Vulnerabilities > Microsoft > Windows Vista > Medium

DATE CVE VULNERABILITY TITLE RISK
2008-09-11 CVE-2008-3629 Resource Management Errors vulnerability in Apple Quicktime
Apple QuickTime before 7.5.5 allows remote attackers to cause a denial of service (application crash) via a crafted PICT image that triggers an out-of-bounds read.
4.3
2008-09-11 CVE-2008-3624 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple Quicktime
Heap-based buffer overflow in Apple QuickTime before 7.5.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a QuickTime Virtual Reality (QTVR) movie file with crafted panorama atoms.
6.8
2008-09-11 CVE-2008-3614 Numeric Errors vulnerability in Apple Quicktime
Integer overflow in Apple QuickTime before 7.5.5 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PICT image, which triggers heap corruption.
6.8
2008-09-11 CVE-2008-2326 Improper Input Validation vulnerability in Apple Bonjour 1.0.4
mDNSResponder in the Bonjour Namespace Provider in Apple Bonjour for Windows before 1.0.5 allows attackers to cause a denial of service (NULL pointer dereference and application crash) by resolving a crafted .local domain name that contains a long label.
network
low complexity
apple microsoft CWE-20
5.0
2008-08-27 CVE-2008-3843 Cross-Site Scripting vulnerability in Microsoft .Net Framework 1.0/1.1/2.0
Request Validation (aka the ValidateRequest filters) in ASP.NET in Microsoft .NET Framework with the MS07-040 update does not properly detect dangerous client input, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated by a query string containing a "<~/" (less-than tilde slash) sequence followed by a crafted STYLE element.
network
microsoft CWE-79
4.3
2008-08-27 CVE-2008-3842 Cross-Site Scripting vulnerability in Microsoft .Net Framework 1.0/1.1/2.0
Request Validation (aka the ValidateRequest filters) in ASP.NET in Microsoft .NET Framework without the MS07-040 update does not properly detect dangerous client input, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated by a query string containing a "</" (less-than slash) sequence.
network
microsoft CWE-79
4.3
2008-07-30 CVE-2008-3365 Path Traversal vulnerability in Pixelpost 1.7.1
Directory traversal vulnerability in index.php in Pixelpost 1.7.1 on Windows, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a ..
6.8
2008-06-12 CVE-2008-1441 Improper Input Validation vulnerability in Microsoft products
Microsoft Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to cause a denial of service (system hang) via a series of Pragmatic General Multicast (PGM) packets with invalid fragment options, aka the "PGM Malformed Fragment Vulnerability."
network
high complexity
microsoft CWE-20
5.4
2008-06-10 CVE-2008-1581 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple Quicktime
Heap-based buffer overflow in Apple QuickTime before 7.5 on Windows allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted packed scanlines in PixData structures in a PICT image.
6.8
2008-04-25 CVE-2008-1932 Numeric Errors vulnerability in Realtek HD Audio Codec Drivers
Integer overflow in Realtek HD Audio Codec Drivers RTKVHDA.sys and RTKVHDA64.sys before 6.0.1.5605 on Windows Vista allows local users to execute arbitrary code via a crafted IOCTL request.
local
low complexity
microsoft realtek CWE-189
6.8