3869 Improper Input Validation vulnerability in Microsoft products
Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to cause a denial of service (daemon hang) via a web-service request containing a crafted X.509 certificate that is not properly handled during validation, aka "Digital Signatures Vulnerability."
network
low complexity
microsoft CWE-20
5.0
2013-06-12 CVE-2013-3136 Resource Management Errors vulnerability in Microsoft products
The kernel in Microsoft Windows XP SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, and Windows 8 on 32-bit platforms does not properly handle unspecified page-fault system calls, which allows local users to obtain sensitive information from kernel memory via a crafted application, aka "Kernel Information Disclosure Vulnerability."
4.4
2013-05-24 CVE-2013-3661 Path Traversal vulnerability in Microsoft products
The EPATHOBJ::bFlatten function in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not check whether linked-list traversal is continually accessing the same list member, which allows local users to cause a denial of service (infinite traversal) via vectors that trigger a crafted PATHRECORD chain.
local
low complexity
microsoft CWE-22
4.9
2012-05-02 CVE-2012-2006 Remote Security vulnerability in HP Insight Management Agents Unspecified
Unspecified vulnerability in HP Insight Management Agents before 9.0.0.0 on Windows Server 2003 and 2008 allows remote attackers to modify data or cause a denial of service via unknown vectors.
network
hp microsoft
4.9
2012-05-02 CVE-2012-2005 Cross-Site Scripting vulnerability in HP Insight Management Agents
Cross-site scripting (XSS) vulnerability in HP Insight Management Agents before 9.0.0.0 on Windows Server 2003 and 2008 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
hp microsoft CWE-79
4.3
2012-05-02 CVE-2012-2003 Cross-Site Request Forgery (CSRF) vulnerability in HP Insight Management Agents
Cross-site request forgery (CSRF) vulnerability in HP Insight Management Agents before 9.0.0.0 on Windows Server 2003 and 2008 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
network
hp microsoft CWE-352
6.8
2012-03-13 CVE-2012-0006 Resource Management Errors vulnerability in Microsoft Windows Server 2003 and Windows Server 2008
The DNS server in Microsoft Windows Server 2003 SP2 and Server 2008 SP2, R2, and R2 SP1 does not properly handle objects in memory during record lookup, which allows remote attackers to cause a denial of service (daemon restart) via a crafted query, aka "DNS Denial of Service Vulnerability."
network
low complexity
microsoft CWE-399
5.0
2011-08-10 CVE-2011-1970 Buffer Errors vulnerability in Microsoft products
The DNS server in Microsoft Windows Server 2003 SP2 and Windows Server 2008 SP2, R2, and R2 SP1 does not properly initialize memory, which allows remote attackers to cause a denial of service (service outage) via a query for a nonexistent domain, aka "DNS Uninitialized Memory Corruption Vulnerability."
network
low complexity
microsoft CWE-119
5.0
2011-06-16 CVE-2011-1264 Cross-Site Scripting vulnerability in Microsoft products
Cross-site scripting (XSS) vulnerability in Active Directory Certificate Services Web Enrollment in Microsoft Windows Server 2003 SP2 and Server 2008 Gold, SP2, R2, and R2 SP1 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka "Active Directory Certificate Services Vulnerability."
network
microsoft CWE-79
4.3